Gentoo Logo
Gentoo Spaceship




Note: Due to technical difficulties, the Archives are currently not up to date. GMANE provides an alternative service for most mailing lists.
c.f. bug 424647
List Archive: gentoo-security
Navigation:
Lists: gentoo-security: < Prev By Thread Next > < Prev By Date Next >
Headers:
To: gentoo-security@g.o
From: Kirk Hoganson <kirk2@...>
Subject: Re: [OT?] automatically firewalling off IPs
Date: Tue, 04 Oct 2005 11:16:14 -0600
Yes, there are.  I use one for my work servers that is iptables based. 
I don't have any links for you unfortunately but I have seen them.  If 
you are really interested I can probably track down one I saw that used 
iptables and was a combination style.  I also know of an open source 
"magic packet" style that I could probably find a link for if you were 
interested.

boger said the following:
> Hello Kirk,
> Is there IPtables based port knocker? 
> I dislike idea opening ports for this purpose because they can be distinguished by some way.
> Promiscuous mode port knockers consume a lot of processor and
>  I don't think it's good for production server.
> 
> KH> A port knocker of some sort is a much more secure solution that will
> KH> allow you to block all unwanted IP's but still allow for dynamic 
> KH> addresses.  There are port knockers that listen on various ports and
> KH> work like a combination lock to open the port, and there are others that
> KH> use a more secure one time pad "magic packet" kind of authentication to
> KH> open the port for your IP.  It is more work to setup, but it is more
> KH> secure than just changing the port.  Remember a few years ago when ssh
> KH> had a remote exploit?  You probably shouldn't leave that port open.
> 
-- 
gentoo-security@g.o mailing list


Replies:
Port knocking
-- Tobias Sager
Re: [OT?] automatically firewalling off IPs
-- boger
References:
[OT?] automatically firewalling off IPs
-- Jeremy Brake
Re: [OT?] automatically firewalling off IPs
-- MaxieZ
Re: [OT?] automatically firewalling off IPs
-- David vasil
Re: [OT?] automatically firewalling off IPs
-- rpfc
Re: [OT?] automatically firewalling off IPs
-- Kirk Hoganson
Re: [OT?] automatically firewalling off IPs
-- boger
Navigation:
Lists: gentoo-security: < Prev By Thread Next > < Prev By Date Next >
Previous by thread:
Re: [OT?] automatically firewalling off IPs
Next by thread:
Re: [OT?] automatically firewalling off IPs
Previous by date:
Re: [OT?] automatically firewalling off IPs
Next by date:
Re: [OT?] automatically firewalling off IPs


Updated Oct 31, 2011

Summary: Archive of the gentoo-security mailing list.

Donate to support our development efforts.

Copyright 2001-2013 Gentoo Foundation, Inc. Questions, Comments? Contact us.