1 |
On December 3, 2008, Steve wrote: |
2 |
> Paul Hartman wrote: |
3 |
> > I think using Dmitry's idea of rejecting the first 2 connections, but |
4 |
> > then allowing it as normal on the third attempt would satisfy your |
5 |
> > requirements for being on the normal port, allowing all IPs and |
6 |
> > requiring no special setup on the client end (other than knowing they |
7 |
> > have to to retry twice). |
8 |
> |
9 |
> Erm - surely I either need to set up my client to port-knock... which is |
10 |
> a faff I'd rather avoid... in order to use the technique. |
11 |
|
12 |
nope. just start connection. wait a minute. cancel. start another one. wait a |
13 |
minute. cancel. start new one - voila! :) |
14 |
|
15 |
> While I recognise port knocking as a valuable strategy in some |
16 |
> circumstances, it seems a very bad fit for my needs. |
17 |
|
18 |
well. Nobody but you knows your requiremens and specifics - we're just listing |
19 |
options. It's up to you to either take 'em or leave 'em ;) |
20 |
|
21 |
-- |
22 |
Dmitry Makovey |
23 |
Web Systems Administrator |
24 |
Athabasca University |
25 |
(780) 675-6245 |