Gentoo Archives: gentoo-user

From: "Dmitry S. Makovey" <dmitry@××××××××××.ca>
To: gentoo-user@l.g.o
Cc: Steve <Gentoo_sjh@×××××××.uk>
Subject: Re: [gentoo-user] Curious pattern in log files from ssh...
Date: Thu, 04 Dec 2008 00:07:26
Message-Id: 200812031707.23306.dmitry@athabascau.ca
In Reply to: Re: [gentoo-user] Curious pattern in log files from ssh... by Steve
1 On December 3, 2008, Steve wrote:
2 > Paul Hartman wrote:
3 > > I think using Dmitry's idea of rejecting the first 2 connections, but
4 > > then allowing it as normal on the third attempt would satisfy your
5 > > requirements for being on the normal port, allowing all IPs and
6 > > requiring no special setup on the client end (other than knowing they
7 > > have to to retry twice).
8 >
9 > Erm - surely I either need to set up my client to port-knock... which is
10 > a faff I'd rather avoid... in order to use the technique.
11
12 nope. just start connection. wait a minute. cancel. start another one. wait a
13 minute. cancel. start new one - voila! :)
14
15 > While I recognise port knocking as a valuable strategy in some
16 > circumstances, it seems a very bad fit for my needs.
17
18 well. Nobody but you knows your requiremens and specifics - we're just listing
19 options. It's up to you to either take 'em or leave 'em ;)
20
21 --
22 Dmitry Makovey
23 Web Systems Administrator
24 Athabasca University
25 (780) 675-6245

Attachments

File name MIME type
signature.asc application/pgp-signature

Replies

Subject Author
Re: [gentoo-user] Curious pattern in log files from ssh... Steve <Gentoo_sjh@×××××××.uk>