Displaying 20 results from an estimated 8000 matches similar to: "Manual Chains Knock.pm DNAT-"
2009 Dec 26
2
Connection tracking, DNAT, and boot sequence
Greetings shorewall users,
I''m running into a problem and hoping someone might have a simple idea
how to fix it.
I have shorewall configured on a linux fw with 2 port DNAT rules to an
internal server for openvpn from external clients. Everything works fine
there.
I have a problem when the fw is rebooted however. When it comes back up,
interfaces are brought up before shorewall is
2013 Mar 11
8
Need some help with a new SNAT/DNAT/NAT + DMZ + Xen Host/Guest config.
Hi.
I''m migrating to shorewall(6) mgmt of my various firewalls.
Simple configs have been easy with the great docs.
I''ve got a slightly more convoluted config, and have gotten ''lost'' in
config''ing a SNAT/DNAT/NAT + DMZ + Xen Host/Guest set up with Static
IP/29. Having some challenges wrapping my head around the ''best''
Shorewall
2004 Sep 27
7
X100P knock-off price jump
Anyone know why the knock-off X100p prices have jumped?
-Nate
2003 Sep 15
3
X100P & T100P knock-off boards
Do they fall under FCC certification if they're built to the same
specifications as the ones from Digium? If I build my own T100Ps from the
schematics and board layouts that are available, are they legal to plug
into the PSTN?
2013 Oct 10
0
Port knocking and DNAT rules
So I found an excellent port knocking tutorial using ONLY iptables rules
that looks to be among the best I've ever seen. (warning: techno music,
tough to read screen, you don't need to type it in because I post a link
to script below)
http://www.youtube.com/watch?v=0zFQocf7C_0
It works fabulously for simply opening a port to a locally managed
service, but I can't seem to get it
2010 Oct 21
10
KVM and bridge
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
An Ubuntu 10.04 server running Shorewall 4.4.6.1 hosts three KVM
virtual servers on the default libvrt virbr0 bridge at the default
vnet+ bridge ports. The bridge and ports are on a separate private
subnet (192.168.122.0/24). Each bridge port and the bridge itself are
in the dmz, there are two physical interfaces and private local
subnets in loc, and
2005 Sep 06
0
Knock SSHD call in and SSH call out scripts
Okay, I finally took the time to re-write the scripts that I had talked about
a few threads earlier.
I have 2 versions of them, and they currently work for Redhat Enterprise 4 and
SuSE Enterprise 9. (using iptables, and xinetd.d)
The 2 varieties are:
#1 knock, to be allowed to connect from the IP address written by the knock
sequence. This adds an iptable entry to allow the specified IP
2014 Dec 21
2
[PATCH] LocalPreCommand: Support for executing command before ssh connection (like port knock before ssh)
Hi guys,
I've made a patch adding LocalPreCommand to ssh_config. It mimics
behaviour of LocalCommand, but is executed right before the connection
is opened. This makes possible e.g. to integrate ssh with port
knocking. It also removes "-oPermitLocalCommand=no" from scp allowing
the same functionality to be used for file transfers.
Applies cleanly on vanilla OpenSSH 6.7p1.
2006 Jul 15
1
patch to add built-in support for port knocking
All,
A friend gave me access to an svn(+ssh) repository the other day, and
told me that I needed to do some port knocking to open up ssh. It
occurred to me that it would be extremely convenient if I could add a
"knock" configuration option for the host to my ~/.ssh/config file
and never think about this again (rather than creating a shell script
to accomplish this behavior,
2024 Jul 07
1
Request for a Lockdown option
Steffen Nurpmeso wrote in
<20240704180538.iV4uex29 at steffen%sdaoden.eu>:
|Simon Josefsson wrote in
| <87jzi1fg24.fsf at kaka.sjd.se>:
||Jochen Bern <Jochen.Bern at binect.de> writes:
||> (And since you mention "port knocking", I'd like to repeat how fond I
||> am of upgrading that original concept to a single-packet
||> crypto-armored
2024 Jul 14
2
Request for a Lockdown option
P.S.:
Steffen Nurpmeso wrote in
<20240707025234.j3oUaPFH at steffen%sdaoden.eu>:
|Steffen Nurpmeso wrote in
| <20240704180538.iV4uex29 at steffen%sdaoden.eu>:
||Simon Josefsson wrote in
|| <87jzi1fg24.fsf at kaka.sjd.se>:
|||Jochen Bern <Jochen.Bern at binect.de> writes:
|||> (And since you mention "port knocking", I'd like to repeat how fond I
2011 Oct 19
5
Instalation of lastest version of Shorewall in Debian
I want to use lastest version of Shorewall in my fresh debian squeeze
instalation,
so I follow http://www.shorewall.net/Install.htm#Debian
but, modify preferences file was not enough for me,
I have to modify/add some other files in /etc/apt/ directory:
1.) include testing repo to source.list
2.) add APT::Default-Release "stable"; to apt.conf
and pinning all other packages to stable
2009 Dec 08
1
EmergingThreats fwrules ipset updater
hi
i''ve created an emergingthreats fwrules ipset updater for use with my
shorewall.
maybe others find this usefull too.
short howto:
* get bash script (emerging-ipset-update.txt) from
http://doc.emergingthreats.net/bin/view/Main/EmergingFirewallRules
* add the configured ipsets to shorewall configfile "blacklist"
* if not already configured: configure your interfaces for
2009 Dec 09
1
Does shorewall change Kernel parameters?
I have a server that runs shorewall lite. This server has a custom
configuration of the semaphore setting. The configuration is set in
/etc/sysctl.conf . It works fine most of the time.
We have a daemon that crashes, we found that is a semaphores config issue.
After the crash we found that semaphore parameters are reseted to defaults.
The only event we found is a reload of firewall rules.
I
2010 Jan 20
1
Rule and a few drops...
I have this rule in place:
--------------------------------------
DNAT net dmz:10.0.0.7 tcp 80,443
- 94.23.242.44
--------------------------------------
When I change this policy:
--------------------------------------
net dmz DROP
--------------------------------------
to:
--------------------------------------
net dmz DROP info
2024 Jul 04
1
Request for a Lockdown option
Simon Josefsson wrote in
<87jzi1fg24.fsf at kaka.sjd.se>:
|Jochen Bern <Jochen.Bern at binect.de> writes:
|> (And since you mention "port knocking", I'd like to repeat how fond I
|> am of upgrading that original concept to a single-packet
|> crypto-armored implementation like fwknop.)
|
|I am reluctantly considering to use some kind of port knocking
2009 Dec 16
3
Dual-homing BGP gate problem
Hi Tom,
After two weeks of nightmares I decided ask You (and anyone reading this mail).
Context is as follows:
I try to update system on my central router from kernel 2.6.29.6 and Shorewall
4.2.6 (old) to kernel 2.6.31.6 and Shorewall 4.4.4.2 (new).
This is LiveCD image boot (Devil-Linux distribution compiled by me), so config
is this same.
I have established ten OpenVPN tunnels and two
2005 Mar 18
3
Easy Accounting?
I have an office setup with shorewall and when there''s bandwidth
problems, I''d like to know who''s hogging my bandwidth and how (port).
What would be the best approach to have shorewall show me something
like:
IP | Port | Bytes In | Bytes Out
I have 20 PCs connected via DHCP.
I looked at the documentation and thought that accounting may be close,
but accounting
2010 Nov 08
15
Can I use shorewell stuff for my problem
Hi all, Im new to shorewell, can anyone guide me whether I can use
shorewell for my work.
I have a requirement in our work:
Each system shall have two Ethernet card interfaces(system means hardware
devices, servers, clients in other words any device or host used in the
project). The IP address of each interface will be of different networks,
subnets and gateways completely. Bcoz if one of
2010 Jan 21
6
Shorewall 4.4.6 and Multiple ISP with 2 routed subnets
Hello,
I have 2 ISP uplinks (zones: inet1 and inet2), each with a fixed IP on the outside and a routed subnet (/25 and /26) on the inside. So, behind the firewall i have 2 networksegments (lan1 and lan2) with public IP-addresses. The segments are completely isolated from eachother: hosts in zone "lan1" connect only to "inet1" and hosts in zone "lan2" only connect