View previous topic :: View next topic |
Author |
Message |
pachanga Tux's lil' helper
![Tux's lil' helper Tux's lil' helper](/images/ranks/rank_rect_1.gif)
![](images/avatars/655969851425e36d90c174.jpg)
Joined: 03 Dec 2004 Posts: 123 Location: Russia, Penza
|
Posted: Fri Nov 25, 2005 9:12 am Post subject: The black list of ips without firewall |
|
|
Folks, what is the best way to implement a black list of ips which should be rejected on connecting to the certain port of the server?
My server doesn't have the packet filter support in kernel yet and while iptables stuff is not available i'd like to make such a black list manually.
Should i use hosts.deny for now? How would that look? Like something as following:
Quote: |
sshd : xxxx.xxxx.xxxx.xxxx, yyyy.yyyy.yyyy.yyyy, ....
|
_________________ Gentoo community rocks! LIMB - a WACT powered CMF tested with SimpleTest |
|
Back to top |
|
![](templates/gentoo/images/spacer.gif) |
Sleipnir Guru
![Guru Guru](/images/ranks/rank_rect_3.gif)
![](images/avatars/152313444043383b258272f.jpg)
Joined: 20 Sep 2005 Posts: 372 Location: Germany
|
Posted: Fri Nov 25, 2005 10:11 am Post subject: |
|
|
According to the man page (man 5 hosts_access) this should work. _________________ A)bort, R)etry, I)nfluence with large hammer. |
|
Back to top |
|
![](templates/gentoo/images/spacer.gif) |
pachanga Tux's lil' helper
![Tux's lil' helper Tux's lil' helper](/images/ranks/rank_rect_1.gif)
![](images/avatars/655969851425e36d90c174.jpg)
Joined: 03 Dec 2004 Posts: 123 Location: Russia, Penza
|
Posted: Fri Nov 25, 2005 10:33 am Post subject: |
|
|
I used this approach and now i get "warning: /etc/hosts.deny, line 0: missing newline or line too long", i have about 200+ ips to block and all of them are on the same line How can i make multiple lines of ips for the same port? _________________ Gentoo community rocks! LIMB - a WACT powered CMF tested with SimpleTest |
|
Back to top |
|
![](templates/gentoo/images/spacer.gif) |
Sleipnir Guru
![Guru Guru](/images/ranks/rank_rect_3.gif)
![](images/avatars/152313444043383b258272f.jpg)
Joined: 20 Sep 2005 Posts: 372 Location: Germany
|
Posted: Fri Nov 25, 2005 12:34 pm Post subject: |
|
|
Maybe you should just try it out.
Code: |
in.sshd: ip1
ip2
ip3
ip4
|
or
Code: |
in.sshd: ip1
in.sshd: ip2
in.sshd: ip3
|
_________________ A)bort, R)etry, I)nfluence with large hammer. |
|
Back to top |
|
![](templates/gentoo/images/spacer.gif) |
pachanga Tux's lil' helper
![Tux's lil' helper Tux's lil' helper](/images/ranks/rank_rect_1.gif)
![](images/avatars/655969851425e36d90c174.jpg)
Joined: 03 Dec 2004 Posts: 123 Location: Russia, Penza
|
Posted: Fri Nov 25, 2005 1:24 pm Post subject: |
|
|
Sleipnir wrote: | Maybe you should just try it out. ![Smile :)](images/smiles/icon_smile.gif) |
I'll give it a try and report here. BTW, what's "in." prefix mean? The incoming connection? _________________ Gentoo community rocks! LIMB - a WACT powered CMF tested with SimpleTest |
|
Back to top |
|
![](templates/gentoo/images/spacer.gif) |
pachanga Tux's lil' helper
![Tux's lil' helper Tux's lil' helper](/images/ranks/rank_rect_1.gif)
![](images/avatars/655969851425e36d90c174.jpg)
Joined: 03 Dec 2004 Posts: 123 Location: Russia, Penza
|
Posted: Wed Nov 30, 2005 10:38 am Post subject: |
|
|
Yep, it worked - splitting the long line into shorter ones. Thanks! _________________ Gentoo community rocks! LIMB - a WACT powered CMF tested with SimpleTest |
|
Back to top |
|
![](templates/gentoo/images/spacer.gif) |
|