LinuxQuestions.org
Download your favorite Linux distribution at LQ ISO.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Newbie
User Name
Password
Linux - Newbie This Linux forum is for members that are new to Linux.
Just starting out and have a question? If it is not in the man pages or the how-to's this is the place!

Notices


Reply
  Search this Thread
Old 04-14-2019, 09:00 AM   #1
djsigmann
LQ Newbie
 
Registered: Apr 2019
Location: Somewhere
Distribution: debian
Posts: 1

Rep: Reputation: 0
Port Forwarding question regarding security.


So, This may be the incorrect place to post this, if it is please let me know.

Basically, I am new to Linux in general and am unsure about many things.

To cut it short, I want to open port 22 to a machine on my network, not for ssh access, but to monitor and record login attempts by other people (using iptables or something).

Would this be safe? Advised? Nonsensical? Why or why not?

Any helpful responses will be greatly appreciated, thanks in advance.
 
Old 04-14-2019, 09:38 AM   #2
TB0ne
LQ Guru
 
Registered: Jul 2003
Location: Birmingham, Alabama
Distribution: SuSE, RedHat, Slack,CentOS
Posts: 26,712

Rep: Reputation: 7972Reputation: 7972Reputation: 7972Reputation: 7972Reputation: 7972Reputation: 7972Reputation: 7972Reputation: 7972Reputation: 7972Reputation: 7972Reputation: 7972
Quote:
Originally Posted by djsigmann View Post
[FONT="Arial"]So, This may be the incorrect place to post this, if it is please let me know.
Basically, I am new to Linux in general and am unsure about many things.

To cut it short, I want to open port 22 to a machine on my network, not for ssh access, but to monitor and record login attempts by other people (using iptables or something). Would this be safe? Advised? Nonsensical? Why or why not?
Linux doesn't have much to do with this, in all honesty. What you're talking about is basic network security, and for that you'd be better off with a real network security solution. IDS systems like Snort exist to do this very thing, and generate useful data from attempts.
 
1 members found this post helpful.
Old 04-14-2019, 09:55 AM   #3
thinknix
Member
 
Registered: Nov 2008
Distribution: Lots!
Posts: 178

Rep: Reputation: 58
You may also want to look into setting up a network honeypot, which would fool attackers into thinking they had compromised a server and record what they did afterwards. Apart from the research aspect (which you may be interested in so I don't want to discourage you), you're likely to be disappointed if you just setup, say an iptables firewall that drops and logs all port 22 login attempts. On any server connected to the internet with port 22 open, you will see brute-force login attempts in your logs all day, every day.
 
1 members found this post helpful.
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
[SOLVED] IPtables : ssh port forwarding one port to another port issue routers Linux - Networking 7 08-07-2018 08:41 AM
Redirec port in device eth0 to port+ip in device wlan0 ( port forwarding on hostpd wireless network) MattFly Linux - Networking 2 08-28-2016 07:21 PM
Shorewall: port forwarding problem, port is closed even after forwarding Synt4x_3rr0r Linux - Networking 2 12-13-2009 04:36 PM
IPCHAINS port forwarding and IPTABLES port forwarding ediestajr Linux - Networking 26 01-14-2007 07:35 PM
Question about port forwarding security. ahh Linux - Security 6 07-10-2004 10:54 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Newbie

All times are GMT -5. The time now is 01:52 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration