LinuxQuestions.org
Share your knowledge at the LQ Wiki.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 01-28-2005, 12:29 PM   #1
bad_andy
Member
 
Registered: Aug 2004
Distribution: Mandrake 10.1/Slackware 10.0
Posts: 154

Rep: Reputation: 30
Guarddog/SSH Question


Suppose I want to allow only myself to remotely log onto my office server via SSH. Can I configure Guarddog to block everyone else but me?
 
Old 01-28-2005, 02:09 PM   #2
leonscape
Senior Member
 
Registered: Aug 2003
Location: UK
Distribution: Debian SID / KDE 3.5
Posts: 2,313

Rep: Reputation: 48
Yes, on your office server create a new zone, and place your home IP address in that zone, and select local on the connection part.

Then goto the protocols tab and select the new zone, and allow access for ssh ( tick ).
 
Old 01-28-2005, 02:14 PM   #3
bad_andy
Member
 
Registered: Aug 2004
Distribution: Mandrake 10.1/Slackware 10.0
Posts: 154

Original Poster
Rep: Reputation: 30
Thanks, I'll give it a try.
 
Old 01-28-2005, 02:23 PM   #4
leonscape
Senior Member
 
Registered: Aug 2003
Location: UK
Distribution: Debian SID / KDE 3.5
Posts: 2,313

Rep: Reputation: 48
Just one thing, When you goto the protocol tab, don't select the new zone, select local, and tick ssh in the new zones column.

Got mixed up as to which way things are worked out
 
Old 01-28-2005, 03:02 PM   #5
bad_andy
Member
 
Registered: Aug 2004
Distribution: Mandrake 10.1/Slackware 10.0
Posts: 154

Original Poster
Rep: Reputation: 30
Thanks for your help so far, but I've got another question for you...

My network has a print server on it, and when I enable Guarddog, nothing prints. What do I have to do get around that problem?
 
Old 01-28-2005, 06:53 PM   #6
bad_andy
Member
 
Registered: Aug 2004
Distribution: Mandrake 10.1/Slackware 10.0
Posts: 154

Original Poster
Rep: Reputation: 30
Hey leonscape, is this another SSH approach?:


hosts.deny
sshd ALL EXCEPT 192.168.xxx.xxx
 
Old 01-28-2005, 07:10 PM   #7
leonscape
Senior Member
 
Registered: Aug 2003
Location: UK
Distribution: Debian SID / KDE 3.5
Posts: 2,313

Rep: Reputation: 48
What port are you using? are we talking CUPS or something else?

As for the other sshd method probably okay, but I don't know how iptables will react to having a different set of rules.
 
Old 01-28-2005, 07:24 PM   #8
bad_andy
Member
 
Registered: Aug 2004
Distribution: Mandrake 10.1/Slackware 10.0
Posts: 154

Original Poster
Rep: Reputation: 30
Yeah, I think it's CUPS--let's assume so. (I didn't set this system up, and Linux is fairly new to me).

I think I saw something about port 413, not 100% sure though.
 
Old 01-29-2005, 03:10 PM   #9
leonscape
Senior Member
 
Registered: Aug 2003
Location: UK
Distribution: Debian SID / KDE 3.5
Posts: 2,313

Rep: Reputation: 48
I think its port 631.

On the print server go to the advanced Tab in guarddog, and click New protocol fill in the name, and set the port to 631 then go back to the protocol tab, and click local on the left go down to the user defined group, and click on the cups protocol to allow access, to which ever zone the client machines are listed in.
 
Old 01-29-2005, 03:17 PM   #10
bad_andy
Member
 
Registered: Aug 2004
Distribution: Mandrake 10.1/Slackware 10.0
Posts: 154

Original Poster
Rep: Reputation: 30
Thanks leonscape, but I figured it out this morning.

The print server uses LPS, not CUPS. Using its network IP address, I created a new zone for the print server and enabled the Line Printer Spooler protocol between it and Local. Works like a charm now!
 
Old 01-29-2005, 03:31 PM   #11
leonscape
Senior Member
 
Registered: Aug 2003
Location: UK
Distribution: Debian SID / KDE 3.5
Posts: 2,313

Rep: Reputation: 48
Glad to hear you got sorted.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
ssh-agent/ssh-add question mega Slackware 2 01-26-2005 03:09 AM
Guarddog Question leeach Linux - Security 2 10-02-2003 03:21 PM
GuardDog/Firewall Question h1tman Linux - Security 2 08-12-2003 12:57 PM
SSH Question... Flipper Linux - Newbie 4 07-20-2003 03:29 PM
ssh question emetib Linux - Software 2 07-13-2003 12:27 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 04:59 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration