LinuxQuestions.org
Share your knowledge at the LQ Wiki.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 02-23-2010, 07:14 PM   #1
abefroman
Senior Member
 
Registered: Feb 2004
Location: lost+found
Distribution: CentOS
Posts: 1,430

Rep: Reputation: 55
Help with firewall, can't deny ips after allowing local subnet


If I allow, my server's IP is:
11.11.11.11

If I allow 11.11.11.11, and block 22.22.22.22

22.22.22.22 can't access the server

But if I allow 11.11.11.0/24, and block 22.22.22.22

22.22.22.22 can still access the server!!

Does anyone know why that is?

TIA
 
Old 02-23-2010, 07:44 PM   #2
Noway2
Senior Member
 
Registered: Jul 2007
Distribution: Gentoo
Posts: 2,125

Rep: Reputation: 781Reputation: 781Reputation: 781Reputation: 781Reputation: 781Reputation: 781Reputation: 781
I would think that it should not. 11.11.11.0/24 and 22.22.22.22 are separate networks.

What are you using for a firewall and how are you performing the testing? There has to be an explaination for what you are experiencing. No doubt it will be one of those, Doh! moments once you figure it out
 
Old 02-23-2010, 07:59 PM   #3
abefroman
Senior Member
 
Registered: Feb 2004
Location: lost+found
Distribution: CentOS
Posts: 1,430

Original Poster
Rep: Reputation: 55
Quote:
Originally Posted by Noway2 View Post
I would think that it should not. 11.11.11.0/24 and 22.22.22.22 are separate networks.

What are you using for a firewall and how are you performing the testing? There has to be an explaination for what you are experiencing. No doubt it will be one of those, Doh! moments once you figure it out
I use the APF firewall, and I tried to SSH in from an IP that I blocked, and it worked. If I remove the /24 ssh access is denied.
 
Old 02-24-2010, 05:20 AM   #4
Noway2
Senior Member
 
Registered: Jul 2007
Distribution: Gentoo
Posts: 2,125

Rep: Reputation: 781Reputation: 781Reputation: 781Reputation: 781Reputation: 781Reputation: 781Reputation: 781
You may want to check the documentation for APF because it looks like it may not support CIDR notation. I haven't used it personally, but in an attempt to help you I read the posts in several forums where others were trying to block a range of IP addresses. In each case the suggestion was that if you wanted to block a specific IP address that APF handled it very simply. However, if they wanted to block a range (x.x.x.0/24), that they needed to add an entry into IP tables.
 
Old 02-24-2010, 05:34 AM   #5
nowonmai
Member
 
Registered: Jun 2003
Posts: 481

Rep: Reputation: 48
Post the output of...
iptables -L
ifconfig
route
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
how to allow and deny ssh acces to certain IPs caedo Linux - Security 4 09-19-2008 11:47 AM
Local webserver -- How to deny all client install their local web server--Please help b:z Linux - Networking 13 04-16-2005 07:11 PM
Forwarding connection using the same subnet IPs superandrzej Linux - Networking 12 04-27-2004 02:05 AM
Suse 9.0 Firewall not allowing local access gSalsero Linux - Security 3 04-19-2004 09:24 PM
How do i deny ips in apache?? vbp6us Linux - General 8 03-17-2003 09:02 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 05:11 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration