LinuxQuestions.org
Register a domain and help support LQ
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices



Reply
 
Search this Thread
Old 06-02-2005, 02:48 AM   #1
gong
LQ Newbie
 
Registered: May 2004
Posts: 13

Rep: Reputation: 0
knockd


I am trying to close my ssh port and open it when knocked with a certain sequence. I'm using knockd to achieve this. The problem is that I cannot establish a connection on this machine from a remote machine. Please, let me know what I'm doing wrong. Here are my config files:

----------/etc/hosts.allow-------
ALL: ALL: DENY

----------/etc/host.deny---------
ALL: ALL

---------rc.firewall----------
#!/bin/bash

iptables -P INPUT DROP
iptables -P FORWARD DROP

iptables -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
iptables -A INPUT -s 127.0.0.1 -d 127.0.0.1 -i lo -j ACCEPT

----------trying to turn allow ssh access--------
start_command = /usr/sbin/iptables -A INPUT -s %IP% -p tcp --syn -j ACCEPT
 
Old 07-03-2005, 07:49 AM   #2
unSpawn
Moderator
 
Registered: May 2001
Posts: 27,744
Blog Entries: 54

Rep: Reputation: 2973Reputation: 2973Reputation: 2973Reputation: 2973Reputation: 2973Reputation: 2973Reputation: 2973Reputation: 2973Reputation: 2973Reputation: 2973Reputation: 2973
Just in case this still ain't working:
1. When troubleshooting applications, try to use verbose mode and log about anything. Same goes for Iptables: put some logrules in before.
2. If your version of OpenSSHd is compiled with Libwrap, it will respect the TCP Wrappers settings (/etc/hosts.*). Your current settings will not allow any tcp/22 connection.
3. Please check your iptables location. IIRC it's by default in /sbin.
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



All times are GMT -5. The time now is 10:44 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
identi.ca: @linuxquestions
Facebook: linuxquestions Google+: linuxquestions
Open Source Consulting | Domain Registration