LinuxQuestions.org
Help answer threads with 0 replies.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Software
User Name
Password
Linux - Software This forum is for Software issues.
Having a problem installing a new program? Want to know which application is best for the job? Post your question in this forum.

Notices


Reply
  Search this Thread
Old 07-09-2010, 11:11 AM   #1
Myiagros
Member
 
Registered: Mar 2009
Distribution: Ubuntu, CentOS 5.3
Posts: 75

Rep: Reputation: 18
Denyhosts blocking router IP


I've been using the denyhosts software for about 8 months to block IPs that are trying to connect to my network that shouldn't be. I'm having trouble with it today for the first time and I can't track down the issue.

It is installed on the main server which is the outside IP for the network as well. This should allow me to SSH to the hostname/network IP, or the NAT IP as well. It worked fine up until this morning when I started to work on an ftp server, as far as I know I didn't make any changes that should cause problems.

hosts.deny starts with no 192.x.x.x addresses in it.
In allowed-hosts for denyhosts I have entered 192.168.1.1 so that the router should never get blocked.
I can SSH to the hostname perfectly fine, connection doesn't drop or anything.
If I SSH to the NAT address the connection hangs there while the IP address gets added to hosts.deny

I can confirm 100% that I was able to SSH to my NAT from within the network with no problem, now it seems to throw the router IP into hosts.deny if I try to connect from within the network using the NAT.

Here is the error that I get in /var/log/secure

sshd[9272]: Did not receive identification string from 192.168.1.1

I did update my system recently which may have changed the way some files behave, I will try updating Denyhosts as well. It looked like the address being blocked was an IPv6 since it was showing as:
sshd[9201]: refused connect from ::ffff:192.168.1.1 (::ffff:192.168.1.1)

I added ::ffff:192.168.1.1 to allowed-hosts and the IPv4 address wasn't added to the hosts.deny the last time I tried.

Last edited by Myiagros; 07-09-2010 at 11:26 AM. Reason: more info added
 
Old 07-09-2010, 12:03 PM   #2
Myiagros
Member
 
Registered: Mar 2009
Distribution: Ubuntu, CentOS 5.3
Posts: 75

Original Poster
Rep: Reputation: 18
I believe the problem may be with the newest firmware for my router, I'm not 100% on that though. It's almost like the authentication isn't being carried to the router so the connection gets dropped. The IP shouldn't be blocked though because I have set it to only block after 5 attempts.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Router domain blocking linuxbird Linux - Networking 1 09-18-2009 09:48 AM
Router blocking SSH, HTTP, FTP? Zmyrgel Linux - Networking 4 04-12-2006 12:19 AM
router blocking access to services openbysource Linux - Networking 3 02-18-2006 01:09 PM
Adware Blocking Router ms662412 Linux - Security 6 05-29-2005 05:32 AM
Linksys Router Blocking Ports BrianW Linux - Networking 2 03-03-2004 12:37 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Software

All times are GMT -5. The time now is 05:12 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration