LinuxQuestions.org
Review your favorite Linux distribution.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Server
User Name
Password
Linux - Server This forum is for the discussion of Linux Software used in a server related context.

Notices


Reply
  Search this Thread
Old 05-27-2010, 01:53 AM   #1
SchoutenCC
LQ Newbie
 
Registered: May 2010
Posts: 2

Rep: Reputation: 0
Conditional (on ip address) /etc/issue.net possible?


Hi all,
I'm running Debian with openssh 1:5.1p1-5 and I've got an operational and legal /etc/issue.net but I'd like to make it depend on the incoming IP address. To be more specific, I'd like to achieve that no banner is shown when logging in from my company's IP range(s) or when logging in from home, but any unknown address (potential intruder) should be confronted with our legal warning.
Is this at all possible?
The server is located off-site and only has one ethernet device active (i.e. I cannot say eth0 is external, eth1 is internal)
Thanks in advance for any tips,
Chris
 
Old 05-27-2010, 03:14 AM   #2
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
In my opinion if a banner is present for policy reasons then it should be shown always. Take for instance a change of network range. If one forgets to change the range exclusions in time then the banner might not be shown as required. That's not about me asking you to make a decision (as it isn't mine or yours to decide anyway), but about you asking your legal dept. what their stance would be on that?..
 
Old 05-30-2010, 06:18 AM   #3
SchoutenCC
LQ Newbie
 
Registered: May 2010
Posts: 2

Original Poster
Rep: Reputation: 0
Hi unSpawn,
That a very valid point (and I have to say I agree) from a procedural point of view, but what I forgot to mention in my initial post was that the question came to me from a day-to-day nuisance of the backup script. I use scp to copy some backed up files to another server, so my inbox is filled with crontab's reports of it encountering the banner In other words, ideally I'd like to hide the banner when it's a cronjob copying from server a to b, hence making an ssh connection that requires displaying the banner.
Best,
Chris
 
Old 05-30-2010, 07:55 AM   #4
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
Depending on your version of OpenSSHd scp and ssh may accept "-q" which should mute sshd_config Banner. Since you're running a cronjob nothing prohibits you from suffixing the jobs command line with something like ">/dev/null 2>&1" as well.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Fedora 7 Net-Install screws up Address to FTP Server D_RangeD Fedora - Installation 1 10-11-2007 09:19 AM
How do you know if IP address is accessible on the net? jonbey Linux - Newbie 8 09-30-2007 11:36 AM
Need an IP address for OpenSuSE net install Thaidog SUSE / openSUSE 2 12-04-2006 02:21 AM
how do I block mail sent to my .net address as opposed to my .com addr? BrianK Linux - General 2 12-01-2003 02:31 AM
changed local net address nfs is hanging at boot spooge Linux - Networking 2 08-20-2003 01:37 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Server

All times are GMT -5. The time now is 05:12 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration