-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 I got a little friskier and put some other rules in place to see how things work. Here are the rules in place on con. So far things look good (via iptables --list -v -n). There are some syslog packets being dropped, but my suspicion are those are from ellipse (which REALLY needs to be turned off). Outside of these rules, the default is to accept packets. If you see a glaring problem let me know. #ACTION SOURCE DEST SSH(ACCEPT) net:140.221.9.203 all SSH(ACCEPT) net:140.221.8.8 all SSH(DROP) net all TFTP(ACCEPT) net:10.135.125.0/24 all TFTP(ACCEPT) net:10.135.250.0/24 all TFTP(ACCEPT) net:128.135.125.0/24 all TFTP(ACCEPT) net:128.135.250.0/24 all TFTP(DROP) net all DHCPfwd(ACCEPT) net:10.135.125.0/24 all DHCPfwd(ACCEPT) net:128.135.125.0/24 all DHCPfwd(DROP) net all Syslog(ACCEPT) net:10.135.125.0/24 all Syslog(ACCEPT) net:10.135.250.0/24 all Syslog(ACCEPT) net:128.135.84.6 all Syslog(ACCEPT) net:128.135.125.0/24 all Syslog(ACCEPT) net:128.135.234.0/24 all Syslog(ACCEPT) net:128.135.250.0/24 all Syslog(ACCEPT) net:149.165.148.2 all Syslog(ACCEPT) net:192.5.86.2 all Syslog(ACCEPT) net:192.5.200.56 all Syslog(DROP) net all On May 14, 2011, at 11:24 PM, Ti Leggett wrote:
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1
In case anyone is trying to get to con, I've locked it down using shorewall to only accept SSH from namby/pamby. I'm doing this as a test over the weekend just to see how things behave. If you need to shut it down, email me or login via namby/pamby and do:
/etc/init.d/shorewall stop
-----BEGIN PGP SIGNATURE----- Version: GnuPG/MacGPG2 v2.0.14 (Darwin)
iEYEARECAAYFAk3PVYYACgkQ4RgdOxQVi0BtDACggY6CAsb4XukIu88atbNhgrFS NGwAoIMUx1ydJVq5j64SmxmOUdU4jk6P =POl3 -----END PGP SIGNATURE-----
-----BEGIN PGP SIGNATURE----- Version: GnuPG/MacGPG2 v2.0.14 (Darwin) iEYEARECAAYFAk3PXMQACgkQ4RgdOxQVi0ACQgCeLSRSUMkD7lpeYChPRM5pZQEe 5pgAoJLQMCLn3FW+FaUyG1KxPE/VbmWt =7aJ4 -----END PGP SIGNATURE-----