Re: Tightening SSH access

From: Keith Keller (kkeller-usenet_at_wombat.san-francisco.ca.us)
Date: 07/08/05


Date: Fri, 8 Jul 2005 14:38:14 -0700

On 2005-07-08, Carlos Moreno <moreno_at_mochima_dot_com@xx.xxx> wrote:
>
> Is there a way to configure SSH + iptables such that it only accepts
> logins coming from our machines? Ideally, the access should require
> password (i.e., a Unix login password) + public-key verification (only
> our keys would be accepted by SSH) + verification (via MAC) that it
> comes from our machines (our IP is not static, so using the source
> IP to validate would be risky). Is it possible?

I can't speak to all of your concerns, but MACs are spoofable, and in
theory anyone on the local network should be able to sniff your MAC.
That being said,

> In the iptables tutorial I have, they mention that the MAC-based
> match support is not quite solid. I'm not sure if that still holds.

I think MAC-based matching is reasonably good in recent kernels. I've
been using it for some of my boxes, and it seems to work fine.

--keith

-- 
kkeller-usenet@wombat.san-francisco.ca.us
(try just my userid to email me)
AOLSFAQ=http://wombat.san-francisco.ca.us/cgi-bin/fom
see X- headers for PGP signature information


Relevant Pages

  • Re: cd recordings vs minidisc recordings
    ... Most of these tend to be Windows or Macs ... where our servers of main machines tend to be Solaris. ... you will end up needing a fan or extra hardware of some other kind. ...
    (uk.rec.audio)
  • Re: Oustanding Value from Dell
    ... while the others are on Windows. ... One of the really great things about Macs is that they *very* unlikely to ... to always have 20 fully functional machines according to a certain spec. ... Nobody in this group likes Dell, but to be fair, they make perfectly ...
    (alt.comp.hardware.pc-homebuilt)
  • Re: Playing Hold em with Mac OS X???
    ... You're right - there are too many clowns in the WinDoze world, ... MACs not only don't crash, but don't get viruses, don't require regular ... Funny - sounds just like all the WinDoze machines I use - they don't ... a Mini Cooper is waycool better ...
    (rec.gambling.poker)
  • Re: OT: Do Macs "tend to be more expensive"? Snit says so... now;)
    ... Steve is about to prove why income and Mac ownership are ... So you now believe that "Macs tend to be more expensive"... ... Even the part about "comparatively pricier machines"? ...
    (comp.sys.mac.advocacy)
  • Re: Playing Hold em with Mac OS X???
    ... I think XP is pretty decent, ... except for security and registry rot issues. ... MACs not only don't crash, but don't get viruses, don't require regular ... Funny - sounds just like all the WinDoze machines I use - they don't ...
    (rec.gambling.poker)