Re: KPF 2.1.5: Catch-all rule complicates having firewall ask about incoming ssh




"Dubious Dude" <Shifty@xxxxxxxx> wrote in message
news:f7d63p$sb6$1@xxxxxxxxxxx
I would like KPF to ask whether to allow incoming TDP connections to port
22.
Creating a rule only lets the user choose whether to permit or deny the
connection, not whether to prompt for permission or denial. I thought
that I
could delete the rule altogether, in which case the user is prompted to
permit
or deny the incoming ssh. However, the last rule of the firewall is a
catch-all
rule that denies any connections not covered by any other rules. This
prevents
KPF from prompting for incoming TDP connections to port 22. Is there a
way to
have KPF prompt for incoming connections to port 22, yet still maintain
the
catch-all rule?

Thanks.

The short answer is no.

The catch-all is meant to be put into place after you have tuned the
firewall for
all the inbound connection you plan on accepting. That way it will not keep
prompting you when new ports are attempted but simply deny them.

If you actually want someone to be able to connect to your port 22 it makes
more sense to simply allow it in your rules. You could even restrict the IP
addresses allowed to connect. Finally, ensure your ssh application is fully
patched and hardened so only authorized parties can get through.


Cheers,

Systemguy


.



Relevant Pages

  • Re: C# Reflection - Nasty bug??
    ... still get the prompt although I cannot connect to the server with my client. ... > Can you telnet into localhost to the port your server is running and get ... >> "is it possible for you to indicate that all connections in your program ...
    (microsoft.public.dotnet.languages.csharp)
  • NewB-Help with logs
    ... I enabled logging on most of my firewall rules -- the 'deny' ones, ... Most are denied connections to my port 80 -- misconfigured DNS ...
    (comp.os.linux.security)
  • Re: KPF 2.1.5: Catch-all rule complicates having firewall ask about incoming ssh
    ... Creating a rule only lets the user choose whether to permit or deny the ... not whether to prompt for permission or denial. ... KPF from prompting for incoming TDP connections to port 22. ...
    (comp.security.firewalls)
  • New to IPFW and would like critique...
    ... fxp0 is my outside interface ... ${fwcmd} add 101 pass all from any to any via lo0 ... $add 119 deny all from any to 127.0.0.0/8 ... # FTP - Allow incoming data channel for outgoing connections, ...
    (comp.unix.bsd.freebsd.misc)
  • Re: AS 2005 HTTP access with Basic Authentication
    ... > would work without demanding the basic authentication credentials again. ... > AS 2000's PTS used WinInet to connect to the server over HTTP. ... > - When PTS 8.0 ran within Internet Explorer, it's WinInet connections were ... so it should always prompt for the cross domain data request ...
    (microsoft.public.sqlserver.olap)

Quantcast