All of lore.kernel.org
 help / color / mirror / Atom feed
* How to block particular port  based on src IP ?
@ 2010-04-14  3:18 J. Bakshi
  0 siblings, 0 replies; 4+ messages in thread
From: J. Bakshi @ 2010-04-14  3:18 UTC (permalink / raw)
  To: netfilter

Hello list,

I have these working rule-sets which blocked the IPs trying to ssh more
then 2 per min. And then the matching IPs are blacklisted for a
pre-defined time. Here 180 sec.

```````````
iptables -A INPUT -p tcp -m hashlimit --hashlimit-above 2/min
--hashlimit-burst 2 \
--hashlimit-name hashlimit -m state --state NEW -m tcp --dport $SSH_PORT
-j \
MARK --set-xmark 0x1/0xffffffff

iptables -A INPUT -m recent --rcheck --seconds 180 --name sshoverflow
--rsource -j DROP

iptables -A INPUT -m mark --mark 0x1 -m recent --set --name sshoverflow
--rsource -j DROP

iptables -A INPUT -p tcp -m state --state NEW --dport $SSH_PORT -j ACCEPT

``````````````````

I am trying to make an arrangement that rather blocking the IP,; only
the access to the ssh port will be blocked from that IP. So the other
services i.e. imap, apache will be still accessible from the IP
excluding ssh. Is it possible ?

Please suggest.
Thanks

-- 
জয়দীপ বক্সী


^ permalink raw reply	[flat|nested] 4+ messages in thread
* How to block particular port  based on src IP ?
@ 2010-04-13  6:51 J. Bakshi
  2010-04-16  9:46 ` Richard Horton
  0 siblings, 1 reply; 4+ messages in thread
From: J. Bakshi @ 2010-04-13  6:51 UTC (permalink / raw)
  To: netfilter

Hello list,

I have these working rule-sets which blocked the IPs trying to ssh more
then 2 per min. And then the matching IPs are blacklisted for a
pre-defined time. Here 180 sec.

```````````
iptables -A INPUT -p tcp -m hashlimit --hashlimit-above 2/min
--hashlimit-burst 2 \
--hashlimit-name hashlimit -m state --state NEW -m tcp --dport $SSH_PORT
-j \
MARK --set-xmark 0x1/0xffffffff

iptables -A INPUT -m recent --rcheck --seconds 180 --name sshoverflow
--rsource -j DROP

iptables -A INPUT -m mark --mark 0x1 -m recent --set --name sshoverflow
--rsource -j DROP

iptables -A INPUT -p tcp -m state --state NEW --dport $SSH_PORT -j ACCEPT

``````````````````

I am trying to make an arrangement that rather blocking the IP,; only
the access to the ssh port will be blocked from that IP. So the other
services i.e. imap, apache will be still accessible from the IP
excluding ssh. Is it possible ?

Please suggest.
Thanks

-- 
জয়দীপ বক্সী


^ permalink raw reply	[flat|nested] 4+ messages in thread

end of thread, other threads:[~2010-04-16 10:37 UTC | newest]

Thread overview: 4+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2010-04-14  3:18 How to block particular port based on src IP ? J. Bakshi
  -- strict thread matches above, loose matches on Subject: below --
2010-04-13  6:51 J. Bakshi
2010-04-16  9:46 ` Richard Horton
2010-04-16 10:37   ` J. Bakshi

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.