SUMMARY: Port restriction according to source IP... ?

From: selcuk karaca (selcuk.karaca_at_aski.gov.tr)
Date: 05/12/03

  • Next message: Frati, Louis: "ASE on Tru64 v5.1b"
    Date: Mon, 12 May 2003 14:05:06 +0300
    To: tru64-unix-managers@ornl.gov
    
    

    Thanks to ;

    Iain Barker
    Christian Wessely
    George Gallen
    EuBank, Chris
    Martin Adolfsson

    for their helpfull suggestions ...

    Suggestions:
    ***screend***

    ***tcpwrappers***
     For usable info look at :
    http://www.porcupine.org/wietse/hints-and-tips.html

    I have learned that it works in my case..

    IPFilter: (IPFilter is an open source firewalling/NAT software.)
    It says
    You can get it from: http://coombs.anu.edu.au/~avalon/

    In the how-to file, I've found the following...

         A long time ago at a university far, far away, Wietse
    Venema created the tcp-wrapper package, and ever since, it's
    been used to add a layer of protection to network services
    all over the world. This is good. But, tcp-wrappers have
    flaws. For starters, they only protect TCP services, as the
    name suggests. Also, unless you run your service from
    inetd, or you have specifically compiled it with libwrap and
    the appropriate hooks, your service isn't protected. This
    leaves gigantic holes in your host security....

    FireWall:
    Firewall is also suggested...

    I have chosen the IPFilter option...

    Thanks for your answers...

    ------------------------------------------
    My question WAS:

    Hello admins..

    My system:
    ES40 - Tru64Unix V5.1

    I need to restrict the port access of a certain IP (or subnet..)
    For example if the source IP is 192.168.100.5 then, I want to restrict port
    access to 80..The source PC can not access other ports (ftp,telnet etc..)

    But other IPs should access any port..

    Can I do this with Tru64 ..?

    TIA..

    Selcuk KARACA
    Unix System Administrator
    Turkiye


  • Next message: Frati, Louis: "ASE on Tru64 v5.1b"

    Relevant Pages

    • Re: Port 25 blocked?
      ... > I have taken the following lines from "Using McAfee VirusScan" ... > VSE 8.0i has new intrusion protection features such as port blocking used ... > firewalls and protection for files, ... >> WindowsServer2003 Firewall is off. ...
      (microsoft.public.windows.server.networking)
    • Re: Question for the Group
      ... And those who claim security are doing better than VMS. ... Eg If you are running a publically accessible webserver on port 80 then you ... vulnerabilities then the firewall provides zero protection. ...
      (comp.os.vms)
    • Re: <How do I close port 80 and still surf the internet?>
      ... > Now everything is stealth but port 80, ... If Kerio is a packet filtering firewall, then it should not matter and I ... The stealth thing is overrated. ... layered protection approach and not depend upon Kerio's sole protection. ...
      (comp.security.firewalls)
    • Re: Port 25 blocked?
      ... firewalls and protection for files, ... Under Port Blocking, you can specify rules to block a port or group of ports ... > WindowsServer2003 Firewall is off. ...
      (microsoft.public.windows.server.networking)
    • Re: best firewall option for FreeBSD
      ... > I have to build a firewall for our University with 2 NIC's. ... For your case I would you ipfilter. ... network to external ftp-server" - because it will use more than one port. ... An Exchange server in the internet without firewall (and securing Windows ...
      (FreeBSD-Security)