how to drop ssh-attacks in SuSEfirewall2?
Subject is the question. I have been trying to use the ipt_recent module, but if i insert rules in /etc/sysconfig/scripts/SuSEfirewall-custom it does not work. Problem is possibly the order in which rules are processed, I guess iptables does not reach my rules and has accepted traffic before hitting them. I tried putting my rules in all locations in the -custom file, to no avail. -- L. de Braal BraHa Systems NL - Terneuzen T +31 115 649333 F +31 115 649444
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Leen de Braal schrieb:
Subject is the question.
I have been trying to use the ipt_recent module, but if i insert rules in /etc/sysconfig/scripts/SuSEfirewall-custom it does not work. Problem is possibly the order in which rules are processed, I guess iptables does not reach my rules and has accepted traffic before hitting them. I tried putting my rules in all locations in the -custom file, to no avail.
You have to enable this in /etc/sysconfig/SuSEfirewall2 at the end of the file (uncomment location of custom file). For me custom rules do work propper, but you have to know how SF2 works that this rules take any effect. You can't just put some rules into some chains if you don't know where this takes effect in SF2 init-script. Reguards Philippe - -- Diese Nachricht ist digital signiert und enthält weder Siegel noch Unterschrift! Die unaufgeforderte Zusendung einer Werbemail an Privatleute verstößt gegen §1 UWG und 823 I BGB (Beschluß des LG Berlin vom 2.8.1998 Az: 16 O 201/98). Jede kommerzielle Nutzung der übermittelten persönlichen Daten sowie deren Weitergabe an Dritte ist ausdrücklich untersagt! -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.2.1 (MingW32) Comment: Using GnuPG with Thunderbird - http://enigmail.mozdev.org iQD1AwUBQrLI/kNg1DRVIGjBAQJjewb8D5Y8kUwOByva+eJDNf2+VQlkWTfuBdl1 lFlqi0jv9CE7zA9yNgWBq6B0Ne5G7I2XfXLjxwxA3XgcBugmmV/Epq9vQfzYLreJ WcodwqvjjqDdOYjoCL0L7k9Wf2SFQVR0QyRLzSP4kR0xlNJ5zx/W4dz+sHC876CF r/kIdK5B/ZpieHPDpv3o4b2SEEkWrMxLzvfq3AmcfbXCRVrYFAScIH07BbRoZGvH Xedb+t6wwhEIScwAD/zsHQbT8lqkbMkfgDMNQX6XEFv5OLzEG9gghmv1yNEwemO4 VDjjSrSFm5A= =kheA -----END PGP SIGNATURE-----
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1
You have to enable this in /etc/sysconfig/SuSEfirewall2 at the end of the file (uncomment location of custom file).
For me custom rules do work propper, but you have to know how SF2 works that this rules take any effect. You can't just put some rules into some chains if you don't know where this takes effect in SF2 init-script.
I will study sfw2 scripts first then. Thks for the hint
Reguards
Philippe
- --
-- L. de Braal BraHa Systems NL - Terneuzen T +31 115 649333 F +31 115 649444
participants (2)
-
Leen de Braal
-
Philippe Vogel