Add Comment

You are not currently logged in. If you do not have a user account then please consider creating one and logging in before you post your comment. This will allow you to track replies to your comment, and take part in the site much more freely.

To add your comment, fill in all the boxes below and then preview it to make sure you're happy with the way that it looks.

This is the comment you were replying to, attached to the article Multiple-port knocking Netfilter/IPtables only implementation:


Re: Multiple-port knocking Netfilter/IPtables only implementation
Posted by love_linux (62.30.xx.xx) on Mon 5 Feb 2007 at 23:46
basely, in shorewall, you are going to do the same thing as the example from above. you just have to change to iptable to run_iptables in SSHKnock (shorewall) and add a extra recent name in rule. thats all. if you want more security then, you could go to shorewall's official website, there is an example there that tell you exactly what you have to do to avoid port scan.
because, for the method that shows in above, it could not avoid port scan.

people could detect your sequence quit easily..
i had both multiple ports knocking and the method to avoid port scan setup in my laptop and server, it works very good.

I love shorewall. its a great tool to use.
if you need the configuration file, you could leave a msg here.



Username:Anonymous
Title:
Your Comment:

Posting Format:

 

Inappropriate comments will be removed.

Some help on entry formatting is available

User Login

Username:

Password:

[ Advanced Login ]

Register Account

Quick Site Search