LinuxQuestions.org
Latest LQ Deal: Latest LQ Deals
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 12-04-2014, 01:13 AM   #1
D0zer
Member
 
Registered: Jul 2014
Location: Johannesburg, South Africa
Distribution: Gentoo
Posts: 30

Rep: Reputation: Disabled
hosts.deny vs arno ip tables blocked hosts


Hi All

A client of mine has a mail server running Gentoo, it has Arno Ip tables installed for the firewall. The person who setup up the server had not loaded anything to block IP addresses with failed login attempts.

I am using denyhosts to block offending IP address. Its amazing how many attempts from people there are to log into the server.

Dnyhosts adds the offending IP addresses to hosts.deny. I have taken to also adding ip's to the blocked hosts in arno ip tables when I have seen attempts in the log files.

Which is the better place to do it? I manually restart Arno Ip tables each time I add an ip address there.

Is it possible to block IP addresses using wildcards. I want to essentially block all attempts from, 103.41.x.x. I have noticed a pattern where the last part of the IP address changes so ideally I want to block all ip address in that range.

Thanks in Advance
 
Old 12-04-2014, 12:36 PM   #2
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
Quote:
Originally Posted by D0zer View Post
Which is the better place to do it?
Obviously Netfilter. Also see Denyhosts vs Fail2ban aka tcp_wrappers vs iptables.


Quote:
Originally Posted by D0zer View Post
I manually restart Arno Ip tables each time I add an ip address there.
Not necessary.


Quote:
Originally Posted by D0zer View Post
Is it possible to block IP addresses using wildcards. I want to essentially block all attempts from, 103.41.x.x. I have noticed a pattern where the last part of the IP address changes so ideally I want to block all ip address in that range.
See man ipset ('ipset create myset hash:net').
 
1 members found this post helpful.
Old 12-07-2014, 02:07 AM   #3
D0zer
Member
 
Registered: Jul 2014
Location: Johannesburg, South Africa
Distribution: Gentoo
Posts: 30

Original Poster
Rep: Reputation: Disabled
Thanks for suggestions unSpawn.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
/etc/hosts.deny not blocking hosts from using NFS - Centos m223464 Linux - Security 3 05-10-2012 08:54 PM
Access denied for NFS - but hosts.allow and hosts.deny seem OK royce2020 Linux - Networking 4 10-17-2011 10:44 PM
can't restrict sshd access through hosts.allow and hosts.deny but was working earlier farhan Linux - Security 4 04-18-2008 07:41 AM
/etc/hosts.deny/hosts.allow have no effect on sshd access bganesh Linux - Security 4 05-04-2006 08:06 PM
Adding shell commands to hosts.deny and hosts.allow ridertech Linux - Security 3 12-29-2003 03:52 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 06:46 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration