Re: Service-Policies does not restrict SSH...

John Stoffel <[email protected]> Wed, 4 Jan 2023 19:16:51 -0500
Newsgroups gmane.comp.hardware.netapp
Message-ID <[email protected]>
--===============5968408622583410763==
Content-Type: multipart/alternative; boundary=Apple-Mail-9CDB8929-5777-476A-904A-12FF3E3E56DD
Content-Transfer-Encoding: 7bit


--Apple-Mail-9CDB8929-5777-476A-904A-12FF3E3E56DD
Content-Type: text/plain;
	charset=utf-8
Content-Transfer-Encoding: quoted-printable

Can=E2=80=99t you restrict the the /32 range which is just a single host?  A=
s for the rest, I haven=E2=80=99t a clue or any 9.12 hosts so I can=E2=80=99=
t really help. =20

The real answer might be a router to block access to the management subnet/v=
lan and have a jump host you need to login to to do your ssh access.


Sent from my iPhone

> On Jan 3, 2023, at 1:36 PM, Heino Walther <[email protected]> wrote:
>=20
> =EF=BB=BF
> Hi there
> =20
> I am trying to restrict which IP addresses can reach the SSH port on the d=
efault cluster management interface=E2=80=A6
> I first cloned the default-management service-policy to a new policy=E2=80=
=A6 I then restrict the service =E2=80=9Cmanagement-ssh=E2=80=9D to a specif=
ic range, say 10.0.2.0/24
> I then modify the cluster lif and the two node management interfaces, so t=
hat they use my new service-policy.
> But=E2=80=A6 I am still able to ssh into the system from 10.10.10.0/24=E2=80=
=A6  which makes no sense at all=E2=80=A6
> If I do the same to the management-https it _does_ work as expected=E2=80=A6=

> =20
> The =E2=80=9Cold=E2=80=9D firewall is enabled, and all policies are set to=
 0.0.0.0/0 (I think this old firewall is depreciated=E2=80=A6 )
> =20
> So it there something specific about ssh?
> (ONTAP 9.12.1)
> =20
> Personally I think the =E2=80=9Cfirewall=E2=80=9D features are a mess on O=
NTAP at the moment=E2=80=A6   also the fact that you can only open up for IP=
 ranges, and not specific IP addresses=E2=80=A6 so the =E2=80=9Cbest=E2=80=9D=
 you can do is /30 I guess?  Why not just allow specific IP or even ranges..=
  like 10.10.10.5, 10.10.10.5-10, and 10.10.20.0/24
> =20
> Any help or input is appreciated =F0=9F=98=8A
> =20
> /H
> =20
> =20
> =20
> =20
> _______________________________________________
> Toasters mailing list
> [email protected]
> https://www.teaparty.net/mailman/listinfo/toasters

--Apple-Mail-9CDB8929-5777-476A-904A-12FF3E3E56DD
Content-Type: text/html;
	charset=utf-8
Content-Transfer-Encoding: quoted-printable

<html><head><meta http-equiv=3D"content-type" content=3D"text/html; charset=3D=
utf-8"></head><body dir=3D"auto">Can=E2=80=99t you restrict the the /32 rang=
e which is just a single host? &nbsp;As for the rest, I haven=E2=80=99t a cl=
ue or any 9.12 hosts so I can=E2=80=99t really help. &nbsp;<div><br></div><d=
iv>The real answer might be a router to block access to the management subne=
t/vlan and have a jump host you need to login to to do your ssh access.</div=
><div><br><br><div dir=3D"ltr">Sent from my iPhone</div><div dir=3D"ltr"><br=
><blockquote type=3D"cite">On Jan 3, 2023, at 1:36 PM, Heino Walther &lt;hw@=
beardmann.dk&gt; wrote:<br><br></blockquote></div><blockquote type=3D"cite">=
<div dir=3D"ltr">=EF=BB=BF

<meta http-equiv=3D"Content-Type" content=3D"text/html; charset=3Dutf-8">
<meta name=3D"Generator" content=3D"Microsoft Word 15 (filtered medium)">
<style>@font-face { font-family: "Cambria Math"; }
@font-face { font-family: Calibri; }
p.MsoNormal, li.MsoNormal, div.MsoNormal { margin: 0cm; font-size: 11pt; fon=
t-family: Calibri, sans-serif; }
span.EmailStyle17 { font-family: Calibri, sans-serif; color: windowtext; }
.MsoChpDefault { font-family: Calibri, sans-serif; }
@page WordSection1 { size: 612pt 792pt; margin: 3cm 2cm; }
div.WordSection1 { page: WordSection1; }</style>


<div class=3D"WordSection1">
<p class=3D"MsoNormal"><span lang=3D"EN-US">Hi there<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-US"><o:p>&nbsp;</o:p></span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-US">I am trying to restrict which IP=
 addresses can reach the SSH port on the default cluster management interfac=
e=E2=80=A6<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-US">I first cloned the default-manag=
ement service-policy to a new policy=E2=80=A6 I then restrict the service =E2=
=80=9Cmanagement-ssh=E2=80=9D to a specific range, say 10.0.2.0/24<o:p></o:p=
></span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-US">I then modify the cluster lif an=
d the two node management interfaces, so that they use my new service-policy=
.<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-US">But=E2=80=A6 I am still able to s=
sh into the system from 10.10.10.0/24=E2=80=A6&nbsp; which makes no sense at=
 all=E2=80=A6<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-US">If I do the same to the manageme=
nt-https it _<i>does</i>_ work as expected=E2=80=A6<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-US"><o:p>&nbsp;</o:p></span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-US">The =E2=80=9Cold=E2=80=9D firewa=
ll is enabled, and all policies are set to 0.0.0.0/0 (I think this old firew=
all is depreciated=E2=80=A6 )<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-US"><o:p>&nbsp;</o:p></span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-US">So it there something specific a=
bout ssh?<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-US">(ONTAP 9.12.1)<o:p></o:p></span>=
</p>
<p class=3D"MsoNormal"><span lang=3D"EN-US"><o:p>&nbsp;</o:p></span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-US">Personally I think the =E2=80=9C=
firewall=E2=80=9D features are a mess on ONTAP at the moment=E2=80=A6 &nbsp;=
&nbsp;also the fact that you can only open up for IP ranges, and not specifi=
c IP addresses=E2=80=A6 so the =E2=80=9Cbest=E2=80=9D you can do is /30 I gu=
ess?&nbsp; Why not just
 allow specific IP or even ranges.. &nbsp;like 10.10.10.5, 10.10.10.5-10, an=
d 10.10.20.0/24<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-US"><o:p>&nbsp;</o:p></span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-US">Any help or input is appreciated=
 </span><span lang=3D"EN-US" style=3D"font-family:&quot;Apple Color Emoji&qu=
ot;">=F0=9F=98=8A</span><span lang=3D"EN-US"><o:p></o:p></span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-US"><o:p>&nbsp;</o:p></span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-US">/H<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-US"><o:p>&nbsp;</o:p></span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-US"><o:p>&nbsp;</o:p></span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-US"><o:p>&nbsp;</o:p></span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-US"><o:p>&nbsp;</o:p></span></p>
</div>


<span>_______________________________________________</span><br><span>Toaste=
rs mailing list</span><br><span>[email protected]</span><br><span>https:=
//www.teaparty.net/mailman/listinfo/toasters</span></div></blockquote></div>=
</body></html>=

--Apple-Mail-9CDB8929-5777-476A-904A-12FF3E3E56DD--

--===============5968408622583410763==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________
Toasters mailing list
[email protected]
https://www.teaparty.net/mailman/listinfo/toasters
--===============5968408622583410763==--