Re: Service-Policies does not restrict SSH...
John Stoffel <[email protected]> Wed, 4 Jan 2023 19:16:51 -0500
| Newsgroups | gmane.comp.hardware.netapp |
|---|---|
| Message-ID | <[email protected]> |
--===============5968408622583410763== Content-Type: multipart/alternative; boundary=Apple-Mail-9CDB8929-5777-476A-904A-12FF3E3E56DD Content-Transfer-Encoding: 7bit --Apple-Mail-9CDB8929-5777-476A-904A-12FF3E3E56DD Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: quoted-printable Can=E2=80=99t you restrict the the /32 range which is just a single host? A= s for the rest, I haven=E2=80=99t a clue or any 9.12 hosts so I can=E2=80=99= t really help. =20 The real answer might be a router to block access to the management subnet/v= lan and have a jump host you need to login to to do your ssh access. Sent from my iPhone > On Jan 3, 2023, at 1:36 PM, Heino Walther <[email protected]> wrote: >=20 > =EF=BB=BF > Hi there > =20 > I am trying to restrict which IP addresses can reach the SSH port on the d= efault cluster management interface=E2=80=A6 > I first cloned the default-management service-policy to a new policy=E2=80= =A6 I then restrict the service =E2=80=9Cmanagement-ssh=E2=80=9D to a specif= ic range, say 10.0.2.0/24 > I then modify the cluster lif and the two node management interfaces, so t= hat they use my new service-policy. > But=E2=80=A6 I am still able to ssh into the system from 10.10.10.0/24=E2=80= =A6 which makes no sense at all=E2=80=A6 > If I do the same to the management-https it _does_ work as expected=E2=80=A6= > =20 > The =E2=80=9Cold=E2=80=9D firewall is enabled, and all policies are set to= 0.0.0.0/0 (I think this old firewall is depreciated=E2=80=A6 ) > =20 > So it there something specific about ssh? > (ONTAP 9.12.1) > =20 > Personally I think the =E2=80=9Cfirewall=E2=80=9D features are a mess on O= NTAP at the moment=E2=80=A6 also the fact that you can only open up for IP= ranges, and not specific IP addresses=E2=80=A6 so the =E2=80=9Cbest=E2=80=9D= you can do is /30 I guess? Why not just allow specific IP or even ranges..= like 10.10.10.5, 10.10.10.5-10, and 10.10.20.0/24 > =20 > Any help or input is appreciated =F0=9F=98=8A > =20 > /H > =20 > =20 > =20 > =20 > _______________________________________________ > Toasters mailing list > [email protected] > https://www.teaparty.net/mailman/listinfo/toasters --Apple-Mail-9CDB8929-5777-476A-904A-12FF3E3E56DD Content-Type: text/html; charset=utf-8 Content-Transfer-Encoding: quoted-printable <html><head><meta http-equiv=3D"content-type" content=3D"text/html; charset=3D= utf-8"></head><body dir=3D"auto">Can=E2=80=99t you restrict the the /32 rang= e which is just a single host? As for the rest, I haven=E2=80=99t a cl= ue or any 9.12 hosts so I can=E2=80=99t really help. <div><br></div><d= iv>The real answer might be a router to block access to the management subne= t/vlan and have a jump host you need to login to to do your ssh access.</div= ><div><br><br><div dir=3D"ltr">Sent from my iPhone</div><div dir=3D"ltr"><br= ><blockquote type=3D"cite">On Jan 3, 2023, at 1:36 PM, Heino Walther <hw@= beardmann.dk> wrote:<br><br></blockquote></div><blockquote type=3D"cite">= <div dir=3D"ltr">=EF=BB=BF <meta http-equiv=3D"Content-Type" content=3D"text/html; charset=3Dutf-8"> <meta name=3D"Generator" content=3D"Microsoft Word 15 (filtered medium)"> <style>@font-face { font-family: "Cambria Math"; } @font-face { font-family: Calibri; } p.MsoNormal, li.MsoNormal, div.MsoNormal { margin: 0cm; font-size: 11pt; fon= t-family: Calibri, sans-serif; } span.EmailStyle17 { font-family: Calibri, sans-serif; color: windowtext; } .MsoChpDefault { font-family: Calibri, sans-serif; } @page WordSection1 { size: 612pt 792pt; margin: 3cm 2cm; } div.WordSection1 { page: WordSection1; }</style> <div class=3D"WordSection1"> <p class=3D"MsoNormal"><span lang=3D"EN-US">Hi there<o:p></o:p></span></p> <p class=3D"MsoNormal"><span lang=3D"EN-US"><o:p> </o:p></span></p> <p class=3D"MsoNormal"><span lang=3D"EN-US">I am trying to restrict which IP= addresses can reach the SSH port on the default cluster management interfac= e=E2=80=A6<o:p></o:p></span></p> <p class=3D"MsoNormal"><span lang=3D"EN-US">I first cloned the default-manag= ement service-policy to a new policy=E2=80=A6 I then restrict the service =E2= =80=9Cmanagement-ssh=E2=80=9D to a specific range, say 10.0.2.0/24<o:p></o:p= ></span></p> <p class=3D"MsoNormal"><span lang=3D"EN-US">I then modify the cluster lif an= d the two node management interfaces, so that they use my new service-policy= .<o:p></o:p></span></p> <p class=3D"MsoNormal"><span lang=3D"EN-US">But=E2=80=A6 I am still able to s= sh into the system from 10.10.10.0/24=E2=80=A6 which makes no sense at= all=E2=80=A6<o:p></o:p></span></p> <p class=3D"MsoNormal"><span lang=3D"EN-US">If I do the same to the manageme= nt-https it _<i>does</i>_ work as expected=E2=80=A6<o:p></o:p></span></p> <p class=3D"MsoNormal"><span lang=3D"EN-US"><o:p> </o:p></span></p> <p class=3D"MsoNormal"><span lang=3D"EN-US">The =E2=80=9Cold=E2=80=9D firewa= ll is enabled, and all policies are set to 0.0.0.0/0 (I think this old firew= all is depreciated=E2=80=A6 )<o:p></o:p></span></p> <p class=3D"MsoNormal"><span lang=3D"EN-US"><o:p> </o:p></span></p> <p class=3D"MsoNormal"><span lang=3D"EN-US">So it there something specific a= bout ssh?<o:p></o:p></span></p> <p class=3D"MsoNormal"><span lang=3D"EN-US">(ONTAP 9.12.1)<o:p></o:p></span>= </p> <p class=3D"MsoNormal"><span lang=3D"EN-US"><o:p> </o:p></span></p> <p class=3D"MsoNormal"><span lang=3D"EN-US">Personally I think the =E2=80=9C= firewall=E2=80=9D features are a mess on ONTAP at the moment=E2=80=A6 = also the fact that you can only open up for IP ranges, and not specifi= c IP addresses=E2=80=A6 so the =E2=80=9Cbest=E2=80=9D you can do is /30 I gu= ess? Why not just allow specific IP or even ranges.. like 10.10.10.5, 10.10.10.5-10, an= d 10.10.20.0/24<o:p></o:p></span></p> <p class=3D"MsoNormal"><span lang=3D"EN-US"><o:p> </o:p></span></p> <p class=3D"MsoNormal"><span lang=3D"EN-US">Any help or input is appreciated= </span><span lang=3D"EN-US" style=3D"font-family:"Apple Color Emoji&qu= ot;">=F0=9F=98=8A</span><span lang=3D"EN-US"><o:p></o:p></span></p> <p class=3D"MsoNormal"><span lang=3D"EN-US"><o:p> </o:p></span></p> <p class=3D"MsoNormal"><span lang=3D"EN-US">/H<o:p></o:p></span></p> <p class=3D"MsoNormal"><span lang=3D"EN-US"><o:p> </o:p></span></p> <p class=3D"MsoNormal"><span lang=3D"EN-US"><o:p> </o:p></span></p> <p class=3D"MsoNormal"><span lang=3D"EN-US"><o:p> </o:p></span></p> <p class=3D"MsoNormal"><span lang=3D"EN-US"><o:p> </o:p></span></p> </div> <span>_______________________________________________</span><br><span>Toaste= rs mailing list</span><br><span>[email protected]</span><br><span>https:= //www.teaparty.net/mailman/listinfo/toasters</span></div></blockquote></div>= </body></html>= --Apple-Mail-9CDB8929-5777-476A-904A-12FF3E3E56DD-- --===============5968408622583410763== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline _______________________________________________ Toasters mailing list [email protected] https://www.teaparty.net/mailman/listinfo/toasters --===============5968408622583410763==--