Re: Shorewall 5.2.3.2 Events - Port Knocking

Jean-Francois Bogaerts <[email protected]>
Newsgroups gmane.comp.security.shorewall
Message-ID <[email protected]>
Hi,

Indeed changing rules order fix it.

SSHKnock:info   net               fw            tcp 8123,1599-1601
REJECT  net     fw      tcp     8123

Thanks


JF Bogaerts
------------------------------------------------------------------------
On 8/12/21 08:05, Matt Darfeuille wrote:
> On 12/7/2021 1:06 PM, Jean-Francois Bogaerts wrote:
>> Hi,
>>
>> If I comment out
>>
>> #REJECT  net     fw      tcp     8123
>>
>>
>> This port is permanently open whatever I knock 1600 or 1599
>>
>
> I would try putting the 'REJECT' rule after the event rule.
>
> Is (1) not what you want?
> If no, please point to the documentation you are using.
>
>
> 1)  https://shorewall.org/Events.html#IfEvent
>
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.