Re: Shorewall 5.2.3.2 Events - Port Knocking
Jean-Francois Bogaerts <[email protected]>
| Newsgroups | gmane.comp.security.shorewall |
|---|---|
| Message-ID | <[email protected]> |
Hi, Indeed changing rules order fix it. SSHKnock:info net fw tcp 8123,1599-1601 REJECT net fw tcp 8123 Thanks JF Bogaerts ------------------------------------------------------------------------ On 8/12/21 08:05, Matt Darfeuille wrote: > On 12/7/2021 1:06 PM, Jean-Francois Bogaerts wrote: >> Hi, >> >> If I comment out >> >> #REJECT net fw tcp 8123 >> >> >> This port is permanently open whatever I knock 1600 or 1599 >> > > I would try putting the 'REJECT' rule after the event rule. > > Is (1) not what you want? > If no, please point to the documentation you are using. > > > 1) https://shorewall.org/Events.html#IfEvent >