Re: Restricting source with dDNS (dynamic DNS)

Laurent Cheylus <[email protected]>
Newsgroups gmane.os.openbsd.pf
Message-ID <20091218164404.GA15765@atom>
Hi,

On Fri, Dec 18, 2009 at 03:40:36PM +0000, Jim Flowers wrote:
> To lock down services (particularly ssh) as tightly as possible, I like to allow
> administrative access to a firewall only from specific ip addresses.
> 
> Unfortunately, some of the administrators are working from dynamic ip addresses
> that change with some frequency.
> 
> Is there a straightforward way to incorporate dynamic ip source addresses in the
> pf ruleset?

- Use a table for these IP src addresses in your pass rule
- Run regularly via cron a script to resolve these dynamic IPs and
  add/modify/delete it in the src table via 'pfctl'

A++ Laurent
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.