Simple block of inbound ssh with exceptions

Rolf Loudon <[email protected]> Mon, 4 Dec 2017 15:17:22 +1100
Newsgroups gmane.os.openbsd.pf
Message-ID <[email protected]>
--Apple-Mail=_E90526F0-925B-45FE-A431-65E93300F720
Content-Transfer-Encoding: quoted-printable
Content-Type: text/plain;
	charset=utf-8

Hello

I=E2=80=99m both new to pf and struggling with what I thought was a =
simple idea.  This is on a laptop, not a firewall per se.  I want to (a) =
allow incoming ssh connections for a small list of addresses, and (b) =
block other inbound ssh.  No outbound restrictions at all.

Can=E2=80=99t make it work.  /etc/pf.conf:

table <mytable> { 192.168.10.13, 192.168.10.14, 192.168.100.1 }

pass in proto tcp from <mytable> port ssh
block in proto tcp from any port ssh
block in log all

I also thought that using =E2=80=98quick=E2=80=99 on the second rule =
would obviate the need for the generic last block.  So achieving it in =
two rules, just like what my specification is.

I=E2=80=99ve tried many variation.  I think I=E2=80=99m missing some =
understanding.  I know the rules are being observed because I can put in =
very basic statements like blocking a certain IP address for any service =
and that works.

Help appreciated.

r.




--Apple-Mail=_E90526F0-925B-45FE-A431-65E93300F720
Content-Transfer-Encoding: quoted-printable
Content-Type: text/html;
	charset=utf-8

<html><head><meta http-equiv=3D"Content-Type" content=3D"text/html =
charset=3Dutf-8"></head><body style=3D"word-wrap: break-word; =
-webkit-nbsp-mode: space; -webkit-line-break: after-white-space;" =
class=3D""><div style=3D"word-wrap: break-word; -webkit-nbsp-mode: =
space; -webkit-line-break: after-white-space;" class=3D"">Hello<div =
class=3D""><br class=3D""></div><div class=3D"">I=E2=80=99m both new to =
pf and struggling with what I thought was a simple idea. &nbsp;This is =
on a laptop, not a firewall per se. &nbsp;I want to (a) allow incoming =
ssh connections for a small list of addresses, and (b) block other =
inbound ssh. &nbsp;No outbound restrictions at all.</div><div =
class=3D""><br class=3D""></div><div class=3D"">Can=E2=80=99t make it =
work. &nbsp;/etc/pf.conf:</div><div class=3D""><br class=3D""></div><div =
class=3D""><div style=3D"margin: 0px; font-size: 11px; line-height: =
normal; font-family: Menlo; background-color: rgb(255, 255, 255);" =
class=3D""><span style=3D"font-variant-ligatures: no-common-ligatures" =
class=3D"">table &lt;mytable&gt; { 192.168.10.13, 192.168.10.14, =
192.168.100.1 }</span></div></div><div style=3D"margin: 0px; font-size: =
11px; line-height: normal; font-family: Menlo; background-color: =
rgb(255, 255, 255);" class=3D""><span style=3D"font-variant-ligatures: =
no-common-ligatures" class=3D""><br class=3D""></span></div><div =
class=3D""><div style=3D"margin: 0px; line-height: normal; =
background-color: rgb(255, 255, 255);" class=3D""><div style=3D"margin: =
0px; line-height: normal;" class=3D""><div style=3D"font-size: 11px; =
font-family: Menlo; margin: 0px; line-height: normal;" class=3D""><span =
style=3D"font-variant-ligatures: no-common-ligatures" class=3D"">pass in =
proto tcp from &lt;mytable&gt; port ssh</span></div><div =
style=3D"font-size: 11px; font-family: Menlo; margin: 0px; line-height: =
normal;" class=3D""><span style=3D"font-variant-ligatures: =
no-common-ligatures" class=3D"">block in proto tcp from any port =
ssh</span></div><div style=3D"font-size: 11px; font-family: Menlo; =
margin: 0px; line-height: normal;" class=3D""><span =
style=3D"font-variant-ligatures: no-common-ligatures" class=3D"">block =
in log all</span></div><div style=3D"font-size: 11px; font-family: =
Menlo; margin: 0px; line-height: normal;" class=3D""><span =
style=3D"font-variant-ligatures: no-common-ligatures" class=3D""><br =
class=3D""></span></div><div style=3D"margin: 0px; line-height: normal;" =
class=3D""><span style=3D"font-variant-ligatures: no-common-ligatures;" =
class=3D"">I also thought that using =E2=80=98<font face=3D"Menlo" =
class=3D""><span style=3D"font-size: 11px;" =
class=3D"">quick</span></font>=E2=80=99 on the second rule would obviate =
the need for the generic last block. &nbsp;So achieving it in two rules, =
just like what my specification is.</span></div><div style=3D"margin: =
0px; line-height: normal;" class=3D""><span =
style=3D"font-variant-ligatures: no-common-ligatures" class=3D""><br =
class=3D""></span></div><div style=3D"margin: 0px; line-height: normal;" =
class=3D"">I=E2=80=99ve tried many variation. &nbsp;I think I=E2=80=99m =
missing some understanding. &nbsp;I know the rules are being observed =
because I can put in very basic statements like blocking a certain IP =
address for any service and that works.</div><div style=3D"margin: 0px; =
line-height: normal;" class=3D""><br class=3D""></div><div =
style=3D"margin: 0px; line-height: normal;" class=3D"">Help =
appreciated.</div><div style=3D"font-size: 11px; font-family: Menlo; =
margin: 0px; line-height: normal;" class=3D""><br class=3D""></div><div =
style=3D"font-size: 11px; font-family: Menlo; margin: 0px; line-height: =
normal;" class=3D"">r.</div><div style=3D"font-size: 11px; font-family: =
Menlo; margin: 0px; line-height: normal;" class=3D""><br =
class=3D""></div><div style=3D"font-size: 11px; font-family: Menlo; =
margin: 0px; line-height: normal;" class=3D""><br class=3D""></div><div =
style=3D"font-size: 11px; font-family: Menlo; margin: 0px; line-height: =
normal;" class=3D""><br =
class=3D""></div></div></div></div></div></body></html>=

--Apple-Mail=_E90526F0-925B-45FE-A431-65E93300F720--