Simple block of inbound ssh with exceptions
Rolf Loudon <[email protected]> Mon, 4 Dec 2017 15:17:22 +1100
| Newsgroups | gmane.os.openbsd.pf |
|---|---|
| Message-ID | <[email protected]> |
--Apple-Mail=_E90526F0-925B-45FE-A431-65E93300F720
Content-Transfer-Encoding: quoted-printable
Content-Type: text/plain;
charset=utf-8
Hello
I=E2=80=99m both new to pf and struggling with what I thought was a =
simple idea. This is on a laptop, not a firewall per se. I want to (a) =
allow incoming ssh connections for a small list of addresses, and (b) =
block other inbound ssh. No outbound restrictions at all.
Can=E2=80=99t make it work. /etc/pf.conf:
table <mytable> { 192.168.10.13, 192.168.10.14, 192.168.100.1 }
pass in proto tcp from <mytable> port ssh
block in proto tcp from any port ssh
block in log all
I also thought that using =E2=80=98quick=E2=80=99 on the second rule =
would obviate the need for the generic last block. So achieving it in =
two rules, just like what my specification is.
I=E2=80=99ve tried many variation. I think I=E2=80=99m missing some =
understanding. I know the rules are being observed because I can put in =
very basic statements like blocking a certain IP address for any service =
and that works.
Help appreciated.
r.
--Apple-Mail=_E90526F0-925B-45FE-A431-65E93300F720
Content-Transfer-Encoding: quoted-printable
Content-Type: text/html;
charset=utf-8
<html><head><meta http-equiv=3D"Content-Type" content=3D"text/html =
charset=3Dutf-8"></head><body style=3D"word-wrap: break-word; =
-webkit-nbsp-mode: space; -webkit-line-break: after-white-space;" =
class=3D""><div style=3D"word-wrap: break-word; -webkit-nbsp-mode: =
space; -webkit-line-break: after-white-space;" class=3D"">Hello<div =
class=3D""><br class=3D""></div><div class=3D"">I=E2=80=99m both new to =
pf and struggling with what I thought was a simple idea. This is =
on a laptop, not a firewall per se. I want to (a) allow incoming =
ssh connections for a small list of addresses, and (b) block other =
inbound ssh. No outbound restrictions at all.</div><div =
class=3D""><br class=3D""></div><div class=3D"">Can=E2=80=99t make it =
work. /etc/pf.conf:</div><div class=3D""><br class=3D""></div><div =
class=3D""><div style=3D"margin: 0px; font-size: 11px; line-height: =
normal; font-family: Menlo; background-color: rgb(255, 255, 255);" =
class=3D""><span style=3D"font-variant-ligatures: no-common-ligatures" =
class=3D"">table <mytable> { 192.168.10.13, 192.168.10.14, =
192.168.100.1 }</span></div></div><div style=3D"margin: 0px; font-size: =
11px; line-height: normal; font-family: Menlo; background-color: =
rgb(255, 255, 255);" class=3D""><span style=3D"font-variant-ligatures: =
no-common-ligatures" class=3D""><br class=3D""></span></div><div =
class=3D""><div style=3D"margin: 0px; line-height: normal; =
background-color: rgb(255, 255, 255);" class=3D""><div style=3D"margin: =
0px; line-height: normal;" class=3D""><div style=3D"font-size: 11px; =
font-family: Menlo; margin: 0px; line-height: normal;" class=3D""><span =
style=3D"font-variant-ligatures: no-common-ligatures" class=3D"">pass in =
proto tcp from <mytable> port ssh</span></div><div =
style=3D"font-size: 11px; font-family: Menlo; margin: 0px; line-height: =
normal;" class=3D""><span style=3D"font-variant-ligatures: =
no-common-ligatures" class=3D"">block in proto tcp from any port =
ssh</span></div><div style=3D"font-size: 11px; font-family: Menlo; =
margin: 0px; line-height: normal;" class=3D""><span =
style=3D"font-variant-ligatures: no-common-ligatures" class=3D"">block =
in log all</span></div><div style=3D"font-size: 11px; font-family: =
Menlo; margin: 0px; line-height: normal;" class=3D""><span =
style=3D"font-variant-ligatures: no-common-ligatures" class=3D""><br =
class=3D""></span></div><div style=3D"margin: 0px; line-height: normal;" =
class=3D""><span style=3D"font-variant-ligatures: no-common-ligatures;" =
class=3D"">I also thought that using =E2=80=98<font face=3D"Menlo" =
class=3D""><span style=3D"font-size: 11px;" =
class=3D"">quick</span></font>=E2=80=99 on the second rule would obviate =
the need for the generic last block. So achieving it in two rules, =
just like what my specification is.</span></div><div style=3D"margin: =
0px; line-height: normal;" class=3D""><span =
style=3D"font-variant-ligatures: no-common-ligatures" class=3D""><br =
class=3D""></span></div><div style=3D"margin: 0px; line-height: normal;" =
class=3D"">I=E2=80=99ve tried many variation. I think I=E2=80=99m =
missing some understanding. I know the rules are being observed =
because I can put in very basic statements like blocking a certain IP =
address for any service and that works.</div><div style=3D"margin: 0px; =
line-height: normal;" class=3D""><br class=3D""></div><div =
style=3D"margin: 0px; line-height: normal;" class=3D"">Help =
appreciated.</div><div style=3D"font-size: 11px; font-family: Menlo; =
margin: 0px; line-height: normal;" class=3D""><br class=3D""></div><div =
style=3D"font-size: 11px; font-family: Menlo; margin: 0px; line-height: =
normal;" class=3D"">r.</div><div style=3D"font-size: 11px; font-family: =
Menlo; margin: 0px; line-height: normal;" class=3D""><br =
class=3D""></div><div style=3D"font-size: 11px; font-family: Menlo; =
margin: 0px; line-height: normal;" class=3D""><br class=3D""></div><div =
style=3D"font-size: 11px; font-family: Menlo; margin: 0px; line-height: =
normal;" class=3D""><br =
class=3D""></div></div></div></div></div></body></html>=
--Apple-Mail=_E90526F0-925B-45FE-A431-65E93300F720--