/* HINT: Search archives @ http://www.indyramp.com/masq/ before posting! */
On Wed, 8 Mar 2000, Jason Bradley Nance wrote:
> ALL : ALL : spawn (/bin/mail root -s "%d - denied connect from %u@%h (%a)")
The spawn is quite unnecessary, as tcpd makes the appropriate logs in
syslog. You _do_ read your logs, don't you? =)
> There is no excuse not to deny everyone then explicitly allow those you want
> to have access..
Agreed, but his original question was how to deny telnet. Had he asked
how to secure his system using tcp wrappers, ALL:ALL would have been the
first thing out of my mouth.
Sean
> -----Original Message-----
> From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED]]On Behalf
> Of Sean A. Walberg
> Sent: Wednesday, March 08, 2000 12:29 PM
> To: Edmund Craske
> Cc: Ronneil Camara; [EMAIL PROTECTED]
> Subject: Re: [Masq] Blocking of telnet traffic internally
>
>
> /* HINT: Search archives @ http://www.indyramp.com/masq/ before posting! */
>
>
> If you're going to do it that way, then you'll want
>
> in.telnetd:ALL
>
> in /etc/hosts.deny
>
> Sean
>
> On Wed, 8 Mar 2000, Edmund Craske wrote:
>
> > /* HINT: Search archives @ http://www.indyramp.com/masq/ before posting!
> */
> >
> >
> > you should be able to set up /etc/hosts.allow with this:
> > in.telnetd : <ip u want to give access to>
> > im not certain tho.... any other readers that can back me up?
> > Edmund Craske
> > ----- Original Message -----
> > From: "Ronneil Camara" <[EMAIL PROTECTED]>
> > To: <[EMAIL PROTECTED]>
> > Sent: Wednesday, March 08, 2000 4:17 PM
> > Subject: [Masq] Blocking of telnet traffic internally
> >
> >
> > > /* HINT: Search archives @ http://www.indyramp.com/masq/ before posting!
> > */
> > >
> > >
> > > Hi. I've used the ipchains script that was written by Trinity. Actually,
> > > here is the link
> > >
> >
> http://www.ecst.csuchico.edu/~dranch/LINUX/TrinityOS-files/rc.firewall-trini
> > > tyos
> > > where I downloaded it. My telnet is ok if someone is going to telnet
> my
> > > linux from an outside host, it is REJECTED. My problem is, I would like
> to
> > > limit only specific ip address internally to telnet to my linux. I have
> > > assigned a number of hosts in the script but still, everybody in my lan
> > can
> > > telnet to it. What seems to be the problem? I would want in such a way
> > that
> > > only specified host internally will be able to telnet to my linux and
> > others
> > > will be REJECTED.
> > >
> > > _______________________________________________
> > > Masq maillist - [EMAIL PROTECTED]
> > > Admin requests can be handled at http://www.indyramp.com/masq-list/ --
> > THIS INCLUDES UNSUBSCRIBING!
> > > or email to [EMAIL PROTECTED]
> > >
> > > PLEASE read the HOWTO and search the archives before posting.
> > > You can start your search at http://www.indyramp.com/masq/
> > > Please keep general linux/unix/pc/internet questions off the list.
> >
> > _______________________________________________
> > Masq maillist - [EMAIL PROTECTED]
> > Admin requests can be handled at http://www.indyramp.com/masq-list/ --
> THIS INCLUDES UNSUBSCRIBING!
> > or email to [EMAIL PROTECTED]
> >
> > PLEASE read the HOWTO and search the archives before posting.
> > You can start your search at http://www.indyramp.com/masq/
> > Please keep general linux/unix/pc/internet questions off the list.
> >
>
> -------------------------------------------------------------------
> Sean Walberg <[EMAIL PROTECTED]> http://www.escape.ca/~sean
> "Fore yeers ago I kudn't spel Engineer. Now I are won."
>
> _______________________________________________
> Masq maillist - [EMAIL PROTECTED]
> Admin requests can be handled at http://www.indyramp.com/masq-list/ -- THIS
> INCLUDES UNSUBSCRIBING!
> or email to [EMAIL PROTECTED]
>
> PLEASE read the HOWTO and search the archives before posting.
> You can start your search at http://www.indyramp.com/masq/
> Please keep general linux/unix/pc/internet questions off the list.
>
>
-------------------------------------------------------------------
Sean Walberg <[EMAIL PROTECTED]> http://www.escape.ca/~sean
"Fore yeers ago I kudn't spel Engineer. Now I are won."
_______________________________________________
Masq maillist - [EMAIL PROTECTED]
Admin requests can be handled at http://www.indyramp.com/masq-list/ -- THIS INCLUDES
UNSUBSCRIBING!
or email to [EMAIL PROTECTED]
PLEASE read the HOWTO and search the archives before posting.
You can start your search at http://www.indyramp.com/masq/
Please keep general linux/unix/pc/internet questions off the list.