請問如何用防火牆限制telnet的登入ip? - BBS
By George
at 2005-09-29T16:54
at 2005-09-29T16:54
Table of Contents
※ 引述《[email protected] (悸動)》之銘言:
: ※ 引述《[email protected] (PP )》之銘言:
: > /sbin/ipfw add pass tcp from IP to me 23
: > /sbin/ipfw add deny all from any to any
: 翻一下任何一本講 TCP connection 連線過程的書,要知道 TCP connection
: 怎麼建立的,還有,要瞭解 TCP 是雙向傳輸...。
: # allow local interface
: ${fwcmd} add allow ip from any to any via lo0
: ${fwcmd} add deny ip from 127.0.0.0/8 to any
: # pass outgoing packet
: ${fwcmd} add allow ip from any to any out
: # pass established
: ${fwcmd} add allow tcp from any to any established
: # pass 140.113.27.50 to me (SYN)
: ${fwcmd} add allow tcp from 140.113.27.50 to me 23 setup
: # deny telnet
: ${fwcmd} add deny tcp from any to me 23
謝謝各位大大指教,
改成
/sbin/ipfw add pass tcp from 140.122.65.54 to me 23
/sbin/ipfw add deny tcp from any to me 23
就可以了。
其他方法我也會去試看看,感謝各位:)
----
原來玩freebsd的都是好人:)
--
: ※ 引述《[email protected] (PP )》之銘言:
: > /sbin/ipfw add pass tcp from IP to me 23
: > /sbin/ipfw add deny all from any to any
: 翻一下任何一本講 TCP connection 連線過程的書,要知道 TCP connection
: 怎麼建立的,還有,要瞭解 TCP 是雙向傳輸...。
: # allow local interface
: ${fwcmd} add allow ip from any to any via lo0
: ${fwcmd} add deny ip from 127.0.0.0/8 to any
: # pass outgoing packet
: ${fwcmd} add allow ip from any to any out
: # pass established
: ${fwcmd} add allow tcp from any to any established
: # pass 140.113.27.50 to me (SYN)
: ${fwcmd} add allow tcp from 140.113.27.50 to me 23 setup
: # deny telnet
: ${fwcmd} add deny tcp from any to me 23
謝謝各位大大指教,
改成
/sbin/ipfw add pass tcp from 140.122.65.54 to me 23
/sbin/ipfw add deny tcp from any to me 23
就可以了。
其他方法我也會去試看看,感謝各位:)
----
原來玩freebsd的都是好人:)
--
Tags:
BBS
All Comments
Related Posts
請問如何用防火牆限制telnet的登入ip?
By Eden
at 2005-09-29T14:17
at 2005-09-29T14:17
請問如何用防火牆限制telnet的登入ip?
By Irma
at 2005-09-29T10:18
at 2005-09-29T10:18
Re: 有人安裝過xfce嗎???
By Mary
at 2005-09-29T02:00
at 2005-09-29T02:00
內建的ftpd怪怪的
By Wallis
at 2005-09-29T01:39
at 2005-09-29T01:39
Re: 有人安裝過xfce嗎???
By Edward Lewis
at 2005-09-29T01:28
at 2005-09-29T01:28