Limiting host access per network interface

From: Claudio Lapidus <clapidus_at_hotmail.com>
Date: Mon, 01 Jul 2002 19:51:55 -0300

Hello,

I have an XP900 box running 4.0F, which is connected to an internal network
through tu0 and to the Internet through tu1. Now the problem is that I want
to be VERY restrictive on the services offered to the public side, while
being more open to the internal network clients. I was unable to find a way
to limit access to diverse services based on interface or in source address,
the way tcp-wrappers in other platforms do. Can any of you people please
give some advice on this?

BTW, I also tried editing ifaccess.conf, but it doesn't seem to be working
at all. Actually, I was able to log in from a "forbidden" source address.

# cat /etc/ifaccess.conf | grep -v '^#'

tu1 zzz.aa.bb.6 255.255.255.255 permit
tu1 zzz.cc.dd.8 255.255.255.255 permit
tu1 zzz.ee.ff.13 255.255.255.255 permit
tu1 0.0.0.0 0.0.0.0 deny
#


regards,
cl.
clapidus_at_hotmail.com


_________________________________________________________________
Join the world’s largest e-mail service with MSN Hotmail.
http://www.hotmail.com
Received on Mon Jul 01 2002 - 22:52:06 NZST

This archive was generated by hypermail 2.4.0 : Wed Nov 08 2023 - 11:53:43 NZDT