Welcome to Linux Forums!

With a comprehensive Linux Forum, information on various types of Linux software and many Linux Reviews articles, we have all the knowledge you need a click away, or accessible via our knowledgeable members.

Linux Forum ArticlesLinux ForumsLinux Forum DownloadsLinux HostsFree MagazinesJobs
Home|Register|FAQ|Member List|Calendar|Unanswered Posts|Forum Rules|Today's Posts|Advanced Search|
SEARCH FOR IN
Go Back   Linux Forums > GNU Linux Zone > Servers
Reload this Page Need help with configuring hosts.allow and hosts.deny
Linux Forums
Linux Forums
Welcome To The Linux Forums!
Welcome to Linux Forums. We pride ourselves in being one of the largest Linux communities on the web, we encourage you to REGISTER on our forums and participate in the community. There are over 150,000 members ready to answer your questions. JOINING US today will allow you to make new posts, get support, send messages to other members and submit downloads to our downloads directory and many other great features!

Servers Anything server related, Apache, MySQL, Samba, server security, sendmail, exim, etc

View Poll Results: Do you prefer xinetd or tcpwrappers?
xinetd 0 0%
tcpwrappers 2 40.00%
both 1 20.00%
I just trust my firewall and pray 2 40.00%
Voters: 5. You may not vote on this poll

Reply
 
Thread Tools Display Modes
Old 07-17-2003   #1 (permalink)
Just Joined!
 
Join Date: Jul 2003
Posts: 2
Need help with configuring hosts.allow and hosts.deny

Hello ppl!

I was reading the man pages for hosts.allow and hosts.deny, but have a hard time understanding how the naming convention for services works.

I want to add ALL: ALL in hosts.deny, and add rules to hosts.allow to enable the following ports ONLY access from outside:

httpd (port 80) access to all
pop3 access
smtp access (I use qmail)
sshd
and mysqld (3306)

I also have no idea how I can tell which services are being "supervised" by tcpwrapers. If I should make all my services run through xinetd instead/as well or not.

Basically, I want to secure up my box and need some help!

Thanks a bunch,
The Mutha.
the_mutha is offline   Reply With Quote
Old 07-17-2003   #2 (permalink)
Linux Guru
 
Join Date: Apr 2003
Location: London, UK
Posts: 3,284
as far as i was aware it was only services that provided an interactive login, such as SSHD which used tcp wrappers?

I use iptables to control exactly what goes in and out from which IP addresses can access what ports etc, and i am more than confident this method provides a suitable level of security for me.

Jason
jasonlambert is offline   Reply With Quote
Old 07-17-2003   #3 (permalink)
Just Joined!
 
Join Date: Jul 2003
Posts: 2
Hows does IPTABLES work? I want to limit my machine like a firewall. I.e. only allow input for

web port
pop3 port
smtp port
ping port
mysql port (3306)
ssh port

Does iptables need a special deamon to be running, and if so, what? Please give some examples if possible.

thanks!
the_mutha is offline   Reply With Quote
Old 07-17-2003   #4 (permalink)
Linux Guru
 
Join Date: Apr 2003
Location: London, UK
Posts: 3,284
iptables is a command line tool which allows you to limit access to ports on your machine using a series of rules which you create. To fully appriciate iptables, it cannot be explained in a sentence. have a look here for a collection of howto's and tutorials:
http://www.netfilter.org/documentation/index.html#HOWTO

you may see some stuff relating to "ipchains", this is the older implementation of iptables. use iptables where possible, as it provides more features and greater control over your firewall.

Jason
jasonlambert is offline   Reply With Quote
Old 08-13-2003   #5 (permalink)
Just Joined!
 
Join Date: Aug 2003
Posts: 5
Re: Need help with configuring hosts.allow and hosts.deny

Quote:
Originally Posted by the_mutha
Hello ppl!

I was reading the man pages for hosts.allow and hosts.deny, but have a hard time understanding how the naming convention for services works.

I want to add ALL: ALL in hosts.deny, and add rules to hosts.allow to enable the following ports ONLY access from outside:

httpd (port 80) access to all
pop3 access
smtp access (I use qmail)
sshd
and mysqld (3306)

I also have no idea how I can tell which services are being "supervised" by tcpwrapers. If I should make all my services run through xinetd instead/as well or not.

Basically, I want to secure up my box and need some help!

Thanks a bunch,
The Mutha.
naming convention:
sendmail : localhost : allow
ftpd: 192.168.1.1/255.255.255.0: allow

You can only use qmail with tcp_wrapper if it's starting from inetd. Qmail recommend you do not start it that way.

Why would you want to deny web viewers to your web site?
if you must deny use the .htaccess file .

Like the other auth mentioned, IPtable is a wise choice.
notez is offline   Reply With Quote
Reply



Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off
 

Free Magazines
Cisco News
Receive a free quarterly e-newsletter with exclusive articles on how Cisco IT uses its own products and solutions to enable the business.
subscribe
Systems Management News, the newspaper for IT systems administration and data center managers!
Each issue of Systems Management News is chock-full of news and analysis to help you understand what's happening in your field.
subscribe
The Enterprise Newsweekly
eWeek is the essential technology information source for builders of e-business.
subscribe
Oracle Magazine
Oracle Magazine contains technology strategy articles, sample code, tips, Oracle and partner news, how to articles for developers and DBAs, and more. Oracle (NASDAQ: ORCL) is the world's largest enterprise software company.
subscribe
Total Telecom
Total Telecom is "The Economist of the communications industry".
subscribe
More free magazines »



All times are GMT. The time now is 02:41 AM.




© 2000 - 2008 - All Rights Reserved - Property of  MAS Media

Content Relevant URLs by vBSEO 3.2.0