diff --git a/docs/PortKnocking.xml b/docs/PortKnocking.xml index 84dba1eca..78bbb11cf 100644 --- a/docs/PortKnocking.xml +++ b/docs/PortKnocking.xml @@ -131,13 +131,13 @@ add_rule( $chainref, '-p tcp --dport 1601 -m recent --name Internet, add this rule in /etc/shorewall/rules: - #ACTION SOURCE DEST PROTO DEST PORT(S) + #ACTION SOURCE DEST PROTO DPORT SSHKnock net $FW tcp 22,1599,1600,1601 If you want to log the DROPs and ACCEPTs done by SSHKnock, you can just add a log level as in: - #ACTION SOURCE DEST PROTO DEST PORT(S) + #ACTION SOURCE DEST PROTO DPORT SSHKnock:info net $FW tcp 22,1599,1600,1601 @@ -146,8 +146,7 @@ SSHKnock:info net $FW tcp 22,1599,1600,1601< 206.124.146.178 to internal system 192.168.1.5. In /etc/shorewall/rules: - #ACTION SOURCE DEST PROTO DEST PORT(S) SOURCE ORIGINAL -# PORT(S) DEST + #ACTION SOURCE DEST PROTO DPORT SPORT ORIGDEST DNAT- net 192.168.1.5 tcp 22 - 206.124.146.178 SSHKnock net $FW tcp 1599,1600,1601 SSHKnock net loc:192.168.1.5 tcp 22 - 206.124.146.178