From 4050aa5180192d0c3f8ef2e1f29d45d42ff53b2e Mon Sep 17 00:00:00 2001 From: Tom Eastep Date: Thu, 18 Feb 2016 15:54:32 -0800 Subject: [PATCH] Update the Port Knocking article for 5.0 Signed-off-by: Tom Eastep --- docs/PortKnocking.xml | 7 +++---- 1 file changed, 3 insertions(+), 4 deletions(-) diff --git a/docs/PortKnocking.xml b/docs/PortKnocking.xml index 84dba1eca..78bbb11cf 100644 --- a/docs/PortKnocking.xml +++ b/docs/PortKnocking.xml @@ -131,13 +131,13 @@ add_rule( $chainref, '-p tcp --dport 1601 -m recent --name Internet, add this rule in /etc/shorewall/rules: - #ACTION SOURCE DEST PROTO DEST PORT(S) + #ACTION SOURCE DEST PROTO DPORT SSHKnock net $FW tcp 22,1599,1600,1601 If you want to log the DROPs and ACCEPTs done by SSHKnock, you can just add a log level as in: - #ACTION SOURCE DEST PROTO DEST PORT(S) + #ACTION SOURCE DEST PROTO DPORT SSHKnock:info net $FW tcp 22,1599,1600,1601 @@ -146,8 +146,7 @@ SSHKnock:info net $FW tcp 22,1599,1600,1601< 206.124.146.178 to internal system 192.168.1.5. In /etc/shorewall/rules: - #ACTION SOURCE DEST PROTO DEST PORT(S) SOURCE ORIGINAL -# PORT(S) DEST + #ACTION SOURCE DEST PROTO DPORT SPORT ORIGDEST DNAT- net 192.168.1.5 tcp 22 - 206.124.146.178 SSHKnock net $FW tcp 1599,1600,1601 SSHKnock net loc:192.168.1.5 tcp 22 - 206.124.146.178