Re: allowing ssh in campus

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



В сообщении от 18 Май 2005 12:49 vaida bogdan написал(a):
> I have NAT.
> (
> > If I allow Student1 ssh on dorm1 gateway then what do I tell the
> > Campus gateway to allow ? (I can't allow full access from Dorm1's
> > gateway public ip.
> )

> On 5/18/05, Пётр Волков  Александрович <torre_cremata@xxxxxxx> wrote:
> > В сообщении от 18 Май 2005 04:42 vaida bogdan написал(a):
> > > My campus connections look like this:

> > > Dorm1 gateway ----\
> > > Dorm2 gateway ----|=> Campus gateway |-> OUTSIDE
> > > Dorm3 gateway ----/                                  \-> University

Well. IIUYC, your task is to allow of drop connections from users that are 
behind NAT. Sorry. I don't think this is possible without access to  Dorm 
gateways. All packets from gateway are looking as coming from single IP, and 
infromation about source of packet is lost. The best you can do is to look at 
ttl field to find out if the packet is from dorm gateway or not. But users 
can simply get around this...

-- 
____________
Peter.



[Index of Archives]     [Linux Netfilter Development]     [Linux Kernel Networking Development]     [Netem]     [Berkeley Packet Filter]     [Linux Kernel Development]     [Advanced Routing & Traffice Control]     [Bugtraq]

  Powered by Linux