Re: How to filter packets resulting from hosts with dynamic IP-address

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



On Tuesday 06 February 2007 16:31, Petr Pisar wrote:
> As you can see, relaing on IP address is not secure. You should consider
> using some type of authentication (e.g. IPsec).
Yes, you are perfectly right. But authetication is only one part of the 
solution. I have pretty bad experience with an open ssh port, although no one 
has managed so far to break in, considerable amount of traffic was generated 
on my connection trying to brute force their way in almost resulting in a 
DOS. Preselecting who I would like to allow access, will reduce those attacs 
to virtually zero.

Frank
-- 
INPHO GmbH   *   Smaragdweg 1   *   70174 Stuttgart   *   Germany
phone: +49 711 2288 10  *  fax: +49 711 2288 111  *  web: www.inpho.de
place of business: Stuttgart    *   managing director: Johannes Saile
commercial register: Stuttgart, HRB 9586



[Index of Archives]     [Linux Netfilter Development]     [Linux Kernel Networking Development]     [Netem]     [Berkeley Packet Filter]     [Linux Kernel Development]     [Advanced Routing & Traffice Control]     [Bugtraq]

  Powered by Linux