Portknocking example wiki.nftables.org

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



Hi folks,

I have the feeling that the nftables portknocking example found on the
wiki [1] is a bit outdated and unnecessarily convoluted.

I have cooked up a small proof of concept [2] using only 4 named sets
and one chain for an arbitrary number of knocks. (Here [3] is the
corresponding bash script to generate the ruleset.) I am not claiming
that this is a particular good solution. But maybe there is some
interest in improving the portknock example in the wiki a bit.

Best,
Matthias

[1] https://wiki.nftables.org/wiki-nftables/index.php/Port_knocking_example

[2] https://tamiko.43-1.org/developer/portknock.ruleset
[3] https://tamiko.43-1.org/developer/generate_portknock_ruleset



[Index of Archives]     [Linux Netfilter Development]     [Linux Kernel Networking Development]     [Netem]     [Berkeley Packet Filter]     [Linux Kernel Development]     [Advanced Routing & Traffice Control]     [Bugtraq]

  Powered by Linux