[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: [cobalt-security] Why does PortSentry continue to log ports 137 and 138 even though I've told it not to?
- Subject: Re: [cobalt-security] Why does PortSentry continue to log ports 137 and 138 even though I've told it not to?
- From: "Lawrence Frewin of Accommodation.com" <Lawrence@xxxxxxxxxxxxxxxxx>
- Date: Tue, 1 May 2001 17:50:38 +0100
- List-id: Mailing list for users to address network security on Cobalt products. <cobalt-security.list.cobalt.com>
Hmm, we used those lines in our copy and it worked fine.
Here is an earlier version of the block, it works for some, but not others.
$IPC -A input -s 0.0.0.0/0.0.0.0 -d 0.0.0.0/0.0.0.0 137:137 -p tcp -j DENY
$IPC -A input -s 0.0.0.0/0.0.0.0 -d 0.0.0.0/0.0.0.0 137:137 -p udp -j DENY
$IPC -A input -s 0.0.0.0/0.0.0.0 -d 0.0.0.0/0.0.0.0 137:138 -p tcp -j DENY
$IPC -A input -s 0.0.0.0/0.0.0.0 -d 0.0.0.0/0.0.0.0 137:138 -p udp -j DENY
$IPC -A input -s 0.0.0.0/0.0.0.0 -d 0.0.0.0/0.0.0.0 137:139 -p tcp -j DENY
$IPC -A input -s 0.0.0.0/0.0.0.0 -d 0.0.0.0/0.0.0.0 137:139 -p udp -j DENY
If you still don't have any luck with it mail me a copy of the text
firewall-on offline I will see if I can sort it out.
Lawrence@xxxxxxxxxx
----- Original Message -----
From: "Dan" <daniel@xxxxxxxxxxxxxxxxxxxxxxxx>
To: <cobalt-security@xxxxxxxxxxxxxxx>
Sent: Tuesday, May 01, 2001 5:27 PM
Subject: Re: [cobalt-security] Why does PortSentry continue to log ports 137
and 138 even though I've told it not to?
> >
> > # Deny Samba, added 20/4/2001
> > #
> > $IPC -A input -p tcp -s 0/0 -d $OUTERNET 137:139 -j DENY
> > $IPC -A input -p udp -s 0/0 -d $OUTERNET 137:139 -j DENY
> > #
> >
> > Make sure these lines are added above the logging line at the bottom of
> > firewall-on which ends with "-l"
> >
> > Lawrence
> >
> >
> Thanks, saw this post, tried it and it did not work. I did put them above
> the "logging" line but in sequence of the ports (as the post suggested).
>
> Dan
>
> _______________________________________________
> cobalt-security mailing list
> cobalt-security@xxxxxxxxxxxxxxx
> http://list.cobalt.com/mailman/listinfo/cobalt-security