Fedora Linux Support Community & Resources Center

Go Back   FedoraForum.org > Other Versions > EOL (End Of Life) Versions
FedoraForum Search

Forgot Password? Join Us!

EOL (End Of Life) Versions This is a Forum to discuss problems and workarounds for versions of Fedora that have passed End of Life.

Closed Thread
 
Thread Tools Search this Thread Display Modes
  #1  
Old 13th September 2007, 12:13 AM
FCL_user Offline
Registered User
 
Join Date: Aug 2007
Posts: 8
how to hosts.allow and host.deny fc6

2 questions:

1) how to block 1 IP
When I add the IP in host.deny it don't seems to work
111.222.333.444.deny example

2) How to block all IP's and add only the IP's in hosts.allow
I tried to add in hosts.deny ALL:ALL but it does not work.

I'm using Fedora Core 6

Regards

FCL_user
  #2  
Old 13th September 2007, 09:15 PM
InfRecursion Offline
Registered User
 
Join Date: Jan 2005
Posts: 214
Add the line to /etc/hosts.deny

ALL:111.222.333.444
  #3  
Old 15th September 2007, 01:05 AM
FCL_user Offline
Registered User
 
Join Date: Aug 2007
Posts: 8
Quote:
Originally Posted by InfRecursion
Add the line to /etc/hosts.deny

ALL:111.222.333.444
I add the IP to /etc/hosts.deny

ALL:111.222.333.444

Then did the following things in therminal:

service iptables save

service iptables restart

And It does no work...!

Why?


Quote:
Originally Posted by ibbo
To go further

Add
ALL:ALL to hosts.deny
This then stops everything dead by default

In hosts.allow you can then open bits n bats like ssh
sshd: <ip address>, <another ip address>
vsftpd: <ip address>

It should have worked just fine. Try looking at your firewall too to ensure certain ports etc are not blocked.

Ibbo
Why does adding ALL:ALL in hosts.deny does not work?


also did:

Then did the following things in therminal:

service iptables save

service iptables restart

And It does no work again...!

Could it has something to do with the thing that a have a tcp port open in iptables?

My iptables:

# Firewall configuration written by system-config-securitylevel
# Manual customization of this file is not recommended.
*filter
:INPUT ACCEPT [0:0]
:FORWARD ACCEPT [0:0]
:OUTPUT ACCEPT [0:0]
:RH-Firewall-1-INPUT - [0:0]
-A INPUT -j RH-Firewall-1-INPUT
-A FORWARD -j RH-Firewall-1-INPUT
-A RH-Firewall-1-INPUT -i lo -j ACCEPT
-A RH-Firewall-1-INPUT -p icmp --icmp-type any -j ACCEPT
-A RH-Firewall-1-INPUT -p 50 -j ACCEPT
-A RH-Firewall-1-INPUT -p 51 -j ACCEPT
-A RH-Firewall-1-INPUT -p udp --dport 5353 -d 224.0.0.251 -j ACCEPT
-A RH-Firewall-1-INPUT -p udp -m udp --dport 631 -j ACCEPT
-A RH-Firewall-1-INPUT -p tcp -m tcp --dport 631 -j ACCEPT
-A RH-Firewall-1-INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
-A RH-Firewall-1-INPUT -m state --state NEW -m tcp -p tcp --dport 22 -j ACCEPT
-A RH-Firewall-1-INPUT -m state --state NEW -m tcp -p tcp --dport 19000 -j ACCEPT
-A RH-Firewall-1-INPUT -j REJECT --reject-with icmp-host-prohibited
COMMIT

Last edited by FCL_user; 15th September 2007 at 01:31 AM.
  #4  
Old 15th September 2007, 09:36 AM
markkuk Offline
Registered User
 
Join Date: Apr 2005
Location: Finland
Posts: 5,076
iptables and hosts.allow/deny have nothing to do with each other. What do you mean exactly by "it does not work"? What services are you trying to control? How are you testing the function of tcp_wrappers? What messages do you see in system logs?
  #5  
Old 15th September 2007, 03:58 PM
FCL_user Offline
Registered User
 
Join Date: Aug 2007
Posts: 8
Quote:
Originally Posted by markkuk
iptables and hosts.allow/deny have nothing to do with each other. What do you mean exactly by "it does not work"? What services are you trying to control? How are you testing the function of tcp_wrappers? What messages do you see in system logs?

Hi Markkuk,

1) I add ALL:ALL to hosts.deny and it does not block ALL IP's ! that's what I mean with its does not work.

2) Is block one IP on a other linux pc, when I add ALL: IP it does not block that IP!


reagrds
  #6  
Old 15th September 2007, 05:12 PM
markkuk Offline
Registered User
 
Join Date: Apr 2005
Location: Finland
Posts: 5,076
Quote:
Originally Posted by FCL_user
1) I add ALL:ALL to hosts.deny and it does not block ALL IP's !
What software are you using to test this? What protocol isn't blocked? Are you sure the server software is compiled with libwrap support?
You need to provide more specific information instead of just repeating "it does not work" if you actually want help with your problem.
  #7  
Old 14th September 2007, 11:05 AM
ibbo's Avatar
ibbo Offline
Registered User
 
Join Date: Jun 2005
Location: Leeds
Posts: 1,264
To go further

Add
ALL:ALL to hosts.deny
This then stops everything dead by default

In hosts.allow you can then open bits n bats like ssh
sshd: <ip address>, <another ip address>
vsftpd: <ip address>

It should have worked just fine. Try looking at your firewall too to ensure certain ports etc are not blocked.

Ibbo
__________________
A Hangover Lasts A Day, But Our Drunken Memories Last A Lifetime
--
Linux user #349545
(GNU/Linux)iD8DBQBAzWjX+MZAIjBWXGURAmflAKCntuBbuKCWenpm XoA7LNydllVQOwCfdjyzXscddzQvlhBedAcD7qfKmHo==zx0H
  #8  
Old 14th November 2010, 08:18 PM
glennzo's Avatar
glennzo Offline
Un-Retired Administrator
 
Join Date: Mar 2004
Location: Salem, Mass USA
Posts: 13,929
linuxchrome
Re: how to hosts.allow and host.deny fc6

Hello MarksCorner. With respect to your needs and the fact that this thread is three years old, go ahead and create a new thread so I can close this one. I'll wait a bit though.
__________________
Glenn
The Bassinator © ®


Laptop: Toshiba Satellite / Intel Core 2 Duo 1.73 GHz / 2GB / 160GB / Intel Mobile 945GM/GMS/GME/943/940GML Integrated Graphics
Desktop: BioStar MCP6PB M2+ / AMD Phenom 9750 Quad Core / 4GB / 1TB SATA / 500GB SATA / EVGA GeForce 8400 GS 1GB
  #9  
Old 14th November 2010, 09:19 PM
MarksCorner Offline
Registered User
 
Join Date: Mar 2007
Location: Ogden Ut.
Age: 48
Posts: 54
linuxfedorafirefox
Re: how to hosts.allow and host.deny fc6

Quote:
Originally Posted by glennzo View Post
Hello MarksCorner. With respect to your needs and the fact that this thread is three years old, go ahead and create a new thread so I can close this one. I'll wait a bit though.
Thanx and sorry...
I started a new thread on what I am trying to accomplish here.
http://forums.fedoraforum.org/showth...21#post1416621
__________________
Registered Linux User #461294
Closed Thread

Tags
fc6, hostdeny, hostsallow

Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
how to configure hosts.allow and hosts.deny nkjha Security and Privacy 4 19th January 2009 03:10 PM
hosts.deny vs iptables cbrenchley Using Fedora 3 15th April 2008 12:38 AM
hosts deny file quacked Security and Privacy 15 15th January 2008 12:52 AM


Current GMT-time: 00:08 (Wednesday, 22-05-2013)

TopSubscribe to XML RSS for all Threads in all ForumsFedoraForumDotOrg Archive
logo

All trademarks, and forum posts in this site are property of their respective owner(s).
FedoraForum.org is privately owned and is not directly sponsored by the Fedora Project or Red Hat, Inc.

Privacy Policy | Term of Use | Posting Guidelines | Archive | Contact Us | Founding Members

Powered by vBulletin® Copyright ©2000 - 2012, vBulletin Solutions, Inc.

FedoraForum is Powered by RedHat