Portál AbcLinuxu, 26. listopadu 2025 07:53
Dec 29 17:02:22 host1 kernel: [53522.095997] IN-internet:IN=eth0 OUT= MAC=ff:ff:ff:ff:ff:ff:52:54:00:00:25:77:08:00 SRC=46.28.111.86 DST=46.28.111.255 LEN=78 TOS=0x00 PREC=0x00 TTL=128 ID=11359 PROTO=UDP SPT=137 DPT=137 LEN=58 Dec 29 17:02:23 host1 kernel: [53522.893117] IN-internet:IN=eth0 OUT= MAC=ff:ff:ff:ff:ff:ff:52:54:00:00:04:70:08:00 SRC=46.28.111.54 DST=255.255.255.255 LEN=182 TOS=0x00 PREC=0x00 TTL=64 ID=18901 DF PROTO=UDP SPT=17500 DPT=17500 LEN=162 Dec 29 17:02:25 host1 kernel: [53524.576072] IN-internet:IN=eth0 OUT= MAC=ff:ff:ff:ff:ff:ff:52:54:00:00:32:c0:08:00 SRC=37.157.199.40 DST=255.255.255.255 LEN=132 TOS=0x00 PREC=0x00 TTL=128 ID=24313 PROTO=UDP SPT=17500 DPT=17500 LEN=112 Dec 29 17:02:26 host1 kernel: [53525.825216] IN-internet:IN=eth0 OUT= MAC=ff:ff:ff:ff:ff:ff:52:54:00:00:13:16:08:00 SRC=37.157.196.217 DST=255.255.255.255 LEN=129 TOS=0x00 PREC=0x00 TTL=64 ID=32637 DF PROTO=UDP SPT=17500 DPT=17500 LEN=109
ufw deny 137,17500/udp).
používám firehol a jeho config je zde:
server_git_ports="tcp/9418"
client_git_ports="default"
home_ips="MOJE IP"
# Accept all client traffic on any interface
interface "eth0" internet src not "${home_ips} ${UNROUTABLE_IPS}"
protection strong 10/sec 10
server ident reject with tcp-reset
server http accept
server https accept
server ssh accept
server ping accept
server ftp accept
server git accept
client ntp accept
client dns accept
client ping accept
client http accept
client https accept
client icmp accept
client rsync accept
Předpokládal jsem, že to funguje tak, že vyjmenuji co je povoleno a ostatní je automaticky zablokováno. Takže to buď chápu špatně, nebo by to mělo být zablokováno. Díky za rady
Tiskni
Sdílej:
ISSN 1214-1267, (c) 1999-2007 Stickfish s.r.o.