Skip to Content.
Sympa Menu

perfsonar-user - Re: [perfsonar-user] SSH Port and updates override local configuration

Subject: perfSONAR User Q&A and Other Discussion

List archive

Re: [perfsonar-user] SSH Port and updates override local configuration


Chronological Thread 
  • From: Andrew Lake <>
  • To: Joseph Ghobrial <>
  • Cc:
  • Subject: Re: [perfsonar-user] SSH Port and updates override local configuration
  • Date: Tue, 12 Sep 2017 18:23:11 +0200
  • Ironport-phdr: 9a23:1FKsnRFFyI9u/qOD3njS6p1GYnF86YWxBRYc798ds5kLTJ78r8WwAkXT6L1XgUPTWs2DsrQf2rqQ6/iocFdDyK7JiGoFfp1IWk1NouQttCtkPvS4D1bmJuXhdS0wEZcKflZk+3amLRodQ56mNBXdrXKo8DEdBAj0OxZrKeTpAI7SiNm82/yv95HJbQhFgDmwbaluIBmqsA7cqtQYjYx+J6gr1xDHuGFIe+NYxWNpIVKcgRPx7dqu8ZBg7ipdpesv+9ZPXqvmcas4S6dYDCk9PGAu+MLrrxjDQhCR6XYaT24bjwBHAwnB7BH9Q5fxri73vfdz1SWGIcH7S60/VC+85Kl3VhDnlCYHNyY48G7JjMxwkLlbqw+lqxBm3oLYfJ2ZOP94c6jAf90VWHBBU95RWSNDDIOyaIQAAeQCM+hFsYfyu0ADogGiCQS2Hu7i0CNEi33w0KYn0+ohCwbG3Ak4Et8StnTbsc/1O7kcUOuoyqfH1zbDYO1L0jr68ofIdA0uoPGXUL1uasrd008vGB3ZjliJr4HuIj2b1uMIs2eB7upgU/qii3Y5pAFrrDiv3cAsio/TiYIP0FzE8zt2wJotKd2iSU50fcCrHIFOuC6HKot7RN4pTWJwuCsi17EKp522cDIExZg9yBPTduaLfomL7x77SuqdPTN1iGhmdb+/nRq+71Wsx+LmWsS2zFpHqDdOnMPWuXAXzRPT79CKSvtj8Uel3jaCzw7T5f9KLEwukarUMJohzqQ/lpoUr0TPBi72mEPog6+Kbkgo5/ak5uf9brjovJOROJJ4hhv/P6ktgsC/BP43MgkKX2iV4+S807jj8FXjT7VMk/I3krLUv47BJcgBoK62HRNV3p456xmjFzemzMgYnX4fIVJdZh2HlYbpO0rJIPD+F/i/mU2gkCpwx//YJL3sGZHNLnnYkLf9ZrZx9VRQyAs1zdBD+Z1UELcBL+zvWkPvrtDXEAI2MxHni9rgXfd6zY4GWSqgAqiTKqLbtRfc5O0vJOOWZYYRkCz8IPVj6vLz2ywXg1gYKICv0YEadzicF/draxGQZ3b9qtoaV2EHolxtH6TRlFSeXGsLND6JVKUm62R+Udr+AA==

No, an update should not change the order of the rules so you shouldn't have to make the change again. We expect people will want to do this type of thing and try to accommodate it with this setup best we can.


On September 12, 2017 at 12:11:17 PM, Joseph Ghobrial () wrote:

Hi Andy, how does that relate to the first jump rule to perfSONAR? Will an update again move that rule to the first rule on the INPUT chain? If so then I'll always run into this. Just wanted to make sure I understand that if I insert something before the perfSONAR jump in the INPUT chain that it will remain where it is and not move up again thus overriding my rules.

Thanks,
Joseph


--
Joseph Ghobrial
Systems Analyst II
Office of Information Technology
Rice University
jghobrial@ rice.edu
x5190

On Mon, Sep 11, 2017 at 11:10 AM, Andrew Lake <> wrote:
Hi,


TL;DR: Leave the perfSONAR chain alone and add your rules in a chain of higher priority.

Hope that helps,
Andy



On September 11, 2017 at 11:40:42 AM, Joseph Ghobrial () wrote:

Hi, I prefer to have my SSH port accessible to a restricted set of addresses, however the default perfSONAR iptables rules allows ssh from anywhere overriding my rules. How do I change the default behavior such that perfSONAR updates exclude including the builtin SSH rule? Or how do I change the default rule to be the way I want it?

Thanks,
Joseph

--
Joseph Ghobrial
Systems Analyst II
Office of Information Technology
Rice University
jghobrial@ rice.edu
x5190




Archive powered by MHonArc 2.6.19.

Top of Page