Security Basics mailing list archives

RE: Reflexive firewalls?


From: "Weir, Jason" <jason.weir () nhrs org>
Date: Thu, 27 Dec 2007 12:15:22 -0500

Sounds like port knocking to me

http://www.portknocking.org/

-Jason

-----Original Message-----
From: listbounce () securityfocus com [mailto:listbounce () securityfocus com]
On Behalf Of Ong Chin Kiat
Sent: Thursday, December 27, 2007 11:24 AM
To: security-basics () securityfocus com
Subject: Reflexive firewalls?


Hi list,

I've recently used an SSH server that had an interesting authentication 
mechanism. You first had to telnet to the machine on a certain port. 
After doing this (it will just time out - no prompt), you then SSH to 
the server in question. The telnet step has to be carried out, if not 
SSH will just time out.

My question is, is this called reflexive firewalling, and can I 
duplicate this with iptables?

Thanks.


Current thread: