Re: [leaf-user] DNAT:ssh how to restrict ?

2003-08-02 Thread Tom Eastep
On Mon, 2003-07-28 at 12:40, Hein Bauer wrote: > Dear List, > I just dnatted my ssh port of Bering 1.0 to a sshd-server inside my > localnet. Works fine :-). But I am concerned about security I would > like to restrict ssh-logins from a list of MAC-Addresses. > I had a look into /etc/shorewa

Re: [leaf-user] DNAT:ssh how to restrict ?

2003-08-02 Thread Steve Wright
On Tue, 2003-07-29 at 07:40, Hein Bauer wrote: > Hm. I cannot use a IP-Adress for restriction, because it changes. The > ssh "client" got a dynamic IP..., so I would like to use MAC-Addresses. > issue static IPs with dhcpd, then limit on IP address. /steve ---

RE: [leaf-user] DNAT:ssh how to restrict ?

2003-08-03 Thread Alex Rhomberg
Hein, > I just dnatted my ssh port of Bering 1.0 to a sshd-server inside my > localnet. Works fine :-). But I am concerned about security I would > like to restrict ssh-logins from a list of MAC-Addresses. Who do you want to protect yourself from? I suspect you want to login from the Interne

Re: [leaf-user] DNAT:ssh how to restrict ?

2003-08-04 Thread Henning Jebsen
Alex Rhomberg wrote: Who do you want to protect yourself from? I suspect you > want to login from the Internet but don't want others to. exactly In that case I recommend using public key authentication and disabling password authentication. > This makes it much harder to guess the password... Tha