From owner-freebsd-questions@FreeBSD.ORG Sat Jun 11 16:07:42 2005 Return-Path: X-Original-To: freebsd-questions@freebsd.org Delivered-To: freebsd-questions@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id F22C016A41C for ; Sat, 11 Jun 2005 16:07:42 +0000 (GMT) (envelope-from dvorakv@vdsoft.org) Received: from mail.vdsoft.org (poseidon.vdsoft.org [193.85.147.250]) by mx1.FreeBSD.org (Postfix) with ESMTP id 9367243D49 for ; Sat, 11 Jun 2005 16:07:42 +0000 (GMT) (envelope-from dvorakv@vdsoft.org) Received: from [10.0.0.132] (laptop.home.deltaeng.com [10.0.0.132]) by mail.vdsoft.org (Postfix) with ESMTP id 20C1447E011; Sat, 11 Jun 2005 18:07:37 +0200 (CEST) Message-ID: <42AB0C54.4030505@vdsoft.org> Date: Sat, 11 Jun 2005 18:07:48 +0200 From: Vladimir Dvorak User-Agent: Debian Thunderbird 1.0.2 (X11/20050331) X-Accept-Language: en-us, en MIME-Version: 1.0 To: Osmany Guirola Cruz References: <1118424653.87529.5.camel@draco.cigb.edu.cu> In-Reply-To: <1118424653.87529.5.camel@draco.cigb.edu.cu> Content-Type: text/plain; charset=ISO-8859-1 Content-Transfer-Encoding: 7bit Cc: freebsd-questions@freebsd.org Subject: Re: wrap sshd X-BeenThere: freebsd-questions@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: User questions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Sat, 11 Jun 2005 16:07:43 -0000 Osmany Guirola Cruz wrote: >Hi > i am trying to restrict the ssh access to my machine from a specific >machine and i am using hosts.allow but does not wor for me this is >my /etc/hosts.allow file > > >sshd : capella.cigb.edu.cu : deny > >then i restart the sshd daemon and doe not work i still have access from >this machine ... > >Thanks > > You have better to deny everything and allow several certain hosts or networks. It is much more secure schema, than have tone of records of bad guy`s hosts in your tcp-wrappers config file. But I admit, that in some cases sense of your question is relevant. But I am not sure in which cases ? :-) Vladimir Dvorak