SSH IP access restriction using tcpwrappers is not working. (hosts.allow and hosts.deny not taken into...
up vote
0
down vote
favorite
I am using sles-12 server and i am trying to restrict ssh access to my server to my pc alone. I have tried to use tcpwrappers and it's not working..!!. I am able to ssh to the server from any IP in my local network.
I have tried different formats from man page to see if anything is working but to no effect. Here is the files I have used for setting the wrappers and commands which might be useful
[root@myserver ~]# cat /etc/hosts.allow
sshd:172.19.112.120
[root@myserver ~]# cat /etc/hosts.deny
sshd:ALL
[root@myserver ~]# tcpdmatch -d -i /etc/xinetd.conf sshd 135.250.164.106 --> another server
client: hostname paranoid
client: address 135.250.164.106
server: process sshd
access: granted --> NOT OK
[root@myserver ~]#
[root@myserver ~]# ldd /usr/sbin/sshd | grep 'libwrap'
libwrap.so.0 => /lib64/libwrap.so.0 (0x00007fa2b71f7000)
PS: IP table restrictions are working fine. But I can't use it in my scenario. and no specific configurations are done in /etc/ssh/ssh_config
linux ssh security
New contributor
add a comment |
up vote
0
down vote
favorite
I am using sles-12 server and i am trying to restrict ssh access to my server to my pc alone. I have tried to use tcpwrappers and it's not working..!!. I am able to ssh to the server from any IP in my local network.
I have tried different formats from man page to see if anything is working but to no effect. Here is the files I have used for setting the wrappers and commands which might be useful
[root@myserver ~]# cat /etc/hosts.allow
sshd:172.19.112.120
[root@myserver ~]# cat /etc/hosts.deny
sshd:ALL
[root@myserver ~]# tcpdmatch -d -i /etc/xinetd.conf sshd 135.250.164.106 --> another server
client: hostname paranoid
client: address 135.250.164.106
server: process sshd
access: granted --> NOT OK
[root@myserver ~]#
[root@myserver ~]# ldd /usr/sbin/sshd | grep 'libwrap'
libwrap.so.0 => /lib64/libwrap.so.0 (0x00007fa2b71f7000)
PS: IP table restrictions are working fine. But I can't use it in my scenario. and no specific configurations are done in /etc/ssh/ssh_config
linux ssh security
New contributor
I have found the problem on why it's not working. I am using openssh v 7.2 and tcpwrappers support is removed from openssh from version 6.7 onwards. Link --> openssh.com/releasenotes.html (Check release notes of version 6.7).
– Ajay Joseph
17 hours ago
add a comment |
up vote
0
down vote
favorite
up vote
0
down vote
favorite
I am using sles-12 server and i am trying to restrict ssh access to my server to my pc alone. I have tried to use tcpwrappers and it's not working..!!. I am able to ssh to the server from any IP in my local network.
I have tried different formats from man page to see if anything is working but to no effect. Here is the files I have used for setting the wrappers and commands which might be useful
[root@myserver ~]# cat /etc/hosts.allow
sshd:172.19.112.120
[root@myserver ~]# cat /etc/hosts.deny
sshd:ALL
[root@myserver ~]# tcpdmatch -d -i /etc/xinetd.conf sshd 135.250.164.106 --> another server
client: hostname paranoid
client: address 135.250.164.106
server: process sshd
access: granted --> NOT OK
[root@myserver ~]#
[root@myserver ~]# ldd /usr/sbin/sshd | grep 'libwrap'
libwrap.so.0 => /lib64/libwrap.so.0 (0x00007fa2b71f7000)
PS: IP table restrictions are working fine. But I can't use it in my scenario. and no specific configurations are done in /etc/ssh/ssh_config
linux ssh security
New contributor
I am using sles-12 server and i am trying to restrict ssh access to my server to my pc alone. I have tried to use tcpwrappers and it's not working..!!. I am able to ssh to the server from any IP in my local network.
I have tried different formats from man page to see if anything is working but to no effect. Here is the files I have used for setting the wrappers and commands which might be useful
[root@myserver ~]# cat /etc/hosts.allow
sshd:172.19.112.120
[root@myserver ~]# cat /etc/hosts.deny
sshd:ALL
[root@myserver ~]# tcpdmatch -d -i /etc/xinetd.conf sshd 135.250.164.106 --> another server
client: hostname paranoid
client: address 135.250.164.106
server: process sshd
access: granted --> NOT OK
[root@myserver ~]#
[root@myserver ~]# ldd /usr/sbin/sshd | grep 'libwrap'
libwrap.so.0 => /lib64/libwrap.so.0 (0x00007fa2b71f7000)
PS: IP table restrictions are working fine. But I can't use it in my scenario. and no specific configurations are done in /etc/ssh/ssh_config
linux ssh security
linux ssh security
New contributor
New contributor
New contributor
asked Dec 3 at 9:54
Ajay Joseph
1
1
New contributor
New contributor
I have found the problem on why it's not working. I am using openssh v 7.2 and tcpwrappers support is removed from openssh from version 6.7 onwards. Link --> openssh.com/releasenotes.html (Check release notes of version 6.7).
– Ajay Joseph
17 hours ago
add a comment |
I have found the problem on why it's not working. I am using openssh v 7.2 and tcpwrappers support is removed from openssh from version 6.7 onwards. Link --> openssh.com/releasenotes.html (Check release notes of version 6.7).
– Ajay Joseph
17 hours ago
I have found the problem on why it's not working. I am using openssh v 7.2 and tcpwrappers support is removed from openssh from version 6.7 onwards. Link --> openssh.com/releasenotes.html (Check release notes of version 6.7).
– Ajay Joseph
17 hours ago
I have found the problem on why it's not working. I am using openssh v 7.2 and tcpwrappers support is removed from openssh from version 6.7 onwards. Link --> openssh.com/releasenotes.html (Check release notes of version 6.7).
– Ajay Joseph
17 hours ago
add a comment |
active
oldest
votes
active
oldest
votes
active
oldest
votes
active
oldest
votes
active
oldest
votes
Ajay Joseph is a new contributor. Be nice, and check out our Code of Conduct.
Ajay Joseph is a new contributor. Be nice, and check out our Code of Conduct.
Ajay Joseph is a new contributor. Be nice, and check out our Code of Conduct.
Ajay Joseph is a new contributor. Be nice, and check out our Code of Conduct.
Thanks for contributing an answer to Unix & Linux Stack Exchange!
- Please be sure to answer the question. Provide details and share your research!
But avoid …
- Asking for help, clarification, or responding to other answers.
- Making statements based on opinion; back them up with references or personal experience.
To learn more, see our tips on writing great answers.
Some of your past answers have not been well-received, and you're in danger of being blocked from answering.
Please pay close attention to the following guidance:
- Please be sure to answer the question. Provide details and share your research!
But avoid …
- Asking for help, clarification, or responding to other answers.
- Making statements based on opinion; back them up with references or personal experience.
To learn more, see our tips on writing great answers.
Sign up or log in
StackExchange.ready(function () {
StackExchange.helpers.onClickDraftSave('#login-link');
});
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
StackExchange.ready(
function () {
StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2funix.stackexchange.com%2fquestions%2f485651%2fssh-ip-access-restriction-using-tcpwrappers-is-not-working-hosts-allow-and-hos%23new-answer', 'question_page');
}
);
Post as a guest
Required, but never shown
Sign up or log in
StackExchange.ready(function () {
StackExchange.helpers.onClickDraftSave('#login-link');
});
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
Sign up or log in
StackExchange.ready(function () {
StackExchange.helpers.onClickDraftSave('#login-link');
});
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
Sign up or log in
StackExchange.ready(function () {
StackExchange.helpers.onClickDraftSave('#login-link');
});
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
I have found the problem on why it's not working. I am using openssh v 7.2 and tcpwrappers support is removed from openssh from version 6.7 onwards. Link --> openssh.com/releasenotes.html (Check release notes of version 6.7).
– Ajay Joseph
17 hours ago