<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Restricting IPs with ssh in Operating System - HP-UX</title>
    <link>https://community.hpe.com/t5/operating-system-hp-ux/restricting-ips-with-ssh/m-p/3134529#M153671</link>
    <description>Yes Vinesh,&lt;BR /&gt;&lt;BR /&gt;you can use IP ranges, hostnames or network numbers in these files.&lt;BR /&gt;&lt;BR /&gt;Best regards,&lt;BR /&gt;Ettore</description>
    <pubDate>Wed, 03 Dec 2003 07:55:52 GMT</pubDate>
    <dc:creator>Fabio Ettore</dc:creator>
    <dc:date>2003-12-03T07:55:52Z</dc:date>
    <item>
      <title>Restricting IPs with ssh</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/restricting-ips-with-ssh/m-p/3134525#M153667</link>
      <description>Hi,&lt;BR /&gt;&lt;BR /&gt;In an attempt to tighten up our security, I have installed ssh and allowed telnet only from specific ips (inetd.sec)&lt;BR /&gt;&lt;BR /&gt;Can I restrict IP addresses for ssh as I have done for telnet?</description>
      <pubDate>Wed, 03 Dec 2003 06:35:46 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/restricting-ips-with-ssh/m-p/3134525#M153667</guid>
      <dc:creator>Vinesh Dhevcharran_1</dc:creator>
      <dc:date>2003-12-03T06:35:46Z</dc:date>
    </item>
    <item>
      <title>Re: Restricting IPs with ssh</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/restricting-ips-with-ssh/m-p/3134526#M153668</link>
      <description>There should be an entire sshd configuration file in /etc in which you can do this.  However, if your sshd is started from inetd, then you can use inetd.sec instead if you prefer.</description>
      <pubDate>Wed, 03 Dec 2003 06:40:16 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/restricting-ips-with-ssh/m-p/3134526#M153668</guid>
      <dc:creator>Mark Grant</dc:creator>
      <dc:date>2003-12-03T06:40:16Z</dc:date>
    </item>
    <item>
      <title>Re: Restricting IPs with ssh</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/restricting-ips-with-ssh/m-p/3134527#M153669</link>
      <description>Hi,&lt;BR /&gt;&lt;BR /&gt;you can restrict IP (and more) into /etc/hosts.allow and /etc/hosts.deny.&lt;BR /&gt;Past from a doc in knowledge base:&lt;BR /&gt;&lt;BR /&gt;First configure /etc/hosts.deny as follows:&lt;BR /&gt;&lt;BR /&gt;      sshd : ALL&lt;BR /&gt;&lt;BR /&gt;      Next configure /etc/hosts.allow as follows:&lt;BR /&gt;&lt;BR /&gt;      sshd : rhino.rose.hp.com&lt;BR /&gt;      sshd : 192.168.20.0/255.255.248.0&lt;BR /&gt;&lt;BR /&gt;You can use IP ranges, hostnames or network numbers in these files.&lt;BR /&gt;&lt;BR /&gt;I hope this helps you.&lt;BR /&gt;&lt;BR /&gt;Best regards,&lt;BR /&gt;Ettore</description>
      <pubDate>Wed, 03 Dec 2003 06:45:13 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/restricting-ips-with-ssh/m-p/3134527#M153669</guid>
      <dc:creator>Fabio Ettore</dc:creator>
      <dc:date>2003-12-03T06:45:13Z</dc:date>
    </item>
    <item>
      <title>Re: Restricting IPs with ssh</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/restricting-ips-with-ssh/m-p/3134528#M153670</link>
      <description>Hi,&lt;BR /&gt;&lt;BR /&gt;Mark, thanks for the response. I tried inetd.sec first, but this requires a service name e.g. telnet (one that exists in the /etc/services file) and ssh does not exist in this file. Therefore I cannot use inetd.sec to restrict IPs for ssh. Or am I wrong?&lt;BR /&gt;&lt;BR /&gt;I tried the hosts.allow and it works. Many thanks. Can I use IP ranges &amp;amp; wildcards here?</description>
      <pubDate>Wed, 03 Dec 2003 07:10:39 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/restricting-ips-with-ssh/m-p/3134528#M153670</guid>
      <dc:creator>Vinesh Dhevcharran_1</dc:creator>
      <dc:date>2003-12-03T07:10:39Z</dc:date>
    </item>
    <item>
      <title>Re: Restricting IPs with ssh</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/restricting-ips-with-ssh/m-p/3134529#M153671</link>
      <description>Yes Vinesh,&lt;BR /&gt;&lt;BR /&gt;you can use IP ranges, hostnames or network numbers in these files.&lt;BR /&gt;&lt;BR /&gt;Best regards,&lt;BR /&gt;Ettore</description>
      <pubDate>Wed, 03 Dec 2003 07:55:52 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/restricting-ips-with-ssh/m-p/3134529#M153671</guid>
      <dc:creator>Fabio Ettore</dc:creator>
      <dc:date>2003-12-03T07:55:52Z</dc:date>
    </item>
    <item>
      <title>Re: Restricting IPs with ssh</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/restricting-ips-with-ssh/m-p/3134530#M153672</link>
      <description>Hi Ettore,&lt;BR /&gt;&lt;BR /&gt;Terribly sorry to but...&lt;BR /&gt;&lt;BR /&gt;I tried using a range as I do in inetd.sec e.g 123.456.789.111-115 but this does not work in hosts.allow. I did a man on hosts.allow and I got no info. My search on ITRC also proved futile in this reguard. &lt;BR /&gt;If I need to use a range what would the syntax be?&lt;BR /&gt;</description>
      <pubDate>Wed, 03 Dec 2003 08:53:29 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/restricting-ips-with-ssh/m-p/3134530#M153672</guid>
      <dc:creator>Vinesh Dhevcharran_1</dc:creator>
      <dc:date>2003-12-03T08:53:29Z</dc:date>
    </item>
    <item>
      <title>Re: Restricting IPs with ssh</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/restricting-ips-with-ssh/m-p/3134531#M153673</link>
      <description>Vinesh,&lt;BR /&gt;&lt;BR /&gt;here is a document I found on the internet.&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://ezine.daemonnews.org/200206/hosts_allow.html" target="_blank"&gt;http://ezine.daemonnews.org/200206/hosts_allow.html&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;This syntax works in hosts.allow&lt;BR /&gt;&lt;BR /&gt;sshd : all : banners=/usr/localcw/opt/sysguard/banners : allow  &lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;but you also need to have a line denying all access in hosts.deny...&lt;BR /&gt;&lt;BR /&gt;I would also suggest adding these lines to hosts.allow as well....&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;ftpd : all : banners=/usr/localcw/opt/sysguard/banners : allow&lt;BR /&gt;telnetd : all : banners=/usr/localcw/opt/sysguard/banners : allow&lt;BR /&gt;tftpd : all : banners=/usr/localcw/opt/sysguard/banners : allow&lt;BR /&gt;logind : all : banners=/usr/localcw/opt/sysguard/banners : allow&lt;BR /&gt;rlogind : all : banners=/usr/localcw/opt/sysguard/banners : allow&lt;BR /&gt;remshd: all : banners=/usr/localcw/opt/sysguard/banners : allow&lt;BR /&gt;rexecd : all : banners=/usr/localcw/opt/sysguard/banners : allow&lt;BR /&gt;</description>
      <pubDate>Wed, 03 Dec 2003 11:04:40 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/restricting-ips-with-ssh/m-p/3134531#M153673</guid>
      <dc:creator>Todd McDaniel_1</dc:creator>
      <dc:date>2003-12-03T11:04:40Z</dc:date>
    </item>
    <item>
      <title>Re: Restricting IPs with ssh</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/restricting-ips-with-ssh/m-p/3134532#M153674</link>
      <description>no points here i hit enter too soon.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;About half way down that link it shows syntax for the sshd as follows:&lt;BR /&gt;&lt;BR /&gt;ssh : 10.0.3. : allow&lt;BR /&gt;ssh : localhost : allow&lt;BR /&gt;ssh : ALL : deny&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Here are some options for the 2nd field..&lt;BR /&gt;&lt;BR /&gt;Wild Cards: Wild card options that can be used are:&lt;BR /&gt;---ALL: All clients regardless of IP address or domain name.&lt;BR /&gt;&lt;BR /&gt;---PARANOID: Clients that have hostnames that don't match its ident/domain lookup names. This does not apply to machines that do not have any reverse domain lookup names.&lt;BR /&gt;&lt;BR /&gt;---LOCAL: A client that comes from the same machine or domain as the host.&lt;BR /&gt;&lt;BR /&gt;---UNKNOWN: A client that cannot be resolved to anything known.&lt;BR /&gt;&lt;BR /&gt;---KNOWN: A client who's name and addresses can be resolved. &lt;BR /&gt;</description>
      <pubDate>Wed, 03 Dec 2003 11:09:03 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/restricting-ips-with-ssh/m-p/3134532#M153674</guid>
      <dc:creator>Todd McDaniel_1</dc:creator>
      <dc:date>2003-12-03T11:09:03Z</dc:date>
    </item>
    <item>
      <title>Re: Restricting IPs with ssh</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/restricting-ips-with-ssh/m-p/3134533#M153675</link>
      <description>Hi Vinesh,&lt;BR /&gt;&lt;BR /&gt;I hope that Todd's links help you, there are described wildcard possibilities on /etc/hosts.allow and /etc/hosts.deny.&lt;BR /&gt;&lt;BR /&gt;Best regards,&lt;BR /&gt;Ettore</description>
      <pubDate>Thu, 04 Dec 2003 05:30:26 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/restricting-ips-with-ssh/m-p/3134533#M153675</guid>
      <dc:creator>Fabio Ettore</dc:creator>
      <dc:date>2003-12-04T05:30:26Z</dc:date>
    </item>
  </channel>
</rss>

