SSH IP access restriction using tcpwrappers is not working. (hosts.allow and hosts.deny not taken into account)
Clash Royale CLAN TAG#URR8PPP
up vote
0
down vote
favorite
I am using sles-12 server and i am trying to restrict ssh access to my server to my pc alone. I have tried to use tcpwrappers and it's not working..!!. I am able to ssh to the server from any IP in my local network.
I have tried different formats from man page to see if anything is working but to no effect. Here is the files I have used for setting the wrappers and commands which might be useful
[root@myserver ~]# cat /etc/hosts.allow
sshd:172.19.112.120
[root@myserver ~]# cat /etc/hosts.deny
sshd:ALL
[root@myserver ~]# tcpdmatch -d -i /etc/xinetd.conf sshd 135.250.164.106 --> another server
client: hostname paranoid
client: address 135.250.164.106
server: process sshd
access: granted --> NOT OK
[root@myserver ~]#
[root@myserver ~]# ldd /usr/sbin/sshd | grep 'libwrap'
libwrap.so.0 => /lib64/libwrap.so.0 (0x00007fa2b71f7000)
PS: IP table restrictions are working fine. But I can't use it in my scenario. and no specific configurations are done in /etc/ssh/ssh_config
linux ssh security
add a comment |
up vote
0
down vote
favorite
I am using sles-12 server and i am trying to restrict ssh access to my server to my pc alone. I have tried to use tcpwrappers and it's not working..!!. I am able to ssh to the server from any IP in my local network.
I have tried different formats from man page to see if anything is working but to no effect. Here is the files I have used for setting the wrappers and commands which might be useful
[root@myserver ~]# cat /etc/hosts.allow
sshd:172.19.112.120
[root@myserver ~]# cat /etc/hosts.deny
sshd:ALL
[root@myserver ~]# tcpdmatch -d -i /etc/xinetd.conf sshd 135.250.164.106 --> another server
client: hostname paranoid
client: address 135.250.164.106
server: process sshd
access: granted --> NOT OK
[root@myserver ~]#
[root@myserver ~]# ldd /usr/sbin/sshd | grep 'libwrap'
libwrap.so.0 => /lib64/libwrap.so.0 (0x00007fa2b71f7000)
PS: IP table restrictions are working fine. But I can't use it in my scenario. and no specific configurations are done in /etc/ssh/ssh_config
linux ssh security
I have found the problem on why it's not working. I am using openssh v 7.2 and tcpwrappers support is removed from openssh from version 6.7 onwards. Link --> openssh.com/releasenotes.html (Check release notes of version 6.7).
– Ajay Joseph
Dec 6 at 11:22
add a comment |
up vote
0
down vote
favorite
up vote
0
down vote
favorite
I am using sles-12 server and i am trying to restrict ssh access to my server to my pc alone. I have tried to use tcpwrappers and it's not working..!!. I am able to ssh to the server from any IP in my local network.
I have tried different formats from man page to see if anything is working but to no effect. Here is the files I have used for setting the wrappers and commands which might be useful
[root@myserver ~]# cat /etc/hosts.allow
sshd:172.19.112.120
[root@myserver ~]# cat /etc/hosts.deny
sshd:ALL
[root@myserver ~]# tcpdmatch -d -i /etc/xinetd.conf sshd 135.250.164.106 --> another server
client: hostname paranoid
client: address 135.250.164.106
server: process sshd
access: granted --> NOT OK
[root@myserver ~]#
[root@myserver ~]# ldd /usr/sbin/sshd | grep 'libwrap'
libwrap.so.0 => /lib64/libwrap.so.0 (0x00007fa2b71f7000)
PS: IP table restrictions are working fine. But I can't use it in my scenario. and no specific configurations are done in /etc/ssh/ssh_config
linux ssh security
I am using sles-12 server and i am trying to restrict ssh access to my server to my pc alone. I have tried to use tcpwrappers and it's not working..!!. I am able to ssh to the server from any IP in my local network.
I have tried different formats from man page to see if anything is working but to no effect. Here is the files I have used for setting the wrappers and commands which might be useful
[root@myserver ~]# cat /etc/hosts.allow
sshd:172.19.112.120
[root@myserver ~]# cat /etc/hosts.deny
sshd:ALL
[root@myserver ~]# tcpdmatch -d -i /etc/xinetd.conf sshd 135.250.164.106 --> another server
client: hostname paranoid
client: address 135.250.164.106
server: process sshd
access: granted --> NOT OK
[root@myserver ~]#
[root@myserver ~]# ldd /usr/sbin/sshd | grep 'libwrap'
libwrap.so.0 => /lib64/libwrap.so.0 (0x00007fa2b71f7000)
PS: IP table restrictions are working fine. But I can't use it in my scenario. and no specific configurations are done in /etc/ssh/ssh_config
linux ssh security
linux ssh security
asked Dec 3 at 9:54
Ajay Joseph
1
1
I have found the problem on why it's not working. I am using openssh v 7.2 and tcpwrappers support is removed from openssh from version 6.7 onwards. Link --> openssh.com/releasenotes.html (Check release notes of version 6.7).
– Ajay Joseph
Dec 6 at 11:22
add a comment |
I have found the problem on why it's not working. I am using openssh v 7.2 and tcpwrappers support is removed from openssh from version 6.7 onwards. Link --> openssh.com/releasenotes.html (Check release notes of version 6.7).
– Ajay Joseph
Dec 6 at 11:22
I have found the problem on why it's not working. I am using openssh v 7.2 and tcpwrappers support is removed from openssh from version 6.7 onwards. Link --> openssh.com/releasenotes.html (Check release notes of version 6.7).
– Ajay Joseph
Dec 6 at 11:22
I have found the problem on why it's not working. I am using openssh v 7.2 and tcpwrappers support is removed from openssh from version 6.7 onwards. Link --> openssh.com/releasenotes.html (Check release notes of version 6.7).
– Ajay Joseph
Dec 6 at 11:22
add a comment |
active
oldest
votes
active
oldest
votes
active
oldest
votes
active
oldest
votes
active
oldest
votes
Thanks for contributing an answer to Unix & Linux Stack Exchange!
- Please be sure to answer the question. Provide details and share your research!
But avoid …
- Asking for help, clarification, or responding to other answers.
- Making statements based on opinion; back them up with references or personal experience.
To learn more, see our tips on writing great answers.
Some of your past answers have not been well-received, and you're in danger of being blocked from answering.
Please pay close attention to the following guidance:
- Please be sure to answer the question. Provide details and share your research!
But avoid …
- Asking for help, clarification, or responding to other answers.
- Making statements based on opinion; back them up with references or personal experience.
To learn more, see our tips on writing great answers.
Sign up or log in
StackExchange.ready(function ()
StackExchange.helpers.onClickDraftSave('#login-link');
);
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
StackExchange.ready(
function ()
StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2funix.stackexchange.com%2fquestions%2f485651%2fssh-ip-access-restriction-using-tcpwrappers-is-not-working-hosts-allow-and-hos%23new-answer', 'question_page');
);
Post as a guest
Required, but never shown
Sign up or log in
StackExchange.ready(function ()
StackExchange.helpers.onClickDraftSave('#login-link');
);
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
Sign up or log in
StackExchange.ready(function ()
StackExchange.helpers.onClickDraftSave('#login-link');
);
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
Sign up or log in
StackExchange.ready(function ()
StackExchange.helpers.onClickDraftSave('#login-link');
);
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
I have found the problem on why it's not working. I am using openssh v 7.2 and tcpwrappers support is removed from openssh from version 6.7 onwards. Link --> openssh.com/releasenotes.html (Check release notes of version 6.7).
– Ajay Joseph
Dec 6 at 11:22