>> I am testing pf in an OpenBSD 4.1. This same configuration works fine on
Is pf enabled? (pfctl -si)
Did your ruleset load ok? (pfctl -sr)
>> What worries me most is that anyone on the outside can see my ssh service .
I do different things on different boxes, but my usual setup these days
is something like this:
PasswordAuthentication no
Match Address "192.168.*,10.*"
PasswordAuthentication yes
This allows passwords to work on selected networks and forces keys
for the rest of the internet. Allows me to hop from machine to machine
on an internal network, access it from anywhere from trusted boxes
with keys, and discourages me from typing passwords in from untrusted
boxes (reduces risk from keyloggers).
| Natalie Protasevich | [BUG] New Kernel Bugs |
| Greg KH | [GIT PATCH] driver core patches against 2.6.24 |
| Bart Van Assche | Integration of SCST in the mainstream Linux kernel |
| Andi Kleen | [PATCH x86] [0/16] Various i386/x86-64 changes |
git: | |
| Gerrit Renker | [PATCH 27/37] dccp: Integration of dynamic feature activation - part 2 (server side) |
| Jarek Poplawski | [PATCH] pkt_sched: Destroy gen estimators under rtnl_lock(). |
| Linus Torvalds | Re: [GIT]: Networking |
| Jeff Kirsher | [net-next PATCH 1/7] e1000e: enable CRC stripping by default |
| Jukka Andberg | ata/wdc vs gcc3 on amiga |
| YAMAMOTO Takashi | Re: wd.c patch to reduce kernel stack usage |
| Jason Thorpe | Re: ksyms patches. |
| rick | NFS transport |
