Author Topic: TECH. HELP - IP tables - [Issue resolved]  (Read 303 times)

Offline CaptainWTF

  • Highly Active
  • ****
  • Posts: 1941
  • Serious Business
    Points:
    -1523
    • View Profile
TECH. HELP - IP tables - [Issue resolved]
« on: September 07, 2010, 04:09:22 PM »
Alright So I've got a remote network I want to secure on certain LAN IP's within the network. specifically 192.168.1.105 and do the same for the web administration panel in the router. If my IP was static it would be alot simpler to do for sure. But since its not I want to use dynamicDNS urls that I've got set up to update with my router here.

basically there is an IP camera system I don't want accessed externally by anyone but me at my house. although there are various questions that come up. whether it would resolve the dyndns or whether it would be considered invalid and not be functional.

Anomaly was mentioning something about SSH tunneling which I think if it works like I've seen you could just set up an Iptable configuration to where it drops all external connections to that LAN ip. and have the computer that records remotely tunneled into the network. Although I'm unsure.
« Last Edit: December 09, 2010, 07:17:45 PM by CaptainWTF »
"Tell the firewall to fuck off"
"Don't be an asshat. No one likes asshats. A cap is alright. A hat is nice. having an ass is compulsory. Combining an ass and a hat? Not a good idea, take it off."





___
Corsair 800D
AsRock 770 Extreme 3 motherboard
Phenom II x3 720 BE (4th core unlocked. OC'd to 4.2ghz)
8gb G.Skill Ripjaw memory @ 667mhz
EVGA GTX 560 Ti video card @ 900mhz W/ Arctic Cooling Accelero Xtreme Plus II
Samsung 830 series 128gb SSD
OCZ StealthXStream2 700w PSU
APC BX1500G 865w UPS

Offline CaptainWTF

  • Highly Active
  • ****
  • Posts: 1941
  • Serious Business
    Points:
    -1523
    • View Profile
Re: DD-WRT SSH firewalling.
« Reply #1 on: September 07, 2010, 07:39:34 PM »
Alright so im getting to understand this a little bit better. although still running into a few issues
"Tell the firewall to fuck off"
"Don't be an asshat. No one likes asshats. A cap is alright. A hat is nice. having an ass is compulsory. Combining an ass and a hat? Not a good idea, take it off."





___
Corsair 800D
AsRock 770 Extreme 3 motherboard
Phenom II x3 720 BE (4th core unlocked. OC'd to 4.2ghz)
8gb G.Skill Ripjaw memory @ 667mhz
EVGA GTX 560 Ti video card @ 900mhz W/ Arctic Cooling Accelero Xtreme Plus II
Samsung 830 series 128gb SSD
OCZ StealthXStream2 700w PSU
APC BX1500G 865w UPS

Offline CaptainWTF

  • Highly Active
  • ****
  • Posts: 1941
  • Serious Business
    Points:
    -1523
    • View Profile
Re: DD-WRT SSH firewalling.
« Reply #2 on: September 07, 2010, 07:59:21 PM »
Hmm I'm curious though is there a way that whenever a unsuccessful attempt to connect via SSH occurs it can leave something somewhere? Like in the log or syslog or something.

Also if I uncheck the allow any remote IP option under remote access on the router can I add something to the IP tables that will allow me to access it but instead of an IP use a dyndns?
« Last Edit: September 07, 2010, 08:32:28 PM by CaptainWTF »
"Tell the firewall to fuck off"
"Don't be an asshat. No one likes asshats. A cap is alright. A hat is nice. having an ass is compulsory. Combining an ass and a hat? Not a good idea, take it off."





___
Corsair 800D
AsRock 770 Extreme 3 motherboard
Phenom II x3 720 BE (4th core unlocked. OC'd to 4.2ghz)
8gb G.Skill Ripjaw memory @ 667mhz
EVGA GTX 560 Ti video card @ 900mhz W/ Arctic Cooling Accelero Xtreme Plus II
Samsung 830 series 128gb SSD
OCZ StealthXStream2 700w PSU
APC BX1500G 865w UPS

Offline [IAM] Anomaly

  • [IAM] Leader
  • Highly Active
  • ******
  • Posts: 451
  • Serious Business
    Points:
    11
    • View Profile
Re: DD-WRT SSH firewalling.
« Reply #3 on: September 08, 2010, 09:25:46 PM »
1.  Take the camera system out of the DMZ
2.  Enable remote SSH access
3.  Use putty, SSH to the router, and instruct putty to forward port 5555 to 192.camera.system.ip:cameraport
4.  Type http://localhost:5555 into browser (assuming a web-managed camera system)
5.  Profit

Offline CaptainWTF

  • Highly Active
  • ****
  • Posts: 1941
  • Serious Business
    Points:
    -1523
    • View Profile
Re: DD-WRT SSH firewalling.
« Reply #4 on: September 08, 2010, 10:45:51 PM »
I've already got it figured out Although I think you added steps I don't need?

I just took the cameras out of the DMZ forwarded ports 80/9002 which are http #1 and #2 for the cameras by what I've set up. and then all I do is just 192.168.1.105 and BAM login prompt.
"Tell the firewall to fuck off"
"Don't be an asshat. No one likes asshats. A cap is alright. A hat is nice. having an ass is compulsory. Combining an ass and a hat? Not a good idea, take it off."





___
Corsair 800D
AsRock 770 Extreme 3 motherboard
Phenom II x3 720 BE (4th core unlocked. OC'd to 4.2ghz)
8gb G.Skill Ripjaw memory @ 667mhz
EVGA GTX 560 Ti video card @ 900mhz W/ Arctic Cooling Accelero Xtreme Plus II
Samsung 830 series 128gb SSD
OCZ StealthXStream2 700w PSU
APC BX1500G 865w UPS

Offline [IAM] Anomaly

  • [IAM] Leader
  • Highly Active
  • ******
  • Posts: 451
  • Serious Business
    Points:
    11
    • View Profile
Re: DD-WRT SSH firewalling.
« Reply #5 on: September 08, 2010, 11:17:14 PM »
If you forward those ports, then anybody can get at it, which you said was not the objective.  of course, if the camera system has its own login system than that might be fine.

Offline CaptainWTF

  • Highly Active
  • ****
  • Posts: 1941
  • Serious Business
    Points:
    -1523
    • View Profile
Re: DD-WRT SSH firewalling.
« Reply #6 on: September 08, 2010, 11:51:00 PM »
WRONG. I those are the ports I set up with putty not the router. derp.
and i've tested trying to get at the cameras I can't. I have to be tunneled in.
"Tell the firewall to fuck off"
"Don't be an asshat. No one likes asshats. A cap is alright. A hat is nice. having an ass is compulsory. Combining an ass and a hat? Not a good idea, take it off."





___
Corsair 800D
AsRock 770 Extreme 3 motherboard
Phenom II x3 720 BE (4th core unlocked. OC'd to 4.2ghz)
8gb G.Skill Ripjaw memory @ 667mhz
EVGA GTX 560 Ti video card @ 900mhz W/ Arctic Cooling Accelero Xtreme Plus II
Samsung 830 series 128gb SSD
OCZ StealthXStream2 700w PSU
APC BX1500G 865w UPS

Offline [IAM] squishy

  • [IAM] Member
  • Highly Active
  • *****
  • Posts: 568
  • Serious Business
    Points:
    71
  • I void warranties
    • View Profile
Re: DD-WRT SSH firewalling.
« Reply #7 on: September 09, 2010, 10:01:52 AM »
i think he means he just opened up those ports on his firewall.

not the most secure, but gets the job done
(15:36:10) Magnet: u only say WoW sucks when 1. u suck ass 2. u have terrible gear 3. u suck ass
_____________________________________________________________________________________

Offline CaptainWTF

  • Highly Active
  • ****
  • Posts: 1941
  • Serious Business
    Points:
    -1523
    • View Profile
Re: DD-WRT SSH firewalling.
« Reply #8 on: September 09, 2010, 01:37:59 PM »
No I have nothing of the such done lol. I have forwarded NOTHING. In putty I set up dynamic ports. I have NO port changes on the router
"Tell the firewall to fuck off"
"Don't be an asshat. No one likes asshats. A cap is alright. A hat is nice. having an ass is compulsory. Combining an ass and a hat? Not a good idea, take it off."





___
Corsair 800D
AsRock 770 Extreme 3 motherboard
Phenom II x3 720 BE (4th core unlocked. OC'd to 4.2ghz)
8gb G.Skill Ripjaw memory @ 667mhz
EVGA GTX 560 Ti video card @ 900mhz W/ Arctic Cooling Accelero Xtreme Plus II
Samsung 830 series 128gb SSD
OCZ StealthXStream2 700w PSU
APC BX1500G 865w UPS