05-15-2008
Well, the simplest way to achieve something like this (for *nix) is to link your app with libwrap:
libwrap - Wikipedia, the free encyclopedia and then bundle tcpwrappers + a sample hosts.allow and hosts.deny with your product.
I'm sure windows has similar api functionality for their packet filter.
Alternatively you can come up with an internal packet filter for the application based on a configuration file, parser and logic that you devise.
It's very simple in theory...An ip based ruleset is created via flat file, xml, etc.., then on a client connect the ruleset is parsed, the client address is
compared for exclusion. If exclusion is indicated the connection is closed with no further processing except, perhaps, for a log notice, otherwise the client
is serviced.
Last edited by ramen_noodle; 05-15-2008 at 12:06 PM..
10 More Discussions You Might Find Interesting
1. IP Networking
Hello All
I am running redhat linux 7.2 and would like to know how i can block telnetting to a specified port .
say for example i would like to block telnet acesses to port 80.
regards
Xiamin (5 Replies)
Discussion started by: xiamin
5 Replies
2. UNIX for Dummies Questions & Answers
can anyone tell me a unix program that can port scan a c block of ips for proxies? a fast one, with reliable results, that can load an ip list, or set an ip range, and specify ports
thanks! (1 Reply)
Discussion started by: user
1 Replies
3. IP Networking
My server is running on a port 16386, in the case when this port is blocked by some other application ( anti virus etc. ) or firewall then how do i know it's block? Is bind will return any specific error in this case.
I have to know is it blocked or not? (2 Replies)
Discussion started by: Saurabh78
2 Replies
4. Linux
Hi,
I will like to allow access to the mysql port (3306) to certain IP address. All other IP's should be automatically blocked. What is the best way to do this? (8 Replies)
Discussion started by: shantanuo
8 Replies
5. Shell Programming and Scripting
Hi Folks,
I am not good in shell scripting. Please help me with my problem. Is it possible to block the file named "ss.cgi" using the port 25 to upload. (4 Replies)
Discussion started by: gsiva
4 Replies
6. Shell Programming and Scripting
Hello
I'm beginner in the linux scripting and i would like to get help. I want to create a script that can block one or more Port even see all the TCP port. The ports must be blocked even when starting my machine.
Of course requires a second script which will allow the ports that you want to... (0 Replies)
Discussion started by: houstaf
0 Replies
7. UNIX for Dummies Questions & Answers
I want to limit all *outbound* traffic on eth0 (or all *.*) on port 25 to a specific (allowed) range...
I.E.
192.168.1.5 (local ip) tries to connect to 1.2.3.4:25 (outside real world ip)
It can proceed because 1.2.3.0/24 is the allowed range
Now, 192.168.1.5 (local ip) tries to connect to... (1 Reply)
Discussion started by: holyearth
1 Replies
8. Solaris
please find the below o/p for your reference
bash-3.00# fcinfo hba-port
HBA Port WWN: 21000024ff295a34
OS Device Name: /dev/cfg/c2
Manufacturer: QLogic Corp.
Model: 375-3356-02
Firmware Version: 05.03.02
FCode/BIOS Version: BIOS: 2.02; fcode: 2.01;... (3 Replies)
Discussion started by: sb200
3 Replies
9. Web Development
Hello,
I am not sure that it's possible to set a server for explained below scenario:
I have ordered a second ip for my streaming server. Both ip addresses are set and well responding to my ping requests. LAMP is installed into server.
Assume that port 15678 is running for nginx. Admin port is... (0 Replies)
Discussion started by: baris35
0 Replies
10. Solaris
Hi,
I need to block ssh port 22 from all the servers except one server ip.
Until solaris11.3 and below, I used to do like below(under /etc/ipf/ipf.conf),and it's working fine
pass in quick from $server_ip to any port=22
block in quick from any to any port=22
But I tried almost same in... (1 Reply)
Discussion started by: Sumanthsv
1 Replies
LEARN ABOUT DEBIAN
ieee1284_open
IEEE1284_OPEN(3) Functions IEEE1284_OPEN(3)
NAME
ieee1284_open - open a port
SYNOPSIS
#include <ieee1284.h>
int ieee1284_open(struct parport *port, int flags, int *capabilities);
DESCRIPTION
In order to begin using a port it must be opened. Any initial set-up of the port is done at this stage. When an open port is no longer
needed it should be closed with ieee1284_close(3).
The possible flags are:
F1284_EXCL
This device cannot share the port with any other device. If this is the case it must be declared at this stage, so that other drivers
trying to access the port know not to bother; otherwise they will wait until this driver releases the port, i.e. never.
The iopl/dev-port access methods don't support this yet, but the ppdev ones do.
If capabilities is not NULL it must point to storage for an int, which will be treated as a set of flags, one per bit, which the library
sets or clears as appropriate. If a capability is present it will be used when asked for. They are:
CAP1284_RAW
Pin-level access is available. If this capability is present then the following functions are effective: ieee1284_write_data,
ieee1284_read_status, ieee1284_wait_status, ieee1284_write_control, ieee1284_read_control, ieee1284_frob_control.
CAP1284_NIBBLE
There is an implementation of nibble mode for this port.
CAP1284_BYTE
There is an implementation of byte mode for this port.
CAP1284_COMPAT
There is an implementation of compatibility mode for this port.
CAP1284_ECP
There is a hardware implementation of ECP mode for this port.
CAP1284_ECPRLE
There is an RLE-aware implementation of ECP mode for this port (the F1284_RLE flag is recognised by the ECP transfer functions).
CAP1284_ECPSWE
There is a software implementation of ECP mode for this port.
CAP1284_BECP
There is an implementation of bounded ECP mode for this port.
CAP1284_EPP
There is a hardware implementation of EPP mode for this port.
CAP1284_EPPSWE
There is a software implementation of EPP mode for this port.
CAP1284_IRQ
An interrupt line is configured for this port and interrupt notifications can be received using ieee1284_get_irq_fd(3).
CAP1284_DMA
A DMA channel is configured for this port.
RETURN VALUE
E1284_OK
The port is now opened.
E1284_INIT
There was a problem during port initialization. This could be because another driver has opened the port exclusively, or some other
reason.
E1284_NOMEM
There is not enough memory.
E1284_NOTAVAIL
One or more of the supplied flags is not supported by this type of port.
E1284_INVALIDPORT
The port parameter is invalid (for instance, the port may already be open).
E1284_SYS
There was a problem at the operating system level. The global variable errno has been set appropriately.
SEE ALSO
ieee1284_close(3)
AUTHOR
Tim Waugh <twaugh@redhat.com>
Author.
COPYRIGHT
Copyright (C) 2001-2003 Tim Waugh
09/18/2007 IEEE1284_OPEN(3)