[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: Remote administration of a machine behind NAT



On Tue, Sep 09, 2008 at 01:12:28AM +0300, Andrei Popescu wrote:
> On Tue,09.Sep.08, 07:51:30, Alex Samad wrote:
>  
> > > Or do you have any other ideas?
> > 
> > openvpn + iptables.
> > 
> > Use openvpn with cert's to create a tunnel and then use iptables on your
> > end to block any traffic, until you want to use it.
> 
> Of course I use iptables on my box and the firewalls integrated in the 
> ADSL modem and the wireless router. I'm trying to protect myself from 
> some possible rootkit on my mothers laptop accessing mine while I do 
> routine administration on hers. Am I too paranoid?

don't see the difference between connectivity via the internet or via an
openvpn network, if your rule states only allow ssh (+ related traffic +
only if it originates from your machine )
over the openvpn network 

You can never be too paranoid, but within reason

> 
> Regards,
> Andrei
> -- 
> If you can't explain it simply, you don't understand it well enough.
> (Albert Einstein)



-- 
How doth the little crocodile
	Improve his shining tail,
And pour the waters of the Nile
	On every golden scale!

How cheerfully he seems to grin,
	How neatly spreads his claws,
And welcomes little fishes in,
	With gently smiling jaws!
		-- Lewis Carrol, "Alice in Wonderland"

Attachment: signature.asc
Description: Digital signature


Reply to: