Posts: 6
Joined: Thu Apr 27, 2017 7:54 pm

portknocking not work

Post by faustf » Thu Feb 01, 2018 5:12 pm

hi guys i have a little problem with portknocking in port 22
i have a "server" with open ssh , i configure iptables like this

sudo iptables -S
-A INPUT -i lo -j ACCEPT
-A INPUT -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT
-A INPUT -p tcp -m tcp --dport 5900 -j ACCEPT
-A INPUT -p tcp -m tcp --dport 5800 -j ACCEPT
and i follow this tutorial
and i use example 1
in client side i run a command

 knock -v 7000 8000 9000
hitting tcp
hitting tcp
hitting tcp
but after and before a command knock , if i run nmpa i have this answer

Starting Nmap 6.40 ( http://nmap.org ) at 2018-02-01 21:51 CET
Nmap scan report for
Host is up.
All 1000 scanned ports on are filtered

Nmap done: 1 IP address (1 host up) scanned in 201.30 seconds
and obviusly if i try to connect with ssh not connect

the log file is blank

anyone can help me ??? thankz at all

Posts: 7826
Joined: Fri Oct 12, 2012 9:44 pm
Location: Australian Antarctic Territory

Re: portknocking not work

Post by catweazel » Fri Feb 02, 2018 1:23 am

faustf wrote:port 22
Try port 2200. Ports below 1024 are protected in linux.
