store | blogs | forums | twitter | facebook | wiki | mailing lists | downloads | support portal
Atomic Secure Linux
It is currently Fri May 24, 2013 8:42 pm

» Feed - Atomicorp

All times are UTC - 5 hours [ DST ]




Post new topic Reply to topic Share/Bookmark  [ 5 posts ] 
Author Message
 Post subject: ASL white list ip range
Unread postPosted: Wed Jun 13, 2012 12:42 pm 
Offline
Forum Regular
Forum Regular

Joined: Wed Jan 02, 2008 3:21 pm
Posts: 515
Location: United Kingdom
Hi, does ASL firewall bl/wl support subnets as follows:
Code:
asl -wl 0x0.0x0.0x0.0x0/28
asl -wl 0x0.0x0.0x0.0x0/27

And is this the best way?
Yes... this is to allow a PCI scan to complete :!: :x


Top
 Profile  
 
 Post subject: Re: ASL white list ip range
Unread postPosted: Wed Jun 13, 2012 3:23 pm 
Offline
Atomicorp Staff - Site Admin
Atomicorp Staff - Site Admin
User avatar

Joined: Thu Feb 07, 2008 7:49 pm
Posts: 3249
Location: Chantilly, VA
Quote:
Hi, does ASL firewall bl/wl support subnets as follows:


Yes, the blacklist and whitelists support CIDRs.

Quote:
And is this the best way?


This:

asl -wl 0x0.0x0.0x0.0x0/28

I assume you just redacted the range, but if not, no that wont work its not valid.

_________________
Michael Shinn
Atomicorp - Security For Everyone

Co-Author of Troubleshooting Linux Firewalls.


Top
 Profile  
 
 Post subject: Re: ASL white list ip range
Unread postPosted: Thu Jun 14, 2012 11:35 am 
Offline
Forum Regular
Forum Regular

Joined: Wed Jan 02, 2008 3:21 pm
Posts: 515
Location: United Kingdom
I take from your response that entering: 0x0.0x0.0x0.0x0/28 in /etc/asl/whitelist will work, but not via cli. Tested and working. Thanks


Top
 Profile  
 
 Post subject: Re: ASL white list ip range
Unread postPosted: Thu Jun 14, 2012 5:18 pm 
Offline
Atomicorp Staff - Site Admin
Atomicorp Staff - Site Admin
User avatar

Joined: Thu Feb 07, 2008 7:49 pm
Posts: 3249
Location: Chantilly, VA
It will work from the command line. For example, this:

asl -wl 10.0.0.0/8

Is valid.

This:

asl -wl 0x0.0x0.0x0.0x0/8

Thats not a valid address, its going to break lots and lots of things. You need to use a valid CIDR, in the form of decimals.

_________________
Michael Shinn
Atomicorp - Security For Everyone

Co-Author of Troubleshooting Linux Firewalls.


Top
 Profile  
 
 Post subject: Re: ASL white list ip range
Unread postPosted: Fri Jun 15, 2012 3:25 am 
Offline
Forum Regular
Forum Regular

Joined: Wed Jan 02, 2008 3:21 pm
Posts: 515
Location: United Kingdom
OK, understood, the 0x0 was meant to represent decimal.decimal.decimal.decimal, my bad.


Top
 Profile  
 
Display posts from previous:  Sort by  
Post new topic Reply to topic Share/Bookmark  [ 5 posts ] 

» Feed - Atomicorp

All times are UTC - 5 hours [ DST ]


Who is online

Users browsing this forum: Google [Bot] and 1 guest


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to:  
Powered by phpBB © 2000, 2002, 2005, 2007 phpBB Group