l i n u x - u s e r s - g r o u p - o f - d a v i s
L U G O D
 
Next Meeting:
April 21: Google Glass
Next Installfest:
TBD
Latest News:
Mar. 18: Google Glass at LUGOD's April meeting
Page last updated:
2004 Jul 15 16:43

The following is an archive of a post made to our 'vox-tech mailing list' by one of its subscribers.

Report this post as spam:

(Enter your email address)
Re: [vox-tech] ssh login slow with iptables
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [vox-tech] ssh login slow with iptables



Brilliant solution!  Thanks!

Samuel Merritt wrote:
Jack LaPlante said:

I'm setting up my nifty new dedicated web server with a firewall
like this: (I'm on RH9, the rpms look like the latest avail )

iptables -F
iptables -A INPUT -i lo -j ACCEPT
iptables -A INPUT -m multiport -p tcp --dport www,ssh,sftp,smtp,10000 \
-j  ACCEPT
iptables -A INPUT -j LOG -m limit
iptables -A INPUT -j REJECT

(an o'reilly setup from the linux security cookbook)

Now, when I log in via SSH or SFTP, there is a 30 second pause while my
password authorizes.  It used to take a second or two.  Flush the rules
and the login is up to speed again.

You don't allow inbound 53/udp, so your machine can't use DNS. By default,
sshd looks up the name of the connecting machine, and it looks like the
DNS lookup takes 30 seconds to time out.


I want to force my clients to use SFTP for all their file transfers but
the delay is going to be annoying.

Any suggestions to speed up my logins?

iptables -A INPUT --source $DNS_SERVER_IP_HERE -p udp --sport 53 -j ACCEPT

Assuming I got the syntax right, do that once for each DNS server you have.

--

                 	
	


--
 Jack LaPlante
 jlaplante@pwx.com
 ________________________________________

 Pyroglyph Inc.
 ________________________________________

        Clarity and Style
        For the Digital Age
 ________________________________________
  pyroglyph.com  pwx.com  uneasychair.com
_______________________________________________
vox-tech mailing list
vox-tech@lists.lugod.org
http://lists.lugod.org/mailman/listinfo/vox-tech



LinkedIn
LUGOD Group on LinkedIn
Sign up for LUGOD event announcements
Your email address:
facebook
LUGOD Group on Facebook
'Like' LUGOD on Facebook:

Hosting provided by:
Sunset Systems
Sunset Systems offers preconfigured Linux systems, remote system administration and custom software development.

LUGOD: Linux Users' Group of Davis
PO Box 2082, Davis, CA 95617
Contact Us

LUGOD is a 501(c)7 non-profit organization
based in Davis, California
and serving the Sacramento area.
"Linux" is a trademark of Linus Torvalds.

Sponsored in part by:
Appahost Applications
For a significant contribution towards our projector, and a generous donation to allow us to continue meeting at the Davis Library.