Iptables is not blocking an ip?

chrisl at xp.etowns.net chrisl at xp.etowns.net
Mon Jul 24 14:24:18 UTC 2006


At one of my customers sites I have iptables configured to drop all ssh packets unless they originate from one of two addresses. However in logwatch, I had login attempts though SSH. 

 Illegal users from:
    220.193.2.37: 6 times

Now the address above is not one on the allowed list. Is it possible that they were able to get past iptables to attempt the login?




More information about the users mailing list