4 ms·
Have you tried knockd https://linux.die.net/man/1/knockd https://linux.die.net/man/1/knockd ? You send a special sequence of "knocks" to the server (packets to
by ff7c11 6y ago
Have you tried knockd https://linux.die.net/man/1/knockd https://linux.die.net/man/1/knockd ? You send a special sequence of "knocks" to the server (packets to different ports) and it executes a command such as allowing your IP for a time period. No JWTs.
- yearoflinux 6y agoThis is very nice and renders the OP useless. OP itself is another attack vector. Do you know what syscall API knockd uses to listen to "link" ?
- thedanbob 6y agoMy go-to is fwnop (https://www.cipherdyne.org/fwknop/ https://www.cipherdyne.org/fwknop/) which is actually similar to the OP’s thing but battle tested. Only downside is it’s not available on iOS, so recently I setup WireGuard for my iPad. And yes, ssh pubkey + fwnop + WireGuard + fail2ban is ridiculous overkill, but hey, it’s my homelab server. That’s how I learn this stuff.