Blocking SSH to server

Comments

5 comments

  • Avatar
    Ron Y

    I'm not looking to open a port for external access. I am looking to block all local SSH to the server. 

    0
    Comment actions Permalink
  • Avatar
    FirewallaSupportDesk

    It depends on your network topology. If the device and the server are in the same LAN, and they are behind a switch, the local flow will just go over the switch, and won't traverse through Firewalla box; Hence, Firewalla is not able to monitor such local flows. Local Network Flows 

    0
    Comment actions Permalink
  • Avatar
    Bob O'Hara

    If it is possible with your wiring, it would be easiest to configure another port on the Firewalla to also carry the LAN. Then plug only your server into that Firewalla port. This ensures all the traffic to the server can be examined (and blocked) by the Firewalla.

    0
    Comment actions Permalink
  • Avatar
    Ron Y

    Thanks for the help. Makes sense that not all the traffic was being monitored and that's what I was missing. I was hoping to centralize access control on the firewalla device, but will now setup ACL on my omada switch to handle this.

    0
    Comment actions Permalink

Please sign in to leave a comment.