Dennis__Lauder_
Feb 14, 2007Nimbostratus
iRULE to drop in-bound ssh connections
I am looking for an iRULE to drop in-bound ssh connections if they are not from an accepted network.
Here is my first attempt:
class allowed_client_IP {
"x.x.x.x"
}
when CLIENT_ACCEPTED {
log local0. "IP [IP::client_addr] Tried to connect"
if { not [matchclass [IP::client_addr] eq [$::allowed_client_IP]]} {
drop}
}
I get the following error:
01070151:3: Rule [ssh_allow] error:
line 1: [undefined procedure: class] [class allowed_client_IP {
"x.x.x.x"
}]
Thanks, Dennis