Closing ports in jail with ipfw
Ernie Luzar
luzar722 at gmail.com
Mon Dec 5 00:31:22 UTC 2016
marcel wrote:
> Hi there,
>
> I've created a jail and when I do a nmap on his IP, I can see that port
> 25 and 22 are open but I don't want. So i've tried to create an IPFW
> rule by adding 'ipwf -q add 00290 deny all from router to jail' to my
> host ipfw conf file and applied it but ports jail are still open. How
> can I close or open the ports of my jail ?
>
> Thanks !
You can not run nmap on the host targeting the jails ip. Doing so only
shows you open ports on the host. You have to run nmap from a computer
on a different public ip address targeting the public ip address
assigned to the jail. If jail is using a non-routeable ip address, nmap
is useless in looking for jail open ports.
More information about the freebsd-jail
mailing list