HowtoForge Forums | HowtoForge - Linux Howtos and Tutorials

HowtoForge Forums | HowtoForge - Linux Howtos and Tutorials (http://www.howtoforge.com/forums/index.php)
-   General (http://www.howtoforge.com/forums/forumdisplay.php?f=25)
-   -   restrict user by location? (http://www.howtoforge.com/forums/showthread.php?t=60567)

vmos 14th February 2013 16:07

restrict user by location?
 
Good morning, we use ispconfig on many of our servers, but only as standalone instances. On each of these we've restricted access to the admin interface on our firewall and also with iptables.
We're giving some thought to using a clustered setup for our DNS and/or mail and we want to open the interface to give users access to manage their own DNS and that.
One of the potential problems with that potentially somebody could brute force the admin login and then get access to everything.

Sure we can use fail2ban to reduce the likelihood of this but is there anyway to eliminate the option entirely?

Either say that the admin user can only log in from a certain IP or can only log in to a certain server in the cluster, and then we'd restrict access to that server?

till 14th February 2013 16:12

Quote:

One of the potential problems with that potentially somebody could brute force the admin login and then get access to everything.
You can not brute force the ispconfig admin login as ispconfig blocks IP's aftersome failed login attempts automatically. Fail2ban is not required for that.

Quote:

Either say that the admin user can only log in from a certain IP or can only log in to a certain server in the cluster, and then we'd restrict access to that server?
The ispconfig login is a normal apache vhost, so you can use all kin of restrictions that are available for apache vhosts as additional protection.

vmos 15th February 2013 11:32

what we want is to make the login interface generally available, just not have the option to login as admin on the public interface, I'm not aware of how to do that via apache.

What method does ispconfig use to block brute force attempts other than fail2ban?

till 15th February 2013 11:38

Quote:

What method does ispconfig use to block brute force attempts other than fail2ban?
It tracks and blocks logins internally.


All times are GMT +2. The time now is 11:42.

Powered by vBulletin® Version 3.8.7
Copyright ©2000 - 2014, vBulletin Solutions, Inc.