Suggestion for time and date command set

This is a discussion on Suggestion for time and date command set within the IPFilter forums, part of the System Security and Security Related category; I think it would be useful if the rules for ipfilter supported a set of time-related commands, such as ...


Go Back   Usenet Forums > System Security and Security Related > IPFilter

FAQ Members List Calendar Search Today's Posts Mark Forums Read
  #1 (permalink)  
Old 10-04-2005
David Kirkby
 
Posts: n/a
Default Suggestion for time and date command set


I think it would be useful if the rules for ipfilter supported a set of
time-related commands, such as year, month, day, dayofweek, hour and
minute. Then you could set up rule sets that applied only on certainly
days, or certain time periods during the day.

Checkpoint supports something like this:
http://www.checkpoint.com/support/te...time.html#3101
and I'm told some Cisco products too.

I often wish ipfilter did too.

Sometimes I have set up rules that I would only like to last a week or
so, when perhaps someone is given temporary access to a computer. Rather
than try to remember to remove the rule, something like:

pass in quick on tun0 proto tcp from 123.123.123.123 to 20.20.20.1/32
port = 22 year = 2005 month = 10 day < 20 keep state

to allow ssh access from 123.123.123.123 between 1st October 2005 and
19th October 2005.


--
David Kirkby,
G8WRB

Please check out http://www.g8wrb.org/
of if you live in Essex http://www.southminster-branch-line.org.uk/


Reply With Quote
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are Off
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT +1. The time now is 12:52 PM.


Powered by vBulletin® Version 3.6.8
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.0.0