All shared-*-whitelist are created to share the domains that the script uses with other scripts so they don't accidentally block each other from downloading content they need to run.Hello
Maybe i use it the wrong way, but when i want to use a custom url to get lists (i selected some lists from Firehol), it parse it without errors, but i can find all urls from my list in /jffs/shared-Skynet-whitelist... Lists selected are to be banned, not whitelist :/
Thanks
To add to the above post:Lists selected are to be banned, not whitelist :/
Hello
Maybe i use it the wrong way, but when i want to use a custom url to get lists (i selected some lists from Firehol), it parse it without errors, but i can find all urls from my list in /jffs/shared-Skynet-whitelist... Lists selected are to be banned, not whitelist :/
Thanks
sh /jffs/scripts/firewall banmalware google.com/filter.list
Do you know why port scans are not blocked ?
By "SPI firewall", do you mean Trendnet DPI engine ?
The firewall is configured to distinguish legitimate packets for different types of connections. Only packets matching a known active connection are allowed to pass the firewall. Stateful packet inspection (SPI), also referred to as dynamic packet filtering, is a security feature often included in business networks.
By expected results, do you mean
I don't know why port scanning tool can scan and find my open ports without being blocked and banned
With IPSET_Block.sh it was ok but now without this script (in conflict with yours so i removed it) it's not protected...
For example, on http://www.inoculer.com/scannerdeports.php , with 80 and 443 opened :
Before (with IPSET_Block.sh) i get all ports "filtered"
After (with Skynet) i get all filtered except ports 80 and 443 "opened"
Does Skynet do the same ? or does it rely on list only ?"Dynamically block unsolicited access attempts using IPSETs. Useful if you have opened ports >1024 as hopefully hackers will start their attempts at the more common ports e.g. 22,23 etc. so will be banned BEFORE they reach your port!"
Does Skynet do the same ? or does it rely on list only ?
That script is literally a copy and paste of a 6 month old version of Skynet with some modifications, non really changing overall functionality.
Welcome To SNBForums
SNBForums is a community for anyone who wants to learn about or discuss the latest in wireless routers, network storage and the ins and outs of building and maintaining a small network.
If you'd like to post a question, simply register and have at it!
While you're at it, please check out SmallNetBuilder for product reviews and our famous Router Charts, Ranker and plenty more!