APF Linux Firewall Open Port 22 From Specific / Selected IP Address Only

Q. I’ve CentOS Linux server configured with APF firewall. How do I open port 22 from specific IP address only? I’ve fix static ADSL IP address assgined and I’d like to open port 22 from my IP 202.5.1.3 only using APF firewall script. How do I configure firewall?

A. You need to edit two files:

ADVERTISEMENTS

a) /etc/apf/conf.apf – Main configuration file

b) /etc/apf/allow_hosts.rules – File to allow host wise configuration. You can set trust based rulesto grant access all or specific IP and port via the firewall.

APF Configuration

Open file /etc/apf/conf.apf, enter:
# vi /etc/apf/conf.apf
Find line that read as follows:
IG_TCP_CPORTS="20,21,22,25,53,80,110,143,443,3306"
ake sure you remove 22 from the list, so that it read as follows:
IG_TCP_CPORTS="20,21,25,53,80,110,143,443,3306"
Save and close the file. Now, open /etc/apf/allow_hosts.rules
# vi /etc/apf/allow_hosts.rules
Allow incomming SSH (TCP port # 22) traffic from your own ADSL connection only 202.5.1.3, append following text.
tcp:in:d=22:s=202.5.1.3
Save and close the file. Restart APF firewall:
# /etc/init.d/apf restart

🐧 Get the latest tutorials on SysAdmin, Linux/Unix, Open Source/DevOps topics:
CategoryList of Unix and Linux commands
File Managementcat
FirewallAlpine Awall CentOS 8 OpenSUSE RHEL 8 Ubuntu 16.04 Ubuntu 18.04 Ubuntu 20.04
Network Utilitiesdig host ip nmap
OpenVPNCentOS 7 CentOS 8 Debian 10 Debian 8/9 Ubuntu 18.04 Ubuntu 20.04
Package Managerapk apt
Processes Managementbg chroot cron disown fg jobs killall kill pidof pstree pwdx time
Searchinggrep whereis which
User Informationgroups id lastcomm last lid/libuser-lid logname members users whoami who w
WireGuard VPNAlpine CentOS 8 Debian 10 Firewall Ubuntu 20.04

ADVERTISEMENTS
2 comments… add one
  • Anymous Sep 2, 2009 @ 4:41

    thanks for the ip adress will hack it soon

  • LuZiFeR Nov 14, 2010 @ 10:40

    Yeah :D Also you could start scanning ‘0.0.0.0 – 255.255.255.255’ ;D

Leave a Reply

Your email address will not be published.

Use HTML <pre>...</pre>, <code>...</code> and <kbd>...</kbd> for code samples.