Author Topic: How to block ssh and email attachements in zentyal  (Read 2209 times)

Zent User

  • Zen Warrior
  • ***
  • Posts: 121
  • Karma: +1/-3
    • View Profile
How to block ssh and email attachements in zentyal
« on: October 13, 2012, 07:40:15 am »
I'm using zentyal2.2 as a my gateway,how can I implement following things in zentyal

    1. Need to block ssh
    2. How can restrict on email attachments size.For example,I've a account in gmail,then I can send mails with an attachment upto 1Mb after that I should allow user to upload more this size.

Thanks in advance
Regards
Zent User

christian

  • Guest
Re: How to block ssh and email attachements in zentyal
« Reply #1 on: October 13, 2012, 09:07:46 am »
I'm using zentyal2.2 as a my gateway,how can I implement following things in zentyal
1. Need to block ssh

If you look at nework services, there is already one for SSH.
You can them easily, in firewall, block this service for either access to Zentyal box or access to internet depending on your need that is not clear here.

Quote
    2. How can restrict on email attachments size.For example,I've a account in gmail,then I can send mails with an attachment upto 1Mb after that I should allow user to upload more this size.

We discussed this yesterday already isn't it  ???
I mean you can ask 01 times, until you specifit better your scenario or Zentyal add some new feature, it is very unlikely that answer changes  :P

Zent User

  • Zen Warrior
  • ***
  • Posts: 121
  • Karma: +1/-3
    • View Profile
Re: How to block ssh and email attachements in zentyal
« Reply #2 on: October 15, 2012, 02:13:12 pm »
I've written rule for internal networks to block the ssh,even though I'm unable to block the ssh,where it is going wrong Mr.christian :)
« Last Edit: October 15, 2012, 02:14:49 pm by Mahesh »
Regards
Zent User

christian

  • Guest
Re: How to block ssh and email attachements in zentyal
« Reply #3 on: October 15, 2012, 02:49:26 pm »
it look OK, at least from my seat.
When I apply same rule to prevent access to external web site (using its IP), it works.

What do you try to prevent exactly? I mean where is/are SSH servers you want to prevent access to?

Zent User

  • Zen Warrior
  • ***
  • Posts: 121
  • Karma: +1/-3
    • View Profile
Re: How to block ssh and email attachements in zentyal
« Reply #4 on: October 15, 2012, 02:54:25 pm »
Suppose in my network two systems are there,whose ip#1:192.168.5.12 and ip#2:192.168.5.14.Currently ip#1 machine can be accessed by ssh from ip#2 machine and vice-verse.I want prevent this,then what should I do,at a time I want to log this events also.
Regards
Zent User

christian

  • Guest
Re: How to block ssh and email attachements in zentyal
« Reply #5 on: October 15, 2012, 03:28:11 pm »
ouch !!!!  :o  you can't so this with Zentyal neither any other system that will not be deployed between 192.168.5.12 and 192.168.5.14.
Communication between these 2 machines is direct.
If you want to control access to some machines, you could still "install" it on dedicated network segment and control access using Zentyal FW.

Hint: could be VLAN

Zent User

  • Zen Warrior
  • ***
  • Posts: 121
  • Karma: +1/-3
    • View Profile
Re: How to block ssh and email attachements in zentyal
« Reply #6 on: October 15, 2012, 03:43:52 pm »
Why can't Zentyal won't control,here any how gateway is zentyal na.Zentyal DHCP itself assigning these IP's to the system.
Regards
Zent User

christian

  • Guest
Re: How to block ssh and email attachements in zentyal
« Reply #7 on: October 15, 2012, 05:05:34 pm »
because once IP addresses are allocated, evne if you stop your Zentyal server, devices that are one same network segment can "see" each others and will not go through Zentyal server to communicate. This is that simple.

Or your network is not what I understand and you should explain further your design.

Zent User

  • Zen Warrior
  • ***
  • Posts: 121
  • Karma: +1/-3
    • View Profile
Re: How to block ssh and email attachements in zentyal
« Reply #8 on: October 16, 2012, 06:32:03 am »
At least is it possible to block ssh from internal network to external network,or you have any confusion here also :) !!!

Network Design : ISP--->Router---->Zentyal etho---->Zentyal eth1---->Switch--->Individual Systems

Anyhow thanks for your support
Regards
Zent User