[nos-bbs] JNOS 2.0 can now use ipset list for firewalling
Maiko Langelaar (Personal)
maiko at pcsinternet.ca
Fri Aug 7 10:56:15 EDT 2026
Unfortunately, this turns into a video game at times, in other
words, it can lead to addictive behaviour ... just saying ....
So now, each time I see a JNOS log entry :
09:41:59 network: 91.x.y.z:55602 - [encap] no UDP (24698) listener
Or a webserver (on linux side) log entry :
2.a.b.c - - [07/Aug/2026:09:45:09 -0500] "GET /jnos2/downloads/linux/
HTTP/1.1" 301 296
I can add both of them to the one ipset, which protects both JNOS and linux
side systems. I mean this is quite simplistic, could setup multiipset
lists, but
that is the approach (evolving over time) I have been using for a while.
Depending where these IP are geolocated, I add them as /16 ...
Quite amazing how little 'no listener' JNOS log entries there are now :]
Maiko
More information about the nos-bbs
mailing list