Michael Cohen michael.cohen at netspeed.com.au
Wed Jan 10 13:40:21 GMT 2007

On Wed, Jan 10, 2007 at 11:16:23PM +1100, Daniel Black wrote:
> http://l7-filter.sourceforge.net/ (iptables based has ssh and ssl pattern 
> rules.) either say port 443 is allowed ssl or port 443 is not allowed ssh.

Note that its quite easy to tunnel one over the other (i.e. ssh over ssl or ssl
over ssh) so it might end up being a futile exercise. Daniels first suggestion
of white listing is probably the most workable.


