Want to protect your cyber security and still get fast solutions? Ask a secure question today.Go Premium

x
  • Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 672
  • Last Modified:

is there a way to 'hosts allow' depending on which mountpoint?

I have a mountpoint I would like to be accessible from the local LAN without a password, but also be accessible from outside the LAN with a password. 'hosts allow' seems to restrict ALL IPs. Is there a way to NOT permit a particular mountpoint if the host IP is outside the LAN?

Here's what I've got (with no 'hosts allow' configured):

[webcontent]
comment = Mountpoint for intra-LAN
writable = yes
path = /this/path
public = yes
guest ok = yes
guest only = yes
guest account = smith
browsable = yes

[website]
comment = Mountpoint for extra-LAN
valid users = smith
path = /this/path
public = yes
writeable = yes
browseable= yes
printable = no

Open in new window


This specifies a mountpoint to the same path for the same user (smith), but mounting 'website' will require a password and mounting 'webcontent' will not.

The problem here is that someone outside the office LAN can still mount the w/o PW mount point. That's what I want to prevent.
0
jmarkfoley
Asked:
jmarkfoley
  • 2
  • 2
1 Solution
 
AggieTexCommented:
[Webcontent]
hosts allow = 127.0.0.1 192.168.1.  #Whatever your internal lan is
hosts deny = ALL

Then just restart your smb service.
#service smb restart
0
 
jmarkfoleyAuthor Commented:
Thanks! I didn't realize I could use the hosts allow inside a mountpoint definition. Do I need the hosts deny? I've never used that with a hosts allow before ... seems like it would undo the allow.
0
 
AggieTexCommented:
Yes, you need to include the hosts deny = all.  It will basically deny everyone except for the addresses you include in hosts allow.  Without it, people outside would still be able to access the share since there is no rule to actually deny them access.
0
 
jmarkfoleyAuthor Commented:
OK, thank!
0

Featured Post

Technology Partners: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

  • 2
  • 2
Tackle projects and never again get stuck behind a technical roadblock.
Join Now