Geekzone: technology news, blogs, forums
Guest
Welcome Guest.
You haven't logged in yet. If you don't have an account you can register now.



233 posts

Master Geek


Topic # 96648 1-Feb-2012 11:02 Send private message

Hello,

Does anyone know the IP range that's allocated to XT Mobile connections?
I want to put an exception into the firewall to allow connections from my mobile without port knocking.
So far I've seen that they have (at least) 115.189.0.0/16 but this is likely to be used by xtra or other parts as well.

Thanks. 

Create new topic
13316 posts

Uber Geek

Trusted
Vodafone NZ
Subscriber

  Reply # 575773 1-Feb-2012 11:03 Send private message

Not a good idea as the IP range is not static

John




Systems Engineer Vodafone NZ

http://forum.vodafone.co.nz

903 posts

Ultimate Geek

Trusted
Telecom NZ

  Reply # 575777 1-Feb-2012 11:06 Send private message

There is this old blog post from NealR.

But I am not sure if it has changed / been updated for a while.  Will go and ask him.




I work for Telecom, but as always my views are my own.



233 posts

Master Geek


  Reply # 575786 1-Feb-2012 11:15 Send private message

Great stuff, thank you.

It's not a big deal if some subnets change as I also have port knocknig enabled if I get an IP address from a new subnet.
I'm not too concerned about security implications as I'll only allow ssh and it's extremely unlikely to have brute force attacks from XT phones. Also, fail2ban will do its job if need be.

Thanks again, if you have an update on the subnet list posted above it would be appreciated.

903 posts

Ultimate Geek

Trusted
Telecom NZ

  Reply # 575792 1-Feb-2012 11:38 Send private message

Neal said he tries to keep it up to date however this is done on a best efforts basis so you should assume it could radically change without warning.




I work for Telecom, but as always my views are my own.



233 posts

Master Geek


  Reply # 575795 1-Feb-2012 11:39 Send private message

Understood, thanks again.

2379 posts

Uber Geek

Trusted
Subscriber

  Reply # 575797 1-Feb-2012 11:47 Send private message

TBH this is a dumb idea as the ranges could change without warning. If you want to do this then get a static IP.

Fail2ban should be good enough....







233 posts

Master Geek


  Reply # 575798 1-Feb-2012 11:51 Send private message

As I said earlier, I have a port-knocking solution in place. The allowing of the range saves me a click to launch the 'knock app'. If the range changes, I just launch the knock app and that's that.

Not sure if (how) I can get a static IP on my XT-Mobile.

903 posts

Ultimate Geek

Trusted
Telecom NZ

  Reply # 575801 1-Feb-2012 11:55 Send private message

tcpdump: As I said earlier, I have a port-knocking solution in place. The allowing of the range saves me a click to launch the 'knock app'. If the range changes, I just launch the knock app and that's that.

Not sure if (how) I can get a static IP on my XT-Mobile.


You can get a Private APN.  But that comes at a cost.




I work for Telecom, but as always my views are my own.

6895 posts

Uber Geek

Trusted
Subscriber

  Reply # 575857 1-Feb-2012 13:20 Send private message

Why not just setup a vpn, most smartphone support various vpn connection options.



233 posts

Master Geek


  Reply # 575859 1-Feb-2012 13:23 Send private message

The firewall is denying everything, including VPN. After a successful knock (or if the IP address/range is in a whitelist) ssh/vpn is being allowed.

Yes, I can be even more paranoid if required ;)

6895 posts

Uber Geek

Trusted
Subscriber

  Reply # 575863 1-Feb-2012 13:27 Send private message

Hah fair enough!

Create new topic



Twitter »
Follow us to receive Twitter updates when new discussions are posted in our forums:



Follow us to receive Twitter updates when news items and blogs are posted in our frontpage:



Follow us to receive Twitter updates when new jobs are posted to our jobs board:



Follow us to receive Twitter updates when tech item prices are listed in our price comparison site:




News »

Trending now »
Hot discussions in our forums right now:

Fecked up religious people strike again :-(
Created by Mark, last reply by NonprayingMantis on 24-May-2013 10:58 (52 replies)
Pages... 2 3 4


Cannabis is illegal yet we have really strong 'legal highs' ?
Created by qwerty7, last reply by freitasm on 23-May-2013 23:20 (74 replies)
Pages... 3 4 5


Xbox One
Created by DjShadow, last reply by macuser on 24-May-2013 11:25 (59 replies)
Pages... 2 3 4


A new project coming to Geekzone
Created by freitasm, last reply by hairy1 on 24-May-2013 12:18 (294 replies)
Pages... 18 19 20


HTC One (2013) owners' discussion
Created by Dingbatt, last reply by Lipex666 on 24-May-2013 11:23 (1556 replies)
Pages... 102 103 104


Orcon, Is this for real or a scam??
Created by old3eyes, last reply by DarthKermit on 22-May-2013 19:12 (29 replies)
Pages... 2


Vodafone Naked Broadband Speeds (Auckland CBD)
Created by wscalioni, last reply by grkiwi on 20-May-2013 21:13 (14 replies)

Entire house HTPC concept
Created by InfiniteLoop, last reply by darthmeow on 24-May-2013 12:19 (26 replies)
Pages... 2



Geekzone Jobs »
Most recent NZ jobs in technology:

Lead Customer Insights Developer
Posted 24-May-2013 12:28

BI Architect
Posted 24-May-2013 12:28

Solution Selling BDM
Posted 24-May-2013 12:28

BI Specialist
Posted 24-May-2013 12:28

SSRS Reporting Specialist
Posted 24-May-2013 12:28

Help Desk Administrator
Posted 24-May-2013 12:28

SQL Developer & DBA reporting specialist
Posted 24-May-2013 12:28


Geekzone Live »
Try automatic live updates from Geekzone directly in your browser, without refreshing the page, with Geekzone Live now.

Are you subscribed to our RSS feed? You can download the latest headlines and summaries from our stories directly to your computer or smartphone by using a feed reader.

Alternatively, you can receive a daily email with Geekzone updates.