Back to tutorials
Key takeaways
- Portsentry works as a honeypot: it listens on TCP and UDP ports you do not use. Any connection to one of them can only be a reconnaissance scan, so the source IP is blocked at the firewall before the attacker has even found a real vulnerability.
- The decisive setting is
BLOCK_TCP/BLOCK_UDPin/etc/portsentry/portsentry.conf:0detects without blocking,1writes to/etc/hosts.deny(barely effective these days),2adds a firewall rule — the only genuinely useful option. KILL_ROUTEholds the actual blocking command, where$TARGET$is substituted with the attacker's IP:/sbin/iptables -I INPUT -s $TARGET$ -j DROPfor iptables, or a rich rule viafirewall-cmdwith--timeout=600under firewalld, which makes the block expire on its own.- By default Portsentry only covers unused ports below 1024. The advanced modes
TCP_MODE="atcp"andUDP_MODE="audp", enabled in/etc/default/portsentry(or/etc/sysconfig/portsentryon CentOS), extend the listener to every unassigned port: far more effective, but more exposed to false positives. - Validation:
sudo systemctl restart portsentry, annmap -p 1-1024launched from a machine whose IP you can afford to lose, watch/var/log/syslog, then runsudo iptables -L INPUT -nto see theDROPrule appear at the top of the chain. Manual unblock:sudo iptables -D INPUT -s BLOCKED_IP -j DROP.
What is Portsentry?
Portsentry is a proactive defense tool that acts as a "honeypot". It listens on TCP and UDP ports that you do not use. If an attacker attempts to connect to one of these ports (which is typical of a reconnaissance scan), Portsentry detects it immediately and can block the attacker's IP address at the firewall level.
Portsentry is a proactive defense tool that acts as a "honeypot". It listens on TCP and UDP ports that you do not use. If an attacker attempts to connect to one of these ports (which is typical of a reconnaissance scan), Portsentry detects it immediately and can block the attacker's IP address at the firewall level.
Why use Portsentry?
- Early detection: A port scan is often the very first step of an attack. Detecting it lets you block an attacker before they even find a real vulnerability.
- Deterrence: Automatically blocking scanners reduces the "noise" in the logs and discourages automated attacks.
- Lightweight: Consumes very few resources.
Prerequisites
- A Linux server (Ubuntu/Debian, CentOS/RHEL).
- Root access or sudo privileges.
- A firewall such as
iptablesorfirewalld.
Premium Content
This advanced tutorial is reserved for premium members.
9,90€ / month
- All advanced tutorials
- New content every week
- Progress tracking
- Cancel anytime