Hi,
I have a smb server on manjaro architect.
I’d want the smb server:
1- to be accessible only on specific interfaces
2- to be advertised only on specific interfaces
For n.1 it’s quite simple, I just added to global configuration:
interfaces = lo br1
bind interfaces only = yes
br1 is a bridge without internet access (192.168.2.x)
I have also br0 (192.168.1.x), another bridge with internet access.
If from another computer I connect to the 192.168.1.x network I can see the smb server available (but obviously not accessible because of n.1).
Is it possible to prevent the server to be shown on br0 network and more in general on all the other networks different from lo and br1 for this specific case?
ufw allow from 192.168.2.0/24
ufw allow out from any to 192.168.2.0/24
ufw allow out 53
ufw allow out http
ufw allow out https
ufw allow out from 192.168.2.1 to 224.0.0.251
I had also to add:
# ok icmp codes for OUTPUT
-A ufw-before-output -p icmp --icmp-type echo-request -j ACCEPT
to before.rules file to make ping to work properly