I haven’t yet covered TCPwrappers, a popular tool for adding logging and access controls to services run from inetd , mainly because inetd is of limited usefulness on a bastion host (see why I think so in Section

But TCPwrappers has an access-control mechanism that restricts incoming connections based on remote clients’ IP addresses, which is a handy way to augment application security. This mecha...


TCP wrapper