For context, I am a pentester as my day job and it's not unusual for me to achieve catastrophic compromise of two or three different corporate networks in a single week. When it's not MS17-010 it's IBM WebSphere and HP DataProtector.
What I'm trying to do here is run my own networks securely, and I see no reason I should let any random intruder find out what services they can attack by portscanning.
@jennamagius a friend of portsentry then?
@krogoth Kiiiinda, yeah, except that shelling out to iptables is a rough way to live your life.
It's a good idea, but it needs to go further.
@krogoth I'm developing them! In the form of an SSH-like remote access service that has port knocking built in from the start.