Re: Somewhat OT -- Looking for ideas on how to test status of SSH TCP tunnel

From: Leonard Isham (leonard.isham_at_gmail.com)
Date: 11/03/05

  • Next message: akonstam_at_trinity.edu: "Re: [FC4] Audio no longer works after upgrade from FC 1"
    Date: Thu, 3 Nov 2005 16:52:56 -0500
    To: For users of Fedora Core releases <fedora-list@redhat.com>
    
    

    On 11/3/05, Bruce McPeek <brucem@vidiator.com> wrote:
    >
    >
    > Hello,
    >
    > I am planning on setting up a TCP tunnel through an SSH connection between
    > our Korean office's intranet and our US office's intranet. This tunnel will
    > be used to provide a connection between a Perforce Proxy server in Korea and
    > our main Perforce server (Redhat 9) in the US.
    >
    > The OS for Korean proxy server will be Redhat FC3 using OpenSSH. I may have
    > to give up this server at some point in the future and go Windows as the
    > underlying OS, if that happens I would like to use Plink (from the maker of
    > PuTTY http://www.chiark.greenend.org.uk/~sgtatham/putty/).
    >
    > I plan to set up the account used to connect our SSH server to a pretty
    > restricted state; no login shell and port forwarding restricted to a
    > specific ip:port.
    >
    > I am planning to script the SSH connection on the client side to reconnect
    > should the connection drop. This should be a fairly trivial task.
    > Unfortunately I have seen long running SSH tunnels in a state where they
    > appear to be connected but no data flows through the tunnel or to the login
    > shell. I would like test for this condition in my script but I am unsure
    > which approach to take.
    >
    > I could conceivably try to connect through the tunnel to the server using
    > some utility but which one? I could conceivable try using the Perforce
    > client but would rather not consume a license to do this. Perhaps I could
    > open have a second tunnel open just to test the connection, but what would
    > be good to use?
    >

    I don't know that there is a solution for this issue.

    If I where you I would consider using OpenVPN (www.openvpn.net). It is
    designed for this type pf application. Has the ability to reconnect
    if a connection is lost, Can use certificatres is cross platform,
    including having RPM available. Well supported and in active
    development.

    --
    Leonard Isham, CISSP
    Ostendo non ostento.
    -- 
    fedora-list mailing list
    fedora-list@redhat.com
    To unsubscribe: https://www.redhat.com/mailman/listinfo/fedora-list
    

  • Next message: akonstam_at_trinity.edu: "Re: [FC4] Audio no longer works after upgrade from FC 1"

    Relevant Pages

    • Re: Listening network port security
      ... socket server program I write or an ssh tunnel, ... you could do it with an SSH tunnel - but that creates ... an outage as long as the SSL connection was still initiated from the ... benefit over restricting the listening port to a single IP address. ...
      (comp.os.linux.security)
    • Re: What is The SSH?
      ... Building and Using SSH Tunnels ... What is an SSH tunnel? ... how to use it to make a connection to a server. ... You will need a working SSH client and server installation to build and test ...
      (microsoft.public.windows.server.networking)
    • Re: Secret Underground.
      ... There is no intentional connection* from the GWR running tunnel into ... the quarries. ... connection, which is one reason why the quarry surveys are so accurate... ... The easternmost shaft is at a point where the tunnel roof is close to ...
      (uk.rec.subterranea)
    • Re: Secret Underground.
      ... There is no intentional connection* from the GWR running tunnel into ... connection, which is one reason why the quarry surveys are so accurate... ... The easternmost shaft is at a point where the tunnel roof is close to the level of the workings, so that one's unlikely but not impossible. ... There wouldn't be any need either: when the munitions store was planned and in use, exit through any of the western quarries was easily possible. ...
      (uk.rec.subterranea)
    • Re: kernel:Disabling IRQ #23
      ... yesterday evening I lost the ssh connection to my server, ... The server contains 10 harddisks ... Something generated spurious IRQs on that IRQ line and caused the interrupt to be disabled. ...
      (Linux-Kernel)