Re: [opensuse] ssh problem from remote LAN



From: "Carl Hartung" <suselinux@xxxxxxxxxxxxx>
On Tue January 30 2007 13:28, James D. Parra wrote:
Hello,

Set up a SLES 10 server and although I can ssh to it from any box on the
local LAN I can't get to it from a remote LAN even though I can ssh to any
other box on the local LAN via ssh.
<snip>

Hi James,

After mulling your post over since yesterday, the thought occurred to me that
you might be troubleshooting the wrong device. Is it possible the router
connecting the local LAN to the Internet has previously been configured to
enable port-forwarding to the other clients?

regards,

Carl

I thought about that too. But, if the router is providing NAT for the LAN, then it doesn't make sense that it (a simple router) would be able to configure port forwarding of an incoming ssh requrest to multiple clients behing the router. Generally, the router will only port forward requests to a single machine on the LAN side. My question would be how is the router configured and how is James ssh'ing to the other machines on the LAN across the router.

My initial thoughts on the problem were a misconfigured /etc/ssh/sshd_conf; a non-running sshd on the SLES machine; or a problem with the /etc/hosts.allow or /etc/hosts.deny setup.

HTH.


--
David C. Rankin, J.D., P.E.
510 Ochiltree Street
Nacogdoches, Texas 75961
(936) 715-9333
(936) 715-9339 fax
www.rankinlawfirm.com
--

--
To unsubscribe, e-mail: opensuse+unsubscribe@xxxxxxxxxxxx
For additional commands, e-mail: opensuse+help@xxxxxxxxxxxx



Relevant Pages

  • Re: ssh: No route to host
    ... >by NAT config, but I assume you mean that I'm pinging the router but not ... you have ssh server that has a private ... Therefore, if you have several ssh serveurs in your LAN, you need them ...
    (Debian-User)
  • Re: ssh: No route to host
    ... >> NAT translation is not a concept i can resume in some lines. ... >> listening for ssh connection onto port 22. ... >> when you do a ssh request on that routeur, the router pass the ... >> request to the right machine of your LAN. ...
    (Debian-User)
  • Re: ufsdump via ssh of remote file system to local tape
    ... You mean you can SSH in but can't SSH out or ... The machine with the tape drive is on the LAN interface of a router. ... You can *not* ssh from the DMZ to the LAN, but you can ssh from the LAN to the DMM or from the DMZ to the internet as a whole. ...
    (comp.unix.solaris)
  • Re: router access through ssh
    ... router from the command prompt. ... Access to SSH should be limited to trusted hosts, ... You can always disable WAN access to the router's config page, ... forward a port on a machine in the LAN back to the router. ...
    (comp.security.ssh)
  • Re: Safest way of accessing a home computer from outside?
    ... what if I my router doesent have a public IP ... I agree - ssh with no password and then use certificates to ... use for ssh is forwarded to your ssh server. ... You can find Hamachi at ...
    (Fedora)