Re: Getting around corporate firewalls to access ssh server



On Fri, 17 Mar 2006 14:10:56 -0600, Moe Trin wrote:

On Thu, 16 Mar 2006, in the Usenet newsgroup comp.os.linux.networking, in
article <pan.2006.03.17.04.10.21.766593@xxxxxxxxx>, General Schvantzkoph
wrote:

On Thu, 16 Mar 2006 20:54:25 -0600, Moe Trin wrote:

From my view, clean address, resolves both ways, and a known port would
_probably_ get the best results. Security for you comes from having
good usernames. and running on up-to-date Linux (or similar).

When I wrote that, I wasn't aware of your use of their public keys. That
pretty well takes care of the security angle.

I checked my IP address using rblcheck and it's clean. I can try swapping
the ports on the two servers and put the release server on 22. Do you
think the problem is due to the fact that I'm using a non-standard port?

Not knowing your IP address, I can't say for sure, but I would guess that
to be a strong possibility. A lot is going to depend on the policies and
paranoia level at the customers. I'm at an R&D facility, and we're very
restrictive of what the users are allowed to do with the network. We do
monitor traffic (generally speaking "after the fact"), and we do have
filters on the routers. I mentioned we block access to "home" netblocks as
one example. We also block all protocols except TCP, UDP and ICMP, and
even there we don't allow "everything". I know that (with a few
exceptions) we block outbound connection starts (SYN) to ports over 1024,
and (again with exceptions) inbound connection starts to most ports. The
idea is that our users should be able to initiate "normal" connections to
remote systems that may reasonably be expected to be work related, and
that no Internet visible servers exist in the user segment of the network,
so there would be no reason to allow such inbound connections. (The
Internet visible stuff is in DMZs and separate networks.)

For those customers where you are having problems, a short note to the
network operations people (RFC2142 says "NOC@domain" and we do have a
mailbox with that name - but try the lower case, and 'postmaster'
addresses if it doesn't work) may elicit some explanation. Whitelisting
generally has to come from inside user requests, and I think someone here
already mentioned having a web page or email form letter that your
customers can use to explain their need to their network/firewall people.

Old guy

Thanks to everyone. I've switched my release server to port 22, hopefully
that will help. I've also e-mailed my IP address to my customers and told
them to contact their IT people and ask them to allow access to my server.
The customer that's having trouble right now is in Japan so I doubt if
I'll know anything before Monday.


.



Relevant Pages

  • Re: Hacked?
    ... have some kind of pointer to try to contact a computer on that network. ... Those are NetBIOS ports, and NetBIOS is somewhat chatty and can generate ... installing Zone Alarm on the computer in question would be ... > currently hosting the email server, DNS, as well ...
    (microsoft.public.security)
  • Re: IIS / Web Services Security threats
    ... You will be surprised to know, due to a recent virus attack on the perimeter network, the common ports have been closed too. ... I also develop Java applications which runs on weblogic server. ... Since, the entire world knows about port 80 and 443, I thought opening a specific port with IP Sec configuration may make the network little secure. ... My security team thinks allowing communication between the two IIS ...
    (microsoft.public.dotnet.framework.webservices)
  • Re: When do I choose for OUTBOUND or INBOUND in a protocol?
    ... Ori YosefiISA Server Team ... > tab I only checked the external network. ... >> If you want to allow access to iSpQ on the internal network, you should>> create a publishing rule that publishes these ports to the external> network. ...
    (microsoft.public.isa)
  • Re: When do I choose for OUTBOUND or INBOUND in a protocol?
    ... Regarding INBOUND and OUTBOUND. ... The usuall meaning of INBOUND is when you have a server in your "internal" ... network, usually being NATed, that ... defines the ports used by the application and then creating a publishing ...
    (microsoft.public.isa)
  • Re: How to spoof MAC-address in SuSE Linux?
    ... > that in their contracts and they threatened the customers and stuff. ... ran more then one PC on the network while it was not allowed to do so. ... Here there are several providers that close all ports till 1024 and some ... support you think you are going to get is gone. ...
    (alt.os.linux.suse)