Re: httptunneling into a firewalled environment?



Bob Tennent wrote:
My daughter is about to take her Linux system into a firewalled
environment. I can't expect that the admins will be willing or able
to forward ssh or webmin to it. Can I set up something on it (and, if
necessary, on my system) that will give me a shell on her system when I
need to do some system administration on it? I thought maybe httptunnel
would do the trick but this seems to be used to connect from inside a
firewall out, and I want to go from the outside in.

I'm not a networking expert so please be detailed and explicit in your
instructions but I do know how to set up mechanisms to get her LAN IP
address and firewall IP address dynamically.

Bob T.

Hi,

If everything is blocked from the outside in by the admin (witch is 99% sure the case), for sure you wont be able to access services such as SSH or HTTP.

The solution I can see is the following:

You could configure a VPN server on your computer at home. If you are using a router, forward the proper VPN ports to this comp.

Then your daughter could connect to your VPN server (usually this is allowed trough campus firewalls IN->OUT). Once your daughter is connected to your VPN server, its just has if she were on your local LAN.

For example if your local lan is 192.168.1.X, well she will get a VPN IP from your private network dhcp server (eg:192.168.1.105). Then all you gotta do is SSH to this IP.

Of course all this has to be initiated from the inside out by your daughter. So for ON DEMAND support, this is a good option.

Good luck !

SiO
.



Relevant Pages

  • Re: httptunneling into a firewalled environment?
    ... Bob Tennent wrote: ... I can't expect that the admins will be willing or able ... If everything is blocked from the outside in by the admin, for sure you wont be able to access services such as SSH or HTTP. ... Then your daughter could connect to your VPN server. ...
    (comp.os.linux.networking)
  • Re: Whats the deal on the -X vs -Y thing?
    ... nor do they have admins who would be responsive ... industry looks to OpenSSH for their ssh solution, ... deep-ssh cannot handle this kind of syntax in its current form. ... > This enhanced client would only be needed on the originating host. ...
    (comp.security.ssh)
  • Re: Oracle 10g on HP blade server
    ... All *NIX admins, however, understand Windows ... ... Working Overloaded Kernel, and then finding three months later (having ... spent three months building the VPN server) that all such VPN servers ... We have a couple Linux boxes running here, but after seeing one of them ...
    (comp.databases.oracle.server)
  • Re: LKM Trojan: How could it have been installed?
    ... > Make sure you run the latest ssh version and I'd disable remote ... Part admins are a hack waiting to happen. ... experienced with security issues. ... I'm assuming a firewall in between too. ...
    (comp.os.linux.security)
  • "Best practices" or "Best implementations"?
    ... We have ~70 hosts, several with HACMP using r-tools and ... The admins connecting via telnet from their PCs to ... ssh from PC to server, personalized accounts, su ... whats the best way implementing ssh in a server farm? ...
    (comp.security.ssh)