ssh problem



I have an ssh problem that has me stumped.

Configuration:

p660-6H1 with a fresh install of AIX 5.3 TL 04
openssl-0.9.7g-1
openssh 4.1.0.5201 from AIX Expansion Pack
non-routed IP number (192.168.250.x) on server that is NAT'd
(198.252.x.x) at the firewall

I could sucessfully ssh to this box before the rebuild when it was at
AIX 5.2 and older versions of openssl and openssh from allowed routed
and non-routed IPs.

I can sucessfully ssh to this box from other systems behind the firewall
(using non-routed to non-routed) AND systems that have a publicly routed
IP number outside the firewall that have firewall permissions to ssh.

I can not ssh to the box from a non-routed number (172.16.14.x) that is
outside the firewall and has firewall permissions.

We have turned logging to a higher level on the firewall and we do not
see the ssh from the private number getting denied by any of the
firewall rules.

I am open to suggestions at this point.

S
--
************************************************************************
Shawn Geil, Senior Systems Administrator shawn.geil@xxxxxxxxxxxx
Information Systems and Services phone number 785.670.1010.2305
Washburn University Topeka, Kansas 66621
************************************************************************



Relevant Pages

  • Re: [fw-wiz] Is NAT in OpenBSD PF UPnP enabled or Non UPnP?
    ... >> I start by not giving logins and SSH access to users I don't trust. ... a network topology which goes around the ... >> firewall and thus is a serious hole to network security. ... >> have access via UPnP to, well, anything that device might happen to ...
    (Firewall-Wizards)
  • Re: ssh attempts
    ... the excellent iptables firewall you probably already have on your system. ... consider changing the port SSH listens on. ... Login to account webmaster not allowed or account non-existent. ... Computer Emergency Response Teams, and Digital Investigations. ...
    (Security-Basics)
  • Re: installing openssh on AIX 5.2
    ... I was not able to solve then "PRNG not seeded" problem with AIX 5.2, so I updated everything to AIX 5.3. ... Now ssh is working properly. ... So I tried to update openssh, which I found required openssl, which I do not have installed. ... Rather than trying to catalogue all the permutations and problems I encountered, it might help if someone could tell me which packages to install, and in what order. ...
    (comp.unix.aix)
  • Re: mpich and iptables firewall?
    ... to me it seems a very weird setup to have a firewall running ... on the cluster nodes. ... Using SGE you could disable rsh and ssh completely ... Chain FORWARD ...
    (comp.parallel.mpi)
  • Re: Problems with ipfw and ssh
    ... I get this error when updating my firewall rules via ssh. ... ${addcmd} 50 allow all from any to any via lo0 ... debug1: PAM: cleanup ...
    (freebsd-questions)