Re: An ssh Question



Jonathan Chen wrote:
On Sat, Jul 07, 2007 at 02:52:21AM -0500, Tim Daneliuk wrote:
I have a machine that is my firewall/gateway to a private network NATing
non-routable addresses. I can ssh at-will from hosts on the private
network to machines out on the net, but when I try to ssh from the
firewall machine to a particular address, it just hangs and eventually
times out. Verbose output is:

OpenSSH_4.5p1 FreeBSD-20061110, OpenSSL 0.9.7e-p1 25 Oct 2004
debug1: Reading configuration data /etc/ssh/ssh_config
debug2: ssh_connect: needpriv 0
debug1: Connecting to xxxxxxxxxxxxxx.com [x.x.x.x] port 22.


What is really baffling is that if I try the exact same thing from, say,
a cygwin session on a host on the private network - this works fine.
So ... it's not a firewall problem as near as I can tell.

It sure sounds like a firewall problem to me. Why do you think
otherwise?

Because machines *behind* the firewall can get out to the machine
in question, but the firewall machine itself cannot...



--
----------------------------------------------------------------------------
Tim Daneliuk tundra@xxxxxxxxxxxxxx
PGP Key: http://www.tundraware.com/PGP/

_______________________________________________
freebsd-questions@xxxxxxxxxxx mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-questions
To unsubscribe, send any mail to "freebsd-questions-unsubscribe@xxxxxxxxxxx"



Relevant Pages

  • Very slow SMB performance on one interface of a multi-homed server
    ... one interface and a private gigabit network on the other. ... Of the seven hosts, four are Windows 2000 server and three are XP. ... Connections using the office LAN and, ...
    (microsoft.public.windows.server.networking)
  • RE: Blackhole
    ... > ssh access from trusted networks. ... Especially if you dont have to offer any network services from the network. ... My trusted network is then narrowed to 15000 possible hosts, ... > those hosts in those trusted networks could get comporised. ...
    (RedHat)
  • RE: SSH with no crypt
    ... my organization want to sniff every network ... That's why i'would like to continue using SSH ... ensure nobody inserts malicious hosts on the network that masquerade as ... possibility of initializing a SSH2 connection without encryption as ...
    (SSH)
  • Re: network setup with multiple ifaces
    ... > What you might do is disable strict multihoming so that the hosts can ... > receive packets for the main network on the private interface. ...
    (comp.unix.solaris)
  • Re: inbound ssh ceased on 4 servers at same time
    ... > at the console, attempting ssh sessions from the db server ... > in the network so there was never an occasion to ssh FROM ... Are you testing to/from multiple hosts here? ...
    (freebsd-questions)