Re: solaris rshd question

From: David Mathog (mathog_at_caltech.edu)
Date: 03/22/05

  • Next message: Barry Margolin: "Re: solaris rshd question"
    Date: Mon, 21 Mar 2005 16:05:00 -0800
    
    

    Neil W Rickert wrote:
    > David Mathog <mathog@caltech.edu> writes:
    >
    >>That last packet is the problem. Neither 856 on the Sun side nor 1021
    >>on the linux side have been used previously _from the linux side_ so
    >>the linux firewall blocks that packet from the sun and that's all she
    >>wrote.
    >
    >
    > rsh opens a secondary connection for diagnostic output (stderr). You
    > are seeing the first step in setting up that secondary connection.
    >

    Hmm. Yeah, I see it now in "man in.rshd" on the Solaris machine.

    The trick as far as the firewall is concerned is that
    rsh will have picked the second port number out of thin air
    and sent it to the Solaris machine - without first telling
    the firewall to accept a return connection on it. The port
    numbers on the rsh side aren't fixed either. Tricky.

    Has anybody ever solved this before? It looks like it might
    be necessary to modify rsh so that it can tell the firewall
    to open the second port.

    Thanks,

    David Mathog
    mathog@caltech.edu


  • Next message: Barry Margolin: "Re: solaris rshd question"

    Relevant Pages

    • Re: solaris rshd question
      ... >rshd does something odd which causes the firewall on the linux ... >firewall allows rsh to work. ... rsh opens a secondary connection for diagnostic output. ... are seeing the first step in setting up that secondary connection. ...
      (comp.sys.sun.admin)
    • Re: krb5 port: -current behaves differently than 4.X w.r.t rsh
      ... In my case there is no firewall ... > I run a couple of Kerberos realms. ... > This rsh session is encrypting input/output data transmissions. ... protocol error or closed connection in circuit setup ...
      (freebsd-current)
    • Re: krb5 port: -current behaves differently than 4.X w.r.t rsh
      ... In my case there is no firewall ... > I run a couple of Kerberos realms. ... > This rsh session is encrypting input/output data transmissions. ... protocol error or closed connection in circuit setup ...
      (freebsd-current)
    • Symantec Raptor 1.5 VRaptor RSH passing adds extra CR Characters?
      ... I have a problem with a raptor firewall when an rsh connection runs ... This is causing problems with the application that runs over the rsh ... The ruleset we have set for testing purposes is an any to any to any ...
      (comp.security.firewalls)
    • rsh problems
      ... We recently upgraded one of our Alphas to Tru64 version 5.1B. ... can 'rsh' to the box but, if I try to 'rsh' with a command, ... This error only happens when using rsh across our firewall ... the 5.1B upgrade so that pretty much rules the firewall out. ...
      (Tru64-UNIX-Managers)