Re: router port forwarding ssh to a zone



On May 29, 10:59 am, KJ <zemp...@xxxxxxxxx> wrote:
On May 29, 8:49 am, Shea Martin <s...@xxxxxxxx> wrote:

I created a zone, and changed the sshd to run on port 9022. On my old
linksys router, I forwarded port 9022 to the zone's IP (192.168.1.9).
Port 22 is forwarded to my global zone (192.168.1.8).

On my LAN, I can ssh to the zone from any machine inside the LAN. But
when I try to ssh to my house, on port 9022, I get a connection refused
error. Yet I can connect to my global zone fine.

Here is the output from ifconfig -a on my global zone:
lo0: flags=2001000849<UP,LOOPBACK,RUNNING,MULTICAST,IPv4,VIRTUAL> mtu
8232 index 1
inet 127.0.0.1 netmask ff000000
lo0:1: flags=2001000849<UP,LOOPBACK,RUNNING,MULTICAST,IPv4,VIRTUAL> mtu
8232 index 1
zone mediatomb
inet 127.0.0.1 netmask ff000000
dmfe0: flags=1000843<UP,BROADCAST,RUNNING,MULTICAST,IPv4> mtu 1500 index 2
inet 192.168.1.8 netmask ffffff00 broadcast 192.168.1.255
dmfe0:1: flags=1000843<UP,BROADCAST,RUNNING,MULTICAST,IPv4> mtu 1500 index 2
zone mediatomb
inet 192.168.1.9 netmask ffffff00 broadcast 192.168.1.255

Are there any obvious mistakes I am making? Is this a limitation of my
router (i.e., not recogining two IP's on the same mac?

~S

Did you restart the SSH server? If not, as root do "svcadm restart
sshd" on Solaris 10.

Even though my Netgear router doesn't "recognize" multiple IP's for
the same MAC address, it works fine, save for the reserved IP address
feature by hostname/IP - which is seriously confused by Solaris
zones. So I'd imagine you'd be okay with your Linksys but have a more
fundamental error.

By the way, what I find easier, if your Linksys supports it, is port-
forwarding within the router.

For example, you don't need to change sshd ports on zones, just let
every global and non-global zone run at the default ports. Then, if
your router supports is, just have your router forward to the proper
LAN IP and port. In your case, you should be able to set WAN request
on port 9022 to be directly to 192.168.1.9 on port 22 and all WAN port
22 traffic to simply traverse to 192.168.1.8.

This setup works especially well when using multiple zones. Then if
you want to switch web server zones, for example, you can simply swap
your zones IP address and have all the port mappings already
configured. Every "business class" Netgear router I've used support
these features, though I'm not sure about your Linksys.

HTH.

.



Relevant Pages

  • Re: Public/Private network split.
    ... > only open up port 80, that means that the only IP application would be ... I can't answer for your Linksys router but hopefully the following ... 192.168.1.xxx including the WAN port of the new wireless router. ...
    (comp.security.misc)
  • Re: VPN problems and Linksys BEFSR411????
    ... I think you need to enable port forwarding in the Advanced ... VPN solutions that use a hash for authentication of the IP header, ... test and keep an eye on the router log during the test to see what ports. ... I might also recommend enabling logging in the Linksys to send all the log ...
    (comp.security.firewalls)
  • Re: VPN problems and Linksys BEFSR411????
    ... I think you need to enable port forwarding in the Advanced ... VPN solutions that use a hash for authentication of the IP header, ... test and keep an eye on the router log during the test to see what ports. ... I might also recommend enabling logging in the Linksys to send all the log ...
    (comp.security.firewalls)
  • Re: OT: NTL and Linksys routers
    ... > OK, I've set up several Linksys cable routers with NTL, but this one has got> me foxed ... > Plugging a PC into the modem provides as good a net connnection as NTL will> ever supply, plus link lights on both ends ... Presumably into the local ethernet port on the modem. ... > Plugging the router into the the modem via the WAN port, no link light at> either end, no connectivity, no IP assigned to router, no traffic at all ...
    (uk.rec.motorcycles)
  • Two routers new attempts
    ... I am still trying to access host PC. ... Linksys BEFVP41 VPN router Main Office Building LAN IP XX.X.X.1 and WAN ip ... Port is open in XP security in both ports 3389 and 1723 for Local Area ... > You would need to change the D-Link address to match your Linksys address range... ...
    (microsoft.public.windowsxp.work_remotely)