RE: Port Forwarding - Firewall Traversal



From: Henry Kupets [mailto:Henry.Kupets@xxxxxxxxxxxxxxx]

I have a host (Oracle app.server) in DMZ that I need to
access through HTTP on port 1810 from the Windows PC that
resides inside the LAN. The firewall does not allow traffic
through port 1810 but allows traffic through port 9000. (When
I point the browser to http://appserver:1810 it returns "The
page cannot be displayed").
I was trying to set up port forwarding on the app.server using:

1) Changed sshd_config on the app.server (AllowTcpForwarding yes)
2) Ran on the app.server: ssh -g -L 9000:appserver:1810 appserver

It's not working. I can see in the firewall log that it
allows the first packet to go to the app.server on port 9000
and it drops the second packet that goes for some reason to
the app.server on port 1810.

Am I missing anything?


Apologies if I sent two of these -- having connectivity issues. It's also
late and my first response bordered on boneheaded.

Are you connecting to http://localhost:9000?

I also think you're overcomplicating things a bit. If it were me, I'd use:

ssh -L1810:appserver:1810

Then browse to:

http://localhost:1810



Relevant Pages

  • Re: Printer to Computer via Ethernet
    ... Printer and cable it to the parallel port. ... Connectivity, Std. ... parallel, 2 EIO slots, HP JetDirect card for Fast Ethernet 10/100Base-TX in 1 ... we should choose the Networked Printer option. ...
    (microsoft.public.windowsxp.hardware)
  • Re: iptables udp and output
    ... >> I think I would ACCEPT policy for OUTPUT ... > filtering them out using state machine and port selection is the best way. ... >> the line for connectivity, no icmp then no dhcp or dns. ...
    (comp.os.linux.security)
  • SUMMARY: Cannot solicit prompt when connecting to COM1
    ... This enabled our DS10 to use the COM port. ... I must save face by saying this server ... > and before bringing down to SRM I wanted to check connectivity over this ... Set the console variable to serial, init the console and you should be ...
    (Tru64-UNIX-Managers)
  • Re: ADSL Modem Router
    ... I have a Linksys WAG54GS. ... This has 802.11g connectivity, an ADSL modem ... port for connecting to your phone line and 4 Ethernet ports. ...
    (alt.internet.wireless)
  • Stock rc.firewall
    ... well -- too well in fact, that it also kills all connectivity to the ... Can't ping it nor can it ping the bsd ... the port 137 blocking. ... services ports, i.e., ntp, dns, ssh, etc. ...
    (FreeBSD-Security)