Re: Reverse SSH tunelling

From: Glynn Clements (glynn.clements_at_virgin.net)
Date: 08/28/04

  • Next message: cwells_at_geoplan.ufl.edu: "Re: Reverse SSH tunelling"
    Date: Sat, 28 Aug 2004 08:26:53 +0100
    To: Raistlin Majere <raistlin@majere.net>
    
    

    Raistlin Majere wrote:

    > I need some advice .. I have a situation where about fifty servers will
    > be located in fifty sites that cannot allow services to be hosted. These
    > servers will be in private network space behind firewalls. I can use
    > them to 'scp' files out to a common home base server, but sometimes I
    > need to access a command line console on these servers. I am thinking of
    > having a hourly cron job ssh out to my home base server and leaving that
    > tunnel open so that I can access that console, but am looking for the
    > specific way of doing this. Security os pf the utmost concern, so I need
    > some sort of encrypted tunnel, hence the thought of ssh, but I don't
    > know how to do this 'reverse' tunnel... I was also thinking of a 'free
    > swan' vpn tunnel ..

    If you have root on the remote systems, I would suggest using a real
    VPN rather than the sort of ad-hoc mechanisms which others have
    suggested. The choice of exactly which VPN is likely to be determined
    by what you can get through the firewall; e.g. if it only allows TCP,
    then you will be limited to a PPP/SLIP-over-SSH/SSL type VPN.

    -- 
    Glynn Clements <glynn.clements@virgin.net>
    

  • Next message: cwells_at_geoplan.ufl.edu: "Re: Reverse SSH tunelling"

    Relevant Pages

    • Re: Site to Site VPN 2 SBS servers
      ... site to site VPN. ... Microsoft CSS Online Newsgroup Support ... This newsgroup only focuses on SBS technical issues. ... | Subject: Re: Site to Site VPN 2 SBS servers ...
      (microsoft.public.windows.server.sbs)
    • Re: IP over IP to make static IP?
      ... My ISP's terms of service even allow me to run private servers. ... > Now what if some third party comes along, and has maybe a class C of IP ... The VPN traffic doesnt have to be limitted to internal traffic. ... A normal tunnel can be used for interent traffic. ...
      (comp.os.linux.networking)
    • Re: Change of IP for Servers
      ... Static device like printers will need to have their gateway's ... All servers ... We have an ISP who is providing internet and VPN access. ...
      (microsoft.public.win2000.networking)
    • site to site vpn using rras - routing problems.
      ... i have 2 sites that i would like to connect, both have firewalls etc... ... laptop from home so i know that the vpn connections work. ... both have demand dial interfaces setup with the correct static routes. ... i have tried adding statics routes on the servers that i am trying to ...
      (microsoft.public.win2000.ras_routing)
    • RE: Connecting to Windows servers through adsl
      ... join your computer into domain after the VPN connection is established. ... | which connect to internet through adsl line from home. ... | servers with their internal ip's and machine names. ... | to see any server's shares, he gets a logon window ...
      (microsoft.public.win2000.security)