SSH connection thru corporate firewall to home sshd on Port 80

From: Bruce Gilmore (bruce.gilmore@dsionline.com)
Date: 02/15/02


From: "Bruce Gilmore" <bruce.gilmore@dsionline.com>
Date: Fri, 15 Feb 2002 16:31:12 -0600

Hello all. I'm perplexed by the results of an effort to establish a ssh
session and perhaps someone can explain this to me.

I have a FreeBSD server running sshd listening on port 80 at home.
I can successfully establish a ssh session from a Winnt/putty:80 box the
internet to this SSHD:80 server (no firewall involved).
When I take the same Winnt machine behind a corporate firewall which passes
outgoing port 80 connections, I cannot establish a ssh session to the same
sshd:80 home server.

The firewall is a Checkpoint and I've also tested it against an
IPChains/Linux flavor without success.

While testing behind the Checkpoint, I could successfully port scan the
FreeBSD server on port 80 and get a response using nmapNT.
Additionally, I captured the client traffic of the ssh/putty attempt where I
could see the 3-way handshake (syn, syn/ack, ack) with my home server but
nothing more. What gives?

Is the firewall dropping my packets because they are not legit http packets
(i.e. Layer 7 filtering)?

Any other alternatives out there?

Thanks in advance
Bruce Gilmore



Relevant Pages

  • Re: need help for setting SSH Server for Windows XP
    ... In my windows firewall proper ports are opened. ... Changing from port 22 to ports 80, 443 also doesn't give any results. ... static LAN IP of the server PC. ... It is *NOT* a valid test to call the SSH server PC from another ...
    (microsoft.public.windowsxp.work_remotely)
  • Re: ssh security question
    ... Someone is attempting to use a dictionary or brute-force attack against your SSH server. ... Recently - I was away from the office - and enabled port 22 on the firewall - so I could access the centos server remotely. ...
    (SSH)
  • Re: bind() udp behavior 2.6.8.1
    ... Allowing a high numbered udp port to remain ... The firewall should allow traffic from the same ip:port to the other ... ip:port and from no other server on the net. ... You new session is totally ...
    (Linux-Kernel)
  • Re: Mac OS X Server Security Questions
    ... go to System Prefernces/Sharing to shut off ssh. ... as it is enabled by default on OS X server. ... Mind you, now with your dedicated Firewall in place, it's a moot point ... PermitRootLogin no ...
    (Security-Basics)
  • Re: An application gateway firewall based on Linux - ITShield firewall
    ... "Proxy" in application gateway firewall is different from proxy in HTTP ... proxy server or FTP proxy server. ... the session (I mean "session", ...
    (comp.security.firewalls)