Re: Disable port forward on specific users

From: smn (smn_at_smn.smn)
Date: 06/06/03


Date: Fri, 06 Jun 2003 17:44:42 GMT

Franky wrote:
> Hi,
>
> I'm wondering if it is possible to prevent a specific user from forwarding a
> specific port on my server (or any port).
> Thanks for your help
>
> FRANK
>
>

You might want to look into the "permitopen" feature which is entered in
the user's authorized_keys file. I have on my server allowed people to
log in and forward a connection to a particular machine and a specific
port. It looks like this for each key:

permitopen="192.168.10.15:5555" ssh-dss AAAAB3Nza...

You might also be interested in the no-port-forwarding option in the sshd.
no-port-forwarding
         Forbids TCP/IP forwarding when this key is used for authentica-

        tion. Any port forward requests by the client will return an
         error. This might be used, e.g., in connection with the command
         option.

- smn



Relevant Pages

  • RE: Some technical errors
    ... If the SMTP server is not running on port 25 TCP it is not a public ... Manager - Computer Assurance Services BDO Chartered Accountants & ...
    (Security-Basics)
  • Re: SRV RRs support in Internet Explorer?
    ... The port number could be implicit (i.e. ... At any point in time, a server could fail ... can't effectively LB or backup because NSs cache the records for the TTL ... I still don't see how SRV records would help backup or LB. ...
    (microsoft.public.win2000.dns)
  • Re: Still cant connect to RWW or OWA remotely
    ... I get 'cannot find server or dns error' on both ... TCP [port number]> to open the ports. ... As for error messages when I fail to access RWW with the laptop, ... network, no connection seems possible. ...
    (microsoft.public.windows.server.sbs)
  • Re: Outlook 2003 client
    ... Items' folder from the Send/Receive group for my account, ... Send/Receive to synchronize Outlook local data with the Exchange Server, ... Port 21 enable external and internal file transfer ... Port 80 enables all nonsecure browser access, ...
    (microsoft.public.windows.server.sbs)
  • RE: SMTPS - Exchange
    ... Microsoft CSS Online Newsgroup Support ... This newsgroup only focuses on SBS technical issues. ... If the Exchange server is listening on other port rather ...
    (microsoft.public.windows.server.sbs)