Re: "public" OpenSSH Tunnel

From: Jukka Salmi (jukka-usenet_at_2003.salmi.ch)
Date: 06/13/03


Date: 13 Jun 2003 09:11:00 GMT

Kyler Laird wrote:
> Be careful...be very careful.
>
> Once you turn that on, you've opened the floodgates. Unless
> you're using something like tcpwrappers, all of your tunnels
> will be available on all of your interfaces. (Someone correct
> me if I'm wrong.) I much prefer to enable these things
> individually.

Thanks for the hint. I'm using 'ssh -o "GatewayPorts yes" ...' only for
one tunnel, so I can leave this option to 'no' in ssh_config. Furthermore
the client subnet and the client itself are firewalled, so only trusted
hosts are allowed to use my tunnel. Hopefully... ;-)

Greetings,

Jukka

-- 
bashian roulette:
$ ((RANDOM%6)) || rm -rf ~