ssh port forwarding and long delays

From: fire on water (invalid_at_spam.xxx)
Date: 02/20/04


Date: Fri, 20 Feb 2004 13:45:20 +0100

Hi all.

I retrieve and send email by tunneling through ssh like so:
ssh -l myusername -L5110:my.remore.server:110 -L5025:my.remote.server:25
my.remote.server

This as you can guess gives me a shell on my.remote.server and opens
local port 5110 which it tunnels to port 110 on the remote machine and
local 5025 which it tunnels to 25 on the remote machine.

If I turn on the default firewall config in SuSE 9.0 the tunneled
connections take very long to get establised. (3-4 minutes before I see
the POP3 server prompt)

To clarify... Whether the firewall is turned on or off, my initial SSH
connection to the remote machine get's established just fine and I get
the remote shell instantly. But when an application on my local machine
requests a connection to 5110 or 5025 if the firewall is turned on it
takes very long before it is connected to the equivalent port on the
remote machine.

Does anyone know where the problem might be?

any help much appreciated...



Relevant Pages

  • SSH trickery using -R
    ... I found the -L and -R switches. ... So what I'd like to be able to establish is a connection to a machine ... port on the remote machine, which is then redirected to the local ... on a port of my choosing. ...
    (Fedora)
  • Re: GUI firewall
    ... > session you are logged into on the remote machine (the machine to ... > you a different desktop than a connection to:0. ... You should try firestarter its got a very easy to use gui. ... Click Open Ports right click and select New Rule and add the port you ...
    (Fedora)
  • Re: Sharing a com port across a network
    ... on the machine with the COM port with which a remote machine could ... >that connects to a cutting machine via the COM port. ... The machine the cutter ... >but rather the software actually looks for the connection at the com port ...
    (microsoft.public.windowsxp.hardware)
  • Re: GUI firewall
    ... you are logged into on the remote machine. ... port 5901 is a virtual X11 desktop started by the vncserver service in ... a different desktop than a connection to:0. ...
    (Fedora)
  • Re: [Fwd: Re: 3 connections as one]
    ... but you can't really load balance multiple links ... If one of the tunnels goes ... I've got a DSL connection and a Cable internet connection at home now, ...
    (freebsd-hackers)