Re: SSH tunneling/port forwarding and stateful packet inspection

From: Richard E. Silverman (res_at_qoxp.net)
Date: 02/25/04


Date: 24 Feb 2004 22:02:59 -0800


> ... However, in doing a packet trace, I saw that the header of the
> packet really is ssl traffic, but the actual port 3389 (term server)
> traffic a) encrypted and b) encapsulated. So as far as teh SPI
> functionality of the firewall is concerned, it is SSL traffic.

Your terminology is confused and you want "SSH" here, not "SSL" (these are
two entirely different protocols) -- but I suppose you've got the idea.
All the firewall can see is a TCP connection whose contents are entirely
opaque because they are encrypted. The fact that the connection is being
to forward traffic between two other TCP connections elsewhere is
invisible to the firewall.

-- 
  Richard Silverman
  res@qoxp.net


Relevant Pages

  • Re: http custom Gzip header being stripped on outbound request.
    ... customizing the firewall to allow these headers other totally switching off ... >> I am adding a custom header to the request ... The web server receives this request ...
    (microsoft.public.win32.programmer.networks)
  • Re: converting Java code to Perl (using LWP?)
    ... here's what my limited documentation says: ... The header structure is: Authorization: BASIC xxxxxxxxxxxxxxxx? ... is a firewall user name and password separated by ... so either ought to work. ...
    (comp.lang.perl.misc)
  • Re: Logging source IP address of a half-open scan
    ... > connection only after the TCP three-way handshake is completed. ... > packet, thereby closing the connection. ... > by a firewall when the first SYN packet is ... > would need to strip off the MAC frame header, the IP header, and then look ...
    (comp.security.firewalls)
  • FIN Timeout
    ... I have a problem with Cisco Firewall Pix 515E. ... I setup a FTP service on DMZ zone on Windows 2003 Server. ... Client can connect to the Ftp service from the Internet, ... Built inbound TCP connection 915578 for outside:xx.xx.xx.xx/50601 ...
    (comp.dcom.sys.cisco)
  • Re: OWA 2007 400 bad request
    ... I had an Exchange 2003 behind a firewall (not ISA). ... Request Header Too Long ...
    (microsoft.public.exchange.admin)