Getting access to entire remote network with SSH



Consider the following scenario:

(192.168.0.0/24)--[firewall, NAT-router]----(Internet)

(192.168.5.0/24)--[firewall, NAT-router with SSH access]--(Internet)

All computers in 192.168.0.0/24 and in 192.168.5.0/24 run under LINUX.

Using SSH port forwarding, it's simple to map e.g. 192.168.5.1:5900
to 192.168.0.20:1500, so that 192.168.5.1:5900 can be accessed (via
192.168.0.20:1500) from any computer in 192.168.0.0/24. But this is not
very comfortable.

Now, what tools are there which allow us to map selected ports from
selected computers in 192.168.5.0/24 to "virtual hosts" visible to the
computers in 192.168.0.0/24?

A made up example telling you roughly what we're after:

192.168.0.20# telnet 192.168.5.1 5900
Trying 192.168.5.1...
telnet: connect to address 192.168.5.1: Network is unreachable
192.168.0.20# connect_to 192.168.5.0/24 via remote_net.dyndns.org
192.168.0.20# telnet 192.168.5.1 5900
Trying 192.168.5.1...
Connected to foo.
Escape character is '^]'.
RFB 003.003

The program "connect_to" should set up all the port mapping and all the
routing. It would be OK, though, if it is necessary to configure it on a
per "remote network" basis, e.g. to tell it what ports at which hosts on
the remote network are needed

--
Dipl.-Phys. Felix E. Klee
Email: fk@xxxxxxxxxxxx (work), felix.klee@xxxxxxx (home)
Tel: +49 721 8307937, Fax: +49 721 8307936
Linuxburg, Goethestr. 15a, 76135 Karlsruhe, Germany
.



Relevant Pages

  • Re: Kazaa Block !
    ... >> security breach, but worse, it is a blatant abuse of work computers. ... >> If this is a home LAN, and these are your children, ground them first, ... >> block KaZaA from their computers, ... > goes over port 80. ...
    (comp.security.firewalls)
  • Re: Cant View Workgroups on One PC
    ... I had previously blocked Port 135 to deal with a ShieldlsUp ... I had run browstat status and both computers with nothing amiss. ... Had earlier found computer browser "start" in Services for each computer. ... computers from the Laptop. ...
    (microsoft.public.windowsxp.network_web)
  • Re: Kazaa Block !
    ... >>> security breach, but worse, it is a blatant abuse of work computers. ... >> goes over port 80. ... >> to a kazaa server and then to the other client to ... >> bad guy by uninstalling software and talking to boss. ...
    (comp.security.firewalls)
  • RE: VBScript: Remote Desktop Disconnected
    ... ISA is allowing OUTBOUND port 4125 through the "SBS RWW Inbound Access ... I have checked the box "Remote Web Workplace". ... 3)A network error might have occurred while establishing the connection. ... client works from any computers in the LAN. ...
    (microsoft.public.windows.server.sbs)
  • HALP! My XPs ports are unusually opened!!
    ... I have Windows XP Pro. ... I used an IP scanner to check all the computers ... on the network and it shows 3 computers on the network (including ... First I connected at port 19. ...
    (microsoft.public.windowsxp.network_web)