Re: allow login from specific address



Todd H. a écrit :
Sylvain Ferriol <sferriol@xxxxxxx> writes:


hello

i want to config a ssh gateway between internet and my intranet:
the specifications are:
- a user from internet can not login the ssh_gateway
- some users (admins) from intranet can login the ssh_gateway

how can i do that ?
can i allow sshd to accept login only from an ip address range ?

is it more secure to only accept port forwarding on ssh_gateway ?


TCP Wrappers rather than an sshd config is the place to do this.

THe 30 second tutorial, assuming it's installed:

edit /etc/hosts.deny
Make this the one and only line: sshd: ALL

the problem is that i want to allow port forwarding from internet to intranet like this:
ssh -N -L 4444:foo_server:4444 sshd_gateway

Or, if you want to get more restrictive and don't host external
services on the box make that:
ALL:ALL

which denies everything by default except things specifically
allowed.

Next, edit /etc/hosts.allow

Add lines sshd: ip.address.to.allow.here
sshd: ip.address2.to.allow.here
sshd: ip.address3.to.allow.here
sshd: ip.address4.to.allow.here
sshd: intranet.mycompany.com

Man hosts.allow for more details and different ways to specify ip
ranges and subnets. If your intranet hosts reverse resolve to a
consistent name e.g. host123.intranet.mycompany.com, then sshd:
intranet.mycompany.com would be your hosts.allow entry.

Best Regards, --
Todd H.
http://www.toddh.net/
.



Relevant Pages

  • Re: Intranet/Internet Site Permissions
    ... require ntfs login from internet and no login from intranet. ...
    (microsoft.public.inetserver.iis)
  • Re: allow login from specific address
    ... i want to config a ssh gateway between internet and my intranet: ... some users from intranet can login the ssh_gateway ...
    (comp.security.ssh)
  • Re: allow login from specific address
    ... i want to config a ssh gateway between internet and my intranet: ... some users from intranet can login the ssh_gateway ... the problem is that i want to allow port forwarding from internet to ...
    (comp.security.ssh)
  • Re: allow login from specific address
    ... i want to config a ssh gateway between internet and my intranet: ... the specifications are: ... some users from intranet can login the ssh_gateway ... TCP Wrappers rather than an sshd config is the place to do this. ...
    (comp.security.ssh)
  • Re: Intranet/Internet Site Permissions
    ... Internet Explorer might consider files.domain.com to be in the Internet ... Intranet Zone. ... > require ntfs login from internet and no login from intranet. ... >> Basic authentication requires log on locally rights. ...
    (microsoft.public.inetserver.iis)