SSH2 tunneling impossible on Pix 525?



Hi there,

I've been trying to setup a simple TCP SSH2 tunnel through a PIX 525
but keep getting an error back as soon as I try to use the tunnel
(logging into the Pix works fine). Basically I want port 4242 on my
localhost to be fwded to port 1666 on a machine behind the Pix.

Using PuTTY I get "Forwarded connection refused by server: Resource
shortage []", when using CygWin I get "channel 2: open failed:
resource shortage:". I get the same error when using ssh under Ubuntu.

I found a couple of web pages that discussed this problem and
apparently found workarounds for their Perl clients:

http://www.cpanforum.com/threads/851
http://www.perlmonks.org/?node_id=361885

both seem to say the Pix has a bug where it can't allocate more than a
single channel per SSH2 connection, but then it would seem to be SSH
tunneling is basically impossible on a Pix.

I tried poking around the PuTTY source code (which is huge and very
old-style C), without luck.

btw I'm using PIX Version 7.2(2).

Any help is greatly appreciated!!

-- p
.



Relevant Pages

  • Re: [Edit] VPN pix 506 to 501 ...
    ... After, if that not resolve the problem, i will change the crypto map by ... > which tells the PIX to ignore the interface ACLs for tunnel traffic. ... unless you had turned that off with 'logging message'... ...
    (comp.dcom.sys.cisco)
  • Re: IPsec performance just 55% of WAN bandwidth
    ... It looks like pings with a payload larger than 1418 bytes are ... I do not know why 1000 exactly, and PIX offers no way to ... SHA-1 is used for the authentication, ... Are the pings going inside the tunnel or outside the tunnel? ...
    (comp.security.misc)
  • Re: IPsec performance just 55% of WAN bandwidth
    ... It looks like pings with a payload larger than 1418 bytes are ... I do not know why 1000 exactly, and PIX offers no way to ... SHA-1 is used for the authentication, ... Are the pings going inside the tunnel or outside the tunnel? ...
    (comp.security.firewalls)
  • Re: Cisco PIX VPN access-lists
    ... IPSec tunnel between a Cisco PIX and a Juniper SSG 20. ... Can you specify host and port access lists using that crypto map match ...
    (comp.dcom.sys.cisco)
  • Re: PIX 501 <-> Concentrator remote client question
    ... Configure an IPSEC tunnel from my PIX to the office where I work. ... set a default route to the hub-facing side of the 'dumb router'. ... route to 'inside' of PIX on port B ...
    (comp.dcom.sys.cisco)