/* HINT: Search archives @ http://www.indyramp.com/masq/ before posting! */ Hi, Does anyone know how to configure IP masquerading such that internal hosts using privileged local ports (<= 1024) for communication with external servers, get those ports mapped to other privilged ports on the masquerading machine? I'm running into this problem while trying to use rhosts/RSA authentication with ssh from a host which is masqueraded to the internet. Because the masquerading server (the machine with an actual internet IP address) maps internal ports to arbitrary unprivileged ports (> 1024), the authentication fails with: sshd: RhostsRsa authentication not available for connections from unprivileged port Ideally, I'd just have my linux box which is doing the masquerading notice when one of the internal local ports was <= 1024, and pick another privileged port to map it to. A picture might help clarify what I'd like to do: ______________ | | | private host |--> ssh's to server.somewhere.com ---- | | | -------------- | | allocates local privileged port 650 for rsh/RSA authentication | ______________ | | | | ------------| linux server |<----------------- | | with real IP | | | | | -------------- | linux server notices the privilegded port, 650 from the internal machine and chooses another privileged port, 801, as the masquerading/mapping port | | | ______________________ | | | ---------->| server.somewhere.com |----------- | | | ---------------------- | | server processes the ssh request, notices the privileged port, and presumably checks the RSA host key against ssh_known_hosts and allows the connection. It communicates back to the linux server on port 801, which gets mapped to the internal server's port 650, and all is well. I read the FAQ, trawled the net, and couldn't find any reference on how to accomplish the above (though I found plenty of information on how to make IP masquerading work with wacky protocols such as those used by IRC and RealAudio). If anyone could offer any help on how to make this configuration work, I'd appreciate it. Or, if you know that the above configuration is definitely -not- supported by the current implementation of IP masquerading on linux (I'm using ipchains on linux kernel 2.0.36), I'd appreciate that information as well. I wouldn't necessarily be opposed to writing an ip_masq mod to specifically support this, but I'd definitely prefer to find a quicker, simpler solution. Thanks much! --- Luke Adamson Omni Development, Inc. [EMAIL PROTECTED] _______________________________________________ Masq maillist - [EMAIL PROTECTED] Admin requests can be handled at http://www.indyramp.com/masq-list/ -- THIS INCLUDES UNSUBSCRIBING! or email to [EMAIL PROTECTED] PLEASE read the HOWTO and search the archives before posting. You can start your search at http://www.indyramp.com/masq/ Please keep general linux/unix/pc/internet questions off the list.
