/* HINT: Search archives @ http://www.indyramp.com/masq/ before posting! */


Hi,

Does anyone know how to configure IP masquerading such that internal hosts using
privileged local ports (<= 1024) for communication with external servers, get those
ports mapped to other privilged ports on the masquerading machine?

I'm running into this problem while trying to use rhosts/RSA authentication with ssh
from a host which is masqueraded to the internet.  Because the masquerading server
(the machine with an actual internet IP address) maps internal ports to arbitrary
unprivileged ports (> 1024), the authentication fails with:

sshd: RhostsRsa authentication not available for connections from unprivileged port

Ideally, I'd just have my linux box which is doing the masquerading notice when one
of the internal local ports was <= 1024, and pick another privileged port to map it
to.

A picture might help clarify what I'd like to do:

    ______________
   |              |
   | private host |--> ssh's to server.somewhere.com ----
   |              |                                      |
    --------------                                       |
                                                         |
                                        allocates local privileged port
                                        650 for rsh/RSA authentication
                                                         |
                        ______________                   |
                       |              |                  |
           ------------| linux server |<-----------------
          |            | with real IP |
          |            |              |
          |             --------------
          |
   linux server notices the privilegded
   port, 650 from the internal machine
   and chooses another privileged port,
   801, as the masquerading/mapping port
          |
          |
          |            ______________________
          |           |                      |
           ---------->| server.somewhere.com |-----------
                      |                      |           |
                       ----------------------            |
                                                         |
                               server processes the ssh request, notices
                               the privileged port, and presumably checks
                               the RSA host key against ssh_known_hosts
                               and allows the connection.  It communicates
                               back to the linux server on port 801, which
                               gets mapped to the internal server's port
                               650, and all is well.


I read the FAQ, trawled the net, and couldn't find any reference on how to accomplish
the above (though I found plenty of information on how to make IP masquerading work
with wacky protocols such as those used by IRC and RealAudio).  If anyone could offer
any help on how to make this configuration work, I'd appreciate it.  Or, if you know
that the above configuration is definitely -not- supported by the current
implementation of IP masquerading on linux (I'm using ipchains on linux kernel
2.0.36), I'd appreciate that information as well.  I wouldn't necessarily be opposed
to writing an ip_masq mod to specifically support this, but I'd definitely prefer to
find a quicker, simpler solution.

Thanks much!
---
        Luke Adamson
        Omni Development, Inc.
        [EMAIL PROTECTED]

_______________________________________________
Masq maillist  -  [EMAIL PROTECTED]
Admin requests can be handled at http://www.indyramp.com/masq-list/ -- THIS INCLUDES 
UNSUBSCRIBING!
or email to [EMAIL PROTECTED]

PLEASE read the HOWTO and search the archives before posting.
You can start your search at http://www.indyramp.com/masq/
Please keep general linux/unix/pc/internet questions off the list.

Reply via email to