/* HINT: Search archives @ http://www.indyramp.com/masq/ before posting! */


        Hello,

        In these days you can't trust the privileged ports.
Just try ssh -P ! If you can't trust your users just use
publickey authentication. You always can solve this
problem without the need to masquerade with privileged
ports. Try ssh-keygen or ssh-keygen -P !

On Mon, 8 May 2000, Luke Adamson wrote:

> /* HINT: Search archives @ http://www.indyramp.com/masq/ before posting! */
> 
> 
> Hi,
> 
> Does anyone know how to configure IP masquerading such that internal hosts using
> privileged local ports (<= 1024) for communication with external servers, get those
> ports mapped to other privilged ports on the masquerading machine?
> 
> I'm running into this problem while trying to use rhosts/RSA authentication with ssh
> from a host which is masqueraded to the internet.  Because the masquerading server
> (the machine with an actual internet IP address) maps internal ports to arbitrary
> unprivileged ports (> 1024), the authentication fails with:
> 
> sshd: RhostsRsa authentication not available for connections from unprivileged port
> 
> Ideally, I'd just have my linux box which is doing the masquerading notice when one
> of the internal local ports was <= 1024, and pick another privileged port to map it
> to.
> 
> A picture might help clarify what I'd like to do:
> 
>     ______________
>    |              |
>    | private host |--> ssh's to server.somewhere.com ----
>    |              |                                      |
>     --------------                                       |
>                                                          |
>                                         allocates local privileged port
>                                         650 for rsh/RSA authentication
>                                                          |
>                         ______________                   |
>                        |              |                  |
>            ------------| linux server |<-----------------
>           |            | with real IP |
>           |            |              |
>           |             --------------
>           |
>    linux server notices the privilegded
>    port, 650 from the internal machine
>    and chooses another privileged port,
>    801, as the masquerading/mapping port
>           |
>           |
>           |            ______________________
>           |           |                      |
>            ---------->| server.somewhere.com |-----------
>                       |                      |           |
>                        ----------------------            |
>                                                          |
>                                server processes the ssh request, notices
>                                the privileged port, and presumably checks
>                                the RSA host key against ssh_known_hosts
>                                and allows the connection.  It communicates
>                                back to the linux server on port 801, which
>                                gets mapped to the internal server's port
>                                650, and all is well.
> 
> 
> I read the FAQ, trawled the net, and couldn't find any reference on how to accomplish
> the above (though I found plenty of information on how to make IP masquerading work
> with wacky protocols such as those used by IRC and RealAudio).  If anyone could offer
> any help on how to make this configuration work, I'd appreciate it.  Or, if you know
> that the above configuration is definitely -not- supported by the current
> implementation of IP masquerading on linux (I'm using ipchains on linux kernel
> 2.0.36), I'd appreciate that information as well.  I wouldn't necessarily be opposed
> to writing an ip_masq mod to specifically support this, but I'd definitely prefer to
> find a quicker, simpler solution.
> 
> Thanks much!
> ---
>       Luke Adamson
>       Omni Development, Inc.
>       [EMAIL PROTECTED]
> 
> _______________________________________________
> Masq maillist  -  [EMAIL PROTECTED]
> Admin requests can be handled at http://www.indyramp.com/masq-list/ -- THIS INCLUDES 
>UNSUBSCRIBING!
> or email to [EMAIL PROTECTED]
> 
> PLEASE read the HOWTO and search the archives before posting.
> You can start your search at http://www.indyramp.com/masq/
> Please keep general linux/unix/pc/internet questions off the list.
> 


Regards

--
Julian Anastasov <[EMAIL PROTECTED]>

_______________________________________________
Masq maillist  -  [EMAIL PROTECTED]
Admin requests can be handled at http://www.indyramp.com/masq-list/ -- THIS INCLUDES 
UNSUBSCRIBING!
or email to [EMAIL PROTECTED]

PLEASE read the HOWTO and search the archives before posting.
You can start your search at http://www.indyramp.com/masq/
Please keep general linux/unix/pc/internet questions off the list.

Reply via email to