/* HINT: Search archives @ http://www.indyramp.com/masq/ before posting! */
Hello,
In these days you can't trust the privileged ports.
Just try ssh -P ! If you can't trust your users just use
publickey authentication. You always can solve this
problem without the need to masquerade with privileged
ports. Try ssh-keygen or ssh-keygen -P !
On Mon, 8 May 2000, Luke Adamson wrote:
> /* HINT: Search archives @ http://www.indyramp.com/masq/ before posting! */
>
>
> Hi,
>
> Does anyone know how to configure IP masquerading such that internal hosts using
> privileged local ports (<= 1024) for communication with external servers, get those
> ports mapped to other privilged ports on the masquerading machine?
>
> I'm running into this problem while trying to use rhosts/RSA authentication with ssh
> from a host which is masqueraded to the internet. Because the masquerading server
> (the machine with an actual internet IP address) maps internal ports to arbitrary
> unprivileged ports (> 1024), the authentication fails with:
>
> sshd: RhostsRsa authentication not available for connections from unprivileged port
>
> Ideally, I'd just have my linux box which is doing the masquerading notice when one
> of the internal local ports was <= 1024, and pick another privileged port to map it
> to.
>
> A picture might help clarify what I'd like to do:
>
> ______________
> | |
> | private host |--> ssh's to server.somewhere.com ----
> | | |
> -------------- |
> |
> allocates local privileged port
> 650 for rsh/RSA authentication
> |
> ______________ |
> | | |
> ------------| linux server |<-----------------
> | | with real IP |
> | | |
> | --------------
> |
> linux server notices the privilegded
> port, 650 from the internal machine
> and chooses another privileged port,
> 801, as the masquerading/mapping port
> |
> |
> | ______________________
> | | |
> ---------->| server.somewhere.com |-----------
> | | |
> ---------------------- |
> |
> server processes the ssh request, notices
> the privileged port, and presumably checks
> the RSA host key against ssh_known_hosts
> and allows the connection. It communicates
> back to the linux server on port 801, which
> gets mapped to the internal server's port
> 650, and all is well.
>
>
> I read the FAQ, trawled the net, and couldn't find any reference on how to accomplish
> the above (though I found plenty of information on how to make IP masquerading work
> with wacky protocols such as those used by IRC and RealAudio). If anyone could offer
> any help on how to make this configuration work, I'd appreciate it. Or, if you know
> that the above configuration is definitely -not- supported by the current
> implementation of IP masquerading on linux (I'm using ipchains on linux kernel
> 2.0.36), I'd appreciate that information as well. I wouldn't necessarily be opposed
> to writing an ip_masq mod to specifically support this, but I'd definitely prefer to
> find a quicker, simpler solution.
>
> Thanks much!
> ---
> Luke Adamson
> Omni Development, Inc.
> [EMAIL PROTECTED]
>
> _______________________________________________
> Masq maillist - [EMAIL PROTECTED]
> Admin requests can be handled at http://www.indyramp.com/masq-list/ -- THIS INCLUDES
>UNSUBSCRIBING!
> or email to [EMAIL PROTECTED]
>
> PLEASE read the HOWTO and search the archives before posting.
> You can start your search at http://www.indyramp.com/masq/
> Please keep general linux/unix/pc/internet questions off the list.
>
Regards
--
Julian Anastasov <[EMAIL PROTECTED]>
_______________________________________________
Masq maillist - [EMAIL PROTECTED]
Admin requests can be handled at http://www.indyramp.com/masq-list/ -- THIS INCLUDES
UNSUBSCRIBING!
or email to [EMAIL PROTECTED]
PLEASE read the HOWTO and search the archives before posting.
You can start your search at http://www.indyramp.com/masq/
Please keep general linux/unix/pc/internet questions off the list.