10-24-2008
ssh X-forwarding and remote forwarding behind proxy
Hi,
from my workplace we use a proxy to connect to the outside world, including external ssh servers.
The problem is that the server is seeing the connection coming from the proxy and knows nothing about the client behind it. The ssh connection itself works fine, but x-forwarding does not work as expected. In my opinion this is because the server is trying to use the display of the proxy and not the one of the client.
Same issue with remote port forwarding, when someone uses the remote port I think the ssh server forwards the request to the proxy and not to the real client.
I have found two workarounds to solve the x-forwarding issue:
-create a VPN between the client and the server, and do the x-forwarding inside the VPN (which is similar to a LAN)
-install a VNC server on the ssh server, a VNC client on the ssh client and do a local port forwarding, then connect to localhost:xxxx
I'm sure the VPN solution will fix the remote forwarding as well, but... is there a way to get around these issues without using other software, maybe some kind of environment variables to set in OpenSSH?
Thanks.
10 More Discussions You Might Find Interesting
1. OS X (Apple)
Hi,
I have issues with running graphical interfaces on my computer being remotely logged into a network via the -X option of ssh. My .cshrc shows DISPLAY=hostname:0 and I think there should be a different number instead of the 0. I changed the ssh_config file already to 'X11 forwarding yes', which... (0 Replies)
Discussion started by: ginese
0 Replies
2. UNIX for Advanced & Expert Users
As in the ssh(1) man page:
-R bind_address:]port:host:hostport
.......By default, the listening socket on the server will be bound to the loopback interface only. This may be overridden by specifying a bind_address. An empty bind_address, or the address `*', indicates... (2 Replies)
Discussion started by: ahmad.zuhd
2 Replies
3. Shell Programming and Scripting
Hi Experts,
I am trying to have the SSH tunnel Remote forwarding command in a shell script. I should be able to do 2 tasks, but unable to get that going.
1) I have 3 servers Server 1, Server 2, Server 3.
I have my Database running on Server 1 and my script running on Server 2 which should... (0 Replies)
Discussion started by: Scriptingglitch
0 Replies
4. UNIX for Dummies Questions & Answers
So this seems like something that should be simple...but I can't quite seem to get it up and running. I have a machine, .107 with a GUI on port 8443. The problem is that I can't connect directly to .107 from my laptop. Now I have another machine, .69 that can connect to .107. So shouldn't I be able... (4 Replies)
Discussion started by: DeCoTwc
4 Replies
5. AIX
Due to a project I'm currently tasked with I'm spending my time trying to find a way to forward the syslog to a remote, in this case Red Hat, server and squeezing it into a SQL DB.
Rsyslog is doing this job quite nicely for most of our test-servers, but I couldn't find any reliable information on... (1 Reply)
Discussion started by: Skleindl
1 Replies
6. UNIX for Advanced & Expert Users
Hi,
Local PC - Ubuntu 11.04 desktop
Remote PC - Debian 6.0 desktop
My problem is 2 desktops, remote and local, are displayed on the same workplace on local PC. It would be quite confusing. Is there any way to display each desktop on one workplace(on its own workplace) OR displaying both... (0 Replies)
Discussion started by: satimis
0 Replies
7. Cybersecurity
Hello,
I have a question about X forwarding. I was told that we can't X forwarding anymore, do to a security checklist.
Example:
bitlord@server1# ssh -X server2
So we have to use the DISPLAY variable now. I thought this was less secure?
Example:
bitlord@server1# xhost + server2
server1... (0 Replies)
Discussion started by: bitlord
0 Replies
8. IP Networking
Hi,
I'm trying to connect ftp over ssh port forwarding to a sever(UnixC) behind FireWall(F/W). here's my env and question.
UnixA(SSH Client) ----F/W ---- UnixB(SSH Svr) ---- UnixC (FTP, 21)
UnixA wants to connect ftp service of UnixC via SSH port forwarding on UnixB.
Unix A,... (3 Replies)
Discussion started by: hanyunq
3 Replies
9. Shell Programming and Scripting
Hi guys, I'm trying to set up an Ubuntu VPN server that will forward an ssh connection automatically as a proxy to two separate LAN hosts.
What I'm looking at doing is making SSH listen on two ports (if that is possible) and get some kind of script, preferably something in bash, that will listen... (2 Replies)
Discussion started by: 3therk1ll
2 Replies
10. Shell Programming and Scripting
Sorry for the wrong question. (2 Replies)
Discussion started by: hce
2 Replies
LEARN ABOUT LINUX
ssh-socks5-proxy-connect
ssh-socks5-proxy-connect(1) User Commands ssh-socks5-proxy-connect(1)
NAME
ssh-socks5-proxy-connect - Secure Shell proxy for SOCKS5
SYNOPSIS
/usr/lib/ssh/ssh-socks5-proxy-connect [-h socks5_proxy_host] [-p socks5_proxy_port] connect_host connect_port
DESCRIPTION
A proxy command for ssh(1) that uses SOCKS5 (RFC 1928). Typical use is where connections external to a network are only allowed via a socks
gateway server.
This proxy command does not provide any of the SOCKS5 authentication mechanisms defined in RFC 1928. Only anonymous connections are possi-
ble.
OPTIONS
The following options are supported:
-h socks5_proxy_host Specifies the proxy web server through which to connect. Overrides the SOCKS5_SERVER environment variable.
-p socks5_proxy_port Specifies the port on which the proxy web server runs. If not specified, port 80 is assumed. Overrides the
SOCKS5_PORT environment variable.
OPERANDS
The following operands are supported:
socks5_proxy_host The host name or IP address (IPv4 or IPv6) of the proxy.
socks5_proxy_port The numeric port number to connect to on socks5_proxy_host.
connect_host The name of the remote host to which the socks gateway is to connect you.
connect_port The numeric port number of the socks gateway to connect you to on connect_host.
EXAMPLES
The recommended way to use a proxy connection command is to configure the ProxyCommand in ssh_config(4) (see Example 1 and Example 2).
Example 3 shows how the proxy command can be specified on the command line when running ssh(1).
Example 1: Setting the proxy from the environment
The following example uses ssh-socks5-proxy-connect in ssh_config(4) when the proxy is set from the environment:
Host playtime.foo.com
ProxyCommand /usr/lib/ssh/ssh-socks5-proxy-connect
playtime.foo.com 22
Example 2: Overriding proxy environment variables
The following example uses ssh-socks5-proxy-connect in ssh_config(4) to override (or if not set) proxy environment variables:
Host playtime.foo.com
ProxyCommand /usr/lib/ssh/ssh-socks5-proxy-connect -h socks-gw
-p 1080 playtime.foo.com 22
Example 3: Using the command line
The following example uses ssh-socks5-proxy-connect from the ssh(1) command line:
example$ ssh -o'ProxyCommand=/usr/lib/ssh/ssh-socks5-proxy-connect
-h socks-gw -p 1080 playtime.foo.com 22' playtime.foo.com
ENVIRONMENT VARIABLES
SOCKS5_SERVER Takes socks5_proxy_host operand to specify the default proxy host.
SOCKS5_PORT Takes socks5_proxy_port operand to specify the default proxy port.
EXIT STATUS
The following exit values are returned:
0 Successful completion.
1 An error occurred.
ATTRIBUTES
See attributes(5) for descriptions of the following attributes:
+-----------------------------+-----------------------------+
| ATTRIBUTE TYPE | ATTRIBUTE VALUE |
+-----------------------------+-----------------------------+
|Availability |SUNWsshu |
+-----------------------------+-----------------------------+
|Interface Stability |Stable |
+-----------------------------+-----------------------------+
SEE ALSO
ssh(1), ssh-http-proxy-connect(1), ssh_config(4), attributes(5)
SunOS 5.10 30 Oct 2002 ssh-socks5-proxy-connect(1)