Firewall is blocking SSH when it shouldn't be

I had a [problem with SSH|http://discussions.apple.com/thread.jspa?threadID=1990417&tstart=0] on my iMac not long ago where SSH was being blocked by the Leopard firewall, even though it is configured to allow it through. I have the firewall configured as "Set access for specific services and applications" and "Remote Login (SSH)" appears on the list automatically since Remote Login is enabled on the Sharing tab of System Prefs.
The first time I had the problem I solved the problem by turning off the Leopard firewall ("allow all incoming") and then turning it back on again (in "specific services" mode). I thought it was just a one time glitch being the first time I'd ever tried getting SSH to work. After that it worked great until restarting my iMac yesterday when the firewall started blocking SSH again. Once again, turning off the firewall and then turning it back on again resolved the problem.
Any ideas? Anyone had similar problems?

Most routers thesedays even consumer routers have a stateful packet inspection firewall and also NAT.
With NAT unless you specifically open ports from the router to your mac then the outside world cannot access any of the services on your mac.
If you want to use SSH from the outside world then you would have to portforward tcp port 22 from the router to your mac. But this is not a problem if you use a strong password eg not a dictionary word or name or better still you can turn off password authentication in your ssh configuration and use public key access only.
So if you have not opened up ports on the router then your application firewall is only preventing access from other computers on your local network.
Call me paranoid, but I don't know anything about how solid the router firewall is, whereas I have much more confidence in the OS X firewall.
If you are savvy enough to know about and how to use SSH then it should be really easy for you to find out how good your router's firewall is. Understanding a router's web interface is far less demanding than learning how to use SSH.
In most cases you simply put the router's IP address into your web browser and you can see all of its services.
But something you should be aware of it is not really incoming connections you should be concerned about. It is outgoing connections that require more control.
For example if you were socially engineered by a website or elsewhere and they convinced you to install a trojan or spyware on your mac then your Mac's Application firewall would not stop these processes dialing out.
Little Snitch from obdev is an application aware firewall that controls your outgoing connections and is far more useful than the mac's application firewall on a desktop computer behind a router.
Apart from that, I'd really like to understand what's going on!
Did you try nerowolfe's suggestion of creating a test user account and login in as that user and see if the problem is still there?

Similar Messages

  • Firewall Blocking sites when it shouldn't

    Hello all,
    I have seen others have mentioned this from time to time. It seems having the nForce firewall "on" causes some websites to be unreachable. Examples include...
    http://www.space.com
    http://www.roxio.com
    http://www.netflix.com
    Try these yourselves. They work with the firewall "off" but there is no access with the firewall "on". The firewall log shows nothing. The only clue is the "Personal Firewall/Information/table" shows the "Denied outbound TCP segments" increases by 2 or more everytime I try one of these sites. I can not find any setting which control how the firewall "Denies outbound TCP segments"... Any thoughts?
    Frank
    K8N Neo Platinum...

    Quote
    Originally posted by fholub
    Hello all,
    I have seen others have mentioned this from time to time. It seems having the nForce firewall "on" causes some websites to be unreachable. Examples include...
    www.space.com
    www.roxio.com
    www.netflix.com
    Sometime in the fall of 2003 I, and some others, suddenly became unable to reach Home Theater Guide, a hi-fi forum. This was at the same time the forum moved to a new ISP.
    It was a well known problem mentioned several times on that forum, mostly by users of D-Link routers (I use a DL-604). D-Link tech support had no idea how this could happen. They said they could reach it with the same router(s).
    A few months later, the forum again changed ISP. At the same time several D-Link users (and me, although later) could universally reach it again.
    Wierd.

  • I am trying to install Kodak printer ESP C310 but it says a firewall is blocking the installation. Can you help?

    I am trying to install Kodak printer ESP C310 but it says a firewall is blocking the installation. Can you help?I am using windows XP. I have searched port 5353 and this is enabling Bonjour.

    You could check this article, but it is about Firefox itself not having access.
    : http://kb.mozillazine.org/Firewalls
    Could you provide the exact wording and punctuation of the message, and try Googling that yourself -- when you google leave out unimportant words and punctuations, group words that are still together as in original message within quotes or with hyphens so that google will look for those words together in that order.

  • Suddenly firefox will not open unless I turn off my firewall (thru McAfee). When the firewall is on, I get an error messsage that it cannot connect to the server. Any thoughts? Thanks

    when opening firefox, the connection goes to www.aol.com, and the eror states it cannot establish the connection. I am not comfortable with on-line banking to leave the firewall off, and this was never a problem until last night.

    A possible cause is security software (firewall) that blocks or restricts Firefox or the plugin-container process without informing you, possibly after detecting changes (update) to the Firefox program.
    Remove all rules for Firefox from the permissions list in the firewall and let your firewall ask again for permission to get full unrestricted access to internet for Firefox and the plugin-container process and the updater process.
    See:
    * https://support.mozilla.com/kb/Server+not+found
    * https://support.mozilla.com/kb/Firewalls

  • Dreaded "port 3689 blocked" message when trying to sync Apple TV

    I have a suggestion that MIGHT help others . . .
    I, too, received the infamous "3689 blocked" message when syncing my ATV (1st gen) to iTunes.  Never had the issue before, maybe the latest update to iTunes had something to do with it?
    Anyway, I tried everything . . . turning off firewall, adding access to port 3689 (TCP protocol) for the Apple TV in my router software, etc.  All to no avail.  Same error.  Then, I came across a reference online to adding access to port 5353 (UDP protocal) . . . that was the trick (at least for me).  So, include both in your firewall access and/or router port forwarding access and see if that does the trick for you.

    You don't need to, just check your firewall settings and ensure that access is allowed to iTunes.
    Are you running any other security software on your Mac.

  • Windows Firewall has blocked Adobe Muse

    I open Adobe Muse for the first time and I'm trying to use it, after going thru some updates and questions I get Windows Firewall has blocked some features of this program. Does Adobe Muse need to have an Internet or network connection for anything at all before I publish? the Publisher is Unknown according to the alert I get from Windows. Do I need to check the box for Private networks or Public networks, I couldn't find anything related to it on Adobe Help and when I searched for Firewall on Adobe Muse Help I get results for other applications instead that I don't use like Flash Media Encoder.

    Yes, you would need to tick both the checkboxes and click Allow Access after that.
    Thanks,
    Vikas

  • Cannot sync; receiving a message that firewall is blocking port 3689

    I am receiving an error message when I try to sync my Apple TV. The error message says that a firewall is blocking port 3689. I have checked the settings I can find, but have been unable to find the source of the problem. Has anyone had this problem and if so, how did you resolve this?

    Thanks Chenks! At least I know I'm not nuts. I have done exactly what you suggest. Itunes is in the list and I went the extra step and added port 3689. Still no luck. I've checked my McAfee settings and anything else I can find. I am at the point of resetting everything to the defaults to see if I can get around this. This is so odd as the Apple TV has been working beautifully, then, BAM! An error code and I can't synce.

  • My safari is blocked. When I press a window comes up sasking Are you sure you want to submit this form again and it will not let me cancel or submit

    My safari is blocked. When I press a window comes up sasking Are you sure you want to submit this form again? and it will not allow me to cancel or submit

    These are your options:
    1. Restore the iPhoto library from the most recent backup that predates the issue.
              Advantages: Always works, if library damage is causing the problem and the backup is intact.
              Disadvantages: Impossible if you don't have a backup. All changes made since the backup are lost.
    2. Repair or rebuild the library. Be sure to back it up first.
              Advantages: May solve the problem with no loss of data.
              Disadvantages: May fail. May take a long time if the library is large.
    3. Scavenge the library with a third-party application called "iPhoto Library Manager," which you can find in a web search. From the application's menu bar (not the iPhoto menu bar), select Library ▹ Rebuild.
              Advantages: All images should be preserved.
              Disadvantages: All books, calendars, and slideshows will be lost.

  • HT4259 I have been trying for hours to extend my Extreme Gen 5 network with an Express Gen 2.  But no matter what I do or try, it doesn't work.  What does happen is my internet gets block somehow when the Express looks like it's set up and 'green' - no in

    I have been trying for hours to extend my Extreme Gen 5 network with an Express Gen 2.  But no matter what I do or try, it doesn't work.  What does happen is my internet gets blocked somehow when the Express is online and looks like it's set up perfect and 'green' - but no internet connection for anything even though the Extreme is green and the modem is good.  Once I disconnect the Express, everything is good again.
    I've tried LAN, WAN, though a switch, direct connect, Extreme set to Extend the network, the Express set to be an extension.  Most of the time I get an error trying to update the Express.  But when it seems to be set up perfect, the entire house can't get to the internet.  Just when it looks right, it is so wrong.
    If anyone can give me exact steps (e.g., "...from the Base Station menu, select the Restore Default Setting option" vice "...just restore the defaults..."), I would greatly appreciate it.  I'm left to the conclusion that the Express is faulty.  I've been using Airport Utility 6.2 from Mountain Lion on one computer and Airport Utility 5.6.1 from Snow Leopard on another computer (the latter give more control while the former just want you to 'forget' the Express).

    I finally got it working.  I was trying to set it up ethernet.  My biggest mistake was when the new Express came on, I did not select 'Continue' - I went straight to manual thinking that I would get the most setup options in manual mode.  So everything I initially tried always resulted in 'wireless'.  Even when I would update or restore default settings, the Express would not completely restart. Or sometimes I would get an error. So most of the time I had to unplug it.  So when it came back up, none of my changes were retained. But there were a lot of times when everything was green and appeared to be fine. But anytime the ethernet cable was plugged in, no more internet.
    So here's the weird part.  When I finally tried 'continue' (vice manual), I would get 4 options.  One would be 'ethernet' extended.  So I would select it, it gave me green lights, all looked good, and still the same problem.  This is when I got frustrated.  I thought I had exhausted all possible combinations.
    But somehow when trying continue again after another restore, I only got 3 options.  One was the same ethernet extended option (can't remember what the missing 4th one was).  And this time it worked - it gave me the big green circle with the checkmark saying it was successful.  I don't know what I did different, but I know now that it won't work if 4 options come up to choose from.  It will work if only 3 options come up.  And success if only verified by the big checkmark.  Had anyone anywhere said the checkmark declaring success is validation, then maybe I wouldn't have gone down so many rabbit holes thinking it should have been successful.
    As for which Airport Utility I prefer, 6.2 looks nice, but it would just ignore the Express and would want me to 'forget' it and would not let me edit it.  Airport Utility 5.6.1 was the one that I ended up using the most and finally had success with.  It still strikes me as odd that there is no manually way to pick ethernet, it can only be choosen following a 'restore defaults', and only from the 3-option list (the 4-option list had the same ethernet choice, but it no worky).
    Thanks for the response.  I really do appreciate it.
    Aiport Extreme Gen5 - internet access and router
    Airport Express Gen2 - connected via ethernet, extending my wireless
    - configured while connect directly to the Extreme, but now on a switch (16-port hub)
    Using Airport 5.6.1
    1) Restore Defaults from Base Station menu
    2) Following restart, Select Continue
    3) Of the 3 option presented, select 'ethernet.... extend network...'
      - if 4 options are present, may not work
    4) Wait for the green circle with the big white checkmark.
    5) Connected Express to the switch where a cable went to other end of house - works.
    Dead-zone went from 2mbps to 24mbps.
    I probably spent 4 hours chasing my tail in anger.  The correct way took about 5 minutes total.
    Thanks again.

  • HP OfficeJet Pro 8500 goes to sleep, but often wakes up when it shouldn't

    HP OfficeJet Pro 8500 goes to sleep, but often wakes up when it shouldn't.  This happens over and over.  It used to sleep until I sent something to be printed. I now shut the printer down, but that takes a long time to start it up.

     When you finally get around to looking at my post, never mind.
    I reset the factory defaults on the printer and reauthorized my WiFi network.
    Now it is working.

  • Podcasts are syncing when they shouldn't be

    My iPod finally ran out of space so I wanted to remove some of the video podcasts from it. I have my podcast syncing set to sync the selected podcasts so I thought I could just uncheck the ones I didn't want to keep on my iPod and sync to remove them. That didn't work so I put my iPod in manual sync mode and removed them. I turned off the manual sync option and told it to sync again and it's copying all my podcasts (even the ones that aren't checked on the podcast tab). How do I make it stop so I can free up some space?

    Ok, I can confirm that the problem doesn't affect music playlists.
    I've also noticed that the files that get copied when they shouldn't take up more space than the ones that are supposed to be there. I noticed this by syncing, checking a podcast that was previously unchecked, then resyncing. It wasn't a lot of space, only around 10-25 mb.
    I've also found a workaround to get the files off my iPod. I have the "Sync only checked songs and videos" option checked on the summary tab for my iPod in iTunes. I can uncheck each individual podcast that I don't want to be on my iPod, then resync and they are removed. So I guess the problem is only present on the Podcasts (possibly movies and tv shows too) tab of the iPod screen in iTunes.
    Is there somewhere else I should go to submit a bug report?

  • Pictures I have taken in the past with my iPhone 5 are now a block and when I click the photo it says loading but never loads. It's like I never took the photos. There's only the blocks with no pictures. I can't click edit or anything

    I'm trying to look at my past photos in my camera roll but all that's there is a block and when I try to click on it the photo says "Loading" but nothing ever shows up. I can't click edit or anything. When I plug my phone in to my computer and open the photo folder they're not even there. It's like I never took these photos

    I notice that the home page redirects to a secure (HTTPS) address. I wonder whether there is a setting blocking this? What if you go directly to a secure page -- will it load?
    https://www.itvsn.com.au/include/sweb.dll/product?product=155602&category=92010&site_id=ITVSN
    Your add-ons list shows AVG, ZoneAlarm, and McAfee products. Could one of them be blocking this site? See whether you can add exceptions or just disable them temporarily and test whether that helps.

  • How can I interrupt the blocking call when call timeout?

    Hi,Guys
    I wrote an application server(daemon process) to talk with oracle server
    continuous which used oracle9 OCCI lib, each 5 min it executes the procedure
    on the DB server.
    Now I have come cross a problem:
    If the network is blocked, app server will blocked at occi call and would
    never pass, and no exception was catched :-(
    for e.g.
    1. Oracle server reboot without shutdown oracle process
    2. udp broadcast message storm blocked the connection between app server and
    oracle DB.
    I consider maybe it's because OCCI using the blocking mode of connection
    that caused this problem.
    How can I interrupt the blocking call when call timeout?

    Manage the timeout using a separate thread. When the timeout happens, issue a break on the OCCI connection. There is no direct way as of now. You need to do this to break a OCCI connection.
    retrieve the OCI handle from the OCCI handle (e.g. using Connection::getOCIServer or Connection::getOCIServiceContext methods) and issue a OCIBreak on it. Do not forget to allocate a error handle which should be passed to OCIBreak call.

  • AfterValueChange event trigged when it shouldn'tbe...

    Hi there,
    I'm hoping that someone out there has experienced the following (and
    knows why it is happening. ) :-)
    I have a couple of windows on which the AfterValueChange event is
    triggered on a field upon hitting the delete key.
    We all know that this should only happen upon leaving the field, ie. the
    field loosing focus. The problem is that I'm trying to recreate this in
    a simple test class, but now it won't happen. I still have the original
    windows on which it is happening, but I would like to construct
    something small and simple to send to Forte.
    Any ideas as to why this could be happening?
    Many thanks in advance.
    Jaco
    To unsubscribe, email '[email protected]' with
    'unsubscribe forte-users' as the body of the message.
    Searchable thread archive <URL:http://pinehurst.sageit.com/listarchive/>

    Thanks for the replies so far, but this is not the problem. I know about
    the "Validate on keystroke" option and it is definitely swithed off.
    I was rather thinking along the lines of this being be a 'funny' in
    Forte. Has anyone seen this before? Here is more information:
    1) The windows that it is happening on all have parent windows.
    2) The fields with this problem are all part of a mapped gridfield, ie.
    it has a type.
    However, I have constructed a test class with these characteristics, but
    it is no good. There must be something else that could cause this. Any
    ideas?
    -----Original Message-----
    From: Rottier, Pascal [SMTP:[email protected]]
    Sent: Friday, October 09, 1998 10:53 AM
    To: Fouche, Jaco
    Cc: Forte Users Mailing list
    Subject: RE: AfterValueChange event trigged when it shouldn't be...
    Hi Jaco,
    Check if the option "Validate on keystroke" is set
    to true on the widget that posts the AfterValueChange.
    If so, than that's the reason. Turn it off and your
    problem will go away.
    Pascal
    Hi there,
    I'm hoping that someone out there has experienced the following (and
    knows why it is happening. ) :-)
    I have a couple of windows on which the AfterValueChange event is
    triggered on a field upon hitting the delete key.
    We all know that this should only happen upon leaving the field, ie.
    the
    field loosing focus. The problem is that I'm trying to recreate this
    in
    a simple test class, but now it won't happen. I still have the
    original
    windows on which it is happening, but I would like to construct
    something small and simple to send to Forte.
    Any ideas as to why this could be happening?
    Many thanks in advance.
    Jaco
    To unsubscribe, email '[email protected]' with
    'unsubscribe forte-users' as the body of the message.
    Searchable thread archive
    <URL:http://pinehurst.sageit.com/listarchive/>
    To unsubscribe, email '[email protected]' with
    'unsubscribe forte-users' as the body of the message.
    Searchable thread archive <URL:http://pinehurst.sageit.com/listarchive/>

  • How do I get my number to show up as a blocked number when I call

    HOw do I get my number to show up as a blocked number when I call someone

    I think you want to simply hide the caller ID and be anonymous, not "be a blocked number" because you wouldn't be able to call anyone.
    Back when I did that, I dialed *70, waited for the next dial tone, and dialed normally. I forget which carrier that was. Verizon is *67 these days.
    Search for "Verizon block caller ID" for example. Verizon has a page and I'm sure the other carriers do, too.

Maybe you are looking for

  • SmartView 11.1.1.1 fails to connect to Provider Services

    Background: Using 11g db, Essbase Spreadsheet Add-In works, Can connect to Admin Server and Essbase with EAS, all Windows services start up fine, installed as 'Deploy Essbase in standalone mode'. Problems: 1. I get the following error trying to conne

  • Calendar not updating in Outlook 2010 but updating on OWA (Ex 2010 with Outlook 2010)

    Hi,  A few users are having this problem including me. There is a room Calendar which was working fine but not anymore. Here what is happening: User A cannot see the updates in Calendar, if someone has meeting user A cannot see it. User A can only se

  • Good day i would like to know how to do bookmark page in adobe reader

    good plz some one help me i am having macbook pro   i want to know how to add bookmark page while i am studying book and how can i bookmark page plzzzzzz thxxx

  • False alerts from LELA

    I keeping alerts from LELA stating that I have no internet connection when my internet connection is working fine. Any ideas?

  • Login credentials

    Hello, I have a question.... Does anybody know what are the credentials for this site: http://apex.oracle.com/pls/apex/f?p=4550:10 I have already tried the username: admin password: (my workspace password) Note that I have not installed apex on my co