[SOLVED]port redirect/routing question

Hi,
mypc - router - ( INTERNET ) - another pc
                                           - destination pc
"another pc" and "destination pc" are both connected to the internet via offical ips, but ports <1024 are blocked.
"another pc" can connect to "destination pc" via ssh (they are in the same network).
now i would like to connect to "another pc" and get redirected (dont know how) to "destination pc" port 22
"another pc" can connect to "destination pc" via ssh, but another pc is not my machine and i would prefer not to put my private key on it. also this solution should only work once.
This works if i want to connect to some machine inside a private lan over a router connected to the inet, but since "another pc" and "destination pc" are in the same network is nat the way to go?
iptables -t nat -A PREROUTING -p tcp -i ppp0 --dport 222 -j DNAT --to-destination 192.168.10.30:22
Any ideas?
greets
metalfan
Last edited by metalfan (2007-12-24 17:06:58)

You need openssh and tsocks
Run these commands from mypc
#tsocks configuration
/etc/tsocks.conf
server = 127.0.0.1
#this will start a shell on another, just let it run. port 1080 is the default port...no entry in /etc/tsocks.conf needed
ssh -D 1080 "another pc"
#or ssh -l yourloginnameon"another pc" -D 1080 "another pc"    #if its another user on "another pc"
#on another shell
tsocks ssh "destination pc"
took me one day to get this running, thx to Al_Berto@quakenet who solved the mistery.
greets
metalfan
Last edited by metalfan (2007-12-24 17:07:59)

Similar Messages

  • Confused asa 5520 port redirect

    HI
    The network was simple like thie
               lan-------------(gi 1)--asa5520--(gi 0)--------------wan
    lan subnet is :  192.168.0.0/24
    wan: only one ip address   1.1.1.1
    The reqire was that:   allow all lan hosts  access to the internet  .
                                      there  is a www server  (192.168.1.10)  in lan. Need it to serve for internet.
    I config the asa like this:
         interface gi 0
              nameif outside
              ip add 1.1.1.1 255.255.255.252
         interface gi 1
              nameif inside
              ip add 192.168.1.1
         object network lan_hosts
              subnet 192.168.1.0 255.255.255.0
              nat (inside,outside) after-auto dynamic source interface
         object networkd www_host
              host 192.168.1.10
              nat (inside,outside) static interface service tcp http http
    after that, i access  the   http://1.1.1.1  from internet. BUT the port redirection wasn't work.
    what's wrong .
    can someone help me!
    tks.

    Hi,
    Although I can't see anything wrong with the actual NAT configurations I would suggest the following for them
    Default PAT for LAN
    object-group network DEFAULT-PAT-LAN-SOURCE
    network-object 192.168.1.0 255.255.255.0
    nat (any,outside) after-auto source dynamic DEFAULT-PAT-LAN-SOURCE interface
    Port Forward configurations you can leave them as is.
    Have you opened the traffic with ACL also?
    For example
    access-list OUTSIDE-IN Remark Allow HTTP for Server
    access-list OUTSIDE-IN permit tcp any object www_host eq www
    access-group OUTSIDE-IN in interface outside
    Please rate if you have found the information helpfull. Ask more questions if needed.
    - Jouni

  • Port redirection in Border Manger 3.7

    Hi
    I configured a windows 2000 based VPN server inside my lan .My lan is
    protected with border manger 3.7.I configured my perimeter router to
    forward all packets to the border manager.Now I have to redirect all VPN
    calls(PPTP tunnel,port 1723) to my internal vpn server.I tested the vpn
    connectivity by bypassing the border manager and it worked fine.How can I
    do the port redirection in Border Manger?
    Chris

    Caterina
    Do BM provide port redirection ,if so how can I do it?
    Chris
    > Chris
    >
    > I've bad news. Novell's NAT (nor packet forwarding nor port redirection)
    > doesn't support the GRE protocol that is needed for the PPTP VPN of
    > Windows. You can't do that.
    > In any case, port redirection in BM is configured through the generic
    > TCP and UDP proxies. BEcause the GRE protocol isn't either TCP or UDP,
    > you can't use them for what you need to do.
    >
    > --
    > Caterina
    > Novell Support Connection Volunteer Sysop

  • Port redirection probelms

    I need to map my computer 192.168.0.1 to our static IP address so that I can access a FileMaker database remotely.
    Our dLink router had a modem built in and we just used to set port redirection and it worked, but that died recently and we are now using a separate modem and an Airport Extreme.
    Our static IP address does not appear in the AE setting and we cannot seem to get the setting right to gain outside access.
    Can anyone help?

    Kevch wrote:
    I need to map my computer 192.168.0.1 to our static IP address so that I can access a FileMaker database remotely.
    Our static IP address does not appear in the AE setting and we cannot seem to get the setting right to gain outside access.
    To configure the AirPort Extreme to use your static IP address, put AirPort Utility into "manual setup" mode, then visit the Internet panel, TCP/IP tab. If your ISP is able to provide your static IP address via DHCP, then set "Configure IPv4" to "Using DHCP", otherwise set it to "Manually".
    To map your computer to that address, I'd first go to the Internet panel, DHCP tab, and reserve a local IP address for your computer. Then go to the NAT tab, check "Enable default host at", and supply that reserved IP address. If you can't get that to work, go to the Advanced panel, Port Mapping tab, and control the mapping there.

  • RV180W - problems on rules and port redirections

    Hello,
    I installed a RV180W router a month ago.
    Our production server has to retreive informations on a remote server so I set up the rules and port redirections accordingly on the firewall.
    I noticed that some times the rules didn't work anymore and I had to reboot the RV to fix it.
    The rules are still active on the router's admin panel as well as the services and the port redirection. The last firmware is installed.
    Does anyone experienced the same problem and found a fix?
    Thanks in advance,
    Best regards

    I hate to say it, but there are issues like this with the rv series.  Have you replace the router with another one?  That's the first thing I would try since you can probably exchange it easily right now.
    Huntsville's Premiere Car and Bike e-magazine: www.huntsvillecarscene.com

  • I am having trouble viewing iStore. It appears as if its a Flash issue, as several minutes after logging in to iStore I get a non-flash page of iStore in my iTunes window. I have re-installed everything and tried opening all ports in router....any ideas?

    I am having trouble viewing iStore. It appears as if its a Flash issue, as several minutes after logging in to iStore I get a non-flash page of iStore in my iTunes window. I have re-installed everything and tried opening all ports in router, and used msconfig to bring up each service individually to see if there is an effect.Flash and iTunes have been re-installed  ...any ideas?

    I agree. I don't rely on iCloud as a backup, that is what I have my portable hard drive for. Its 500 GB so I can hold my entire iTunes library several times over on it. I have all my movies on my hard drive, but somehow "The Mist" got deleted off of my hard drive, so I figured "Well, the option to redownload an already purchased movie is available through iCloud, I'll just do that!"
    And permissions and download availability have nothing to do with it, the movie's still there, it still allows me to redownload it. The only problem is when I click download, I get that message.
    And nobody else uses my computer, but I do have multiple accounts authorized on it. Even still though, I am attepmpting to download it through the account I purchased it under. :/

  • Has anyone successfully used a "WD My Book for Mac" via NAS (plugged into USB port on router) as a Time Machine back-up drive?

    Has anyone successfully used a "WD My Book for Mac" via NAS (plugged into USB port on router) as a Time Machine back-up drive? Apple support tech tried to tell me it wasn't possible and that the only NAS Time Machine could back up to is the Time Capsule, but I'm not buying it. I know it's doable, but I'm having a hard time figuring out which External HDDs will work and which ones won't.  If not My Book for Mac, is there an External HDD that will work? (Running OS X 10.9.1 - Mavericks, btw...)

    Given the nature of backups, my recommendation has always been to use a strategy that is unequivocally supported by Apple. As you already determined Apple Support unequivocally informed you that your proposal will not work, unless your router is an Apple AirPort Extreme or Time Capsule.
    The exhaustive list of devices supported by Time Machine amounts to the following:
    AirPort Time Capsule's built-in hard disk (any model)
    External USB hard disk drive connected to a Time Capsule (any model)
    External USB hard disk drive connected to an AirPort Extreme (current model only)
    A hard disk drive directly connected to your Mac
    That is all.
    Use whatever backup device you want, but you should be aware that this site is full of reports of misery from hapless individuals who had been using NAS devices for Time Machine backups, only to find that they were incomplete, corrupted, or useless when they were required. Apple won't care if you lose your data while using a Time Machine configuration specifically excluded from their technical support documents.

  • How to check UC560 FXO Port Not Problem Question

    Dear All,
    We are newbie on Cisco UC560.
    Our customer use Cisco UC560, ESW-520-24P and Cisco SPA 502G and 508G for their branch office replace old traditional PBX. Cisco UC560 have built-in VIC2-4FXO and VIC2-4FXS.
    Our customer PSTN line connected to UC560 FXO port (1 line PSTN).
    We receive report from our customer that they cannot make a call to PSTN and receive call from PSTN that connected to UC560 FXO port (on physical FXO port LED Green turn on).  When the problem happen our customer has restart UC560 or shutdown FXO port from CLI.
    We have do some test to our customer UC560.
    - Moving PSTN line to another FXO port (example: port from 0/1/0 to 0/1/1). The result is same (cannot make call to PSTN and receive call from PSTN)
    Today, We have checked on our customer UC560 via show voice port summary and found that port0/1/2 and 0/1/3 OPER status is up wihout cable connected to this port.
    Our question:
    - What command on UC560 to make sure FXO port on UC560 doesn't have problem?
    We attach:
    show tech-support voice
    show tech-support
    We hope you can give us information about this.
    Thanks For Your Attention

    Hi There,
    If you cannot find the Indonesian "Disconnect Supervision" you may get away with using Singapores "Disconnect Supervision" as your carrier networks are similar to each other
    Cheers,
    David Trad.

  • Port based routing?

    Hi,
    My Mac connects to Internet through ADSL router, and to a PPTP-VPN host through this connection.
    And I want to FORCE all my http/https connections(that use destination port 80, 443, and perhaps some more) to use the VPN, while keep anything else go through the ADSL router directly.
    Is this possible?

    Did you find any solution?
    I'm trying to find a way to do this too.. on linux port based routing can be done with iptables. Mac OS X uses ipfw but:
    The fwd action does not change the contents of the packet at all.
    In particular, the destination address remains unmodified, so
    packets forwarded to another system will usually be rejected by
    that system unless there is a matching rule on that system to
    capture them.
    Then there is natd? I'm not sure if this can be used..
    And another one is /etc/pf.conf which has this openbsd guide but fails with "PF ERROR! No ALTQ support in kernel. ALTQ related functions disabled".

  • ACE 4170 port redirection in Bridged mode

    Hi Friends,
    Is it possible to do port redirection on ACE while it is configured on Bridged Mode. For example. a user is accessing the Loadbalancer VIP on port 80 and this is redirected to port 8080 on backend servers?
    I have attached a diagram for easier understanding. Is there a need to configure NAT in such cases?
    Any help will be appreciated. Thanks in advance guys.

    Hi,
    if you want to allow ping to the VIP address, you only need to apply this command in your L3-4 policy map:
    loadbalance vip icmp-reply
    example:
    policy-map multi-match L4-TEST-VIPS
    class WWW-TEST
    loadbalance vip inservice
    loadbalance policy WWW_POLICY
    loadbalance vip icmp-reply
    more info can be found here:
    http://www.cisco.com/en/US/docs/interfaces_modules/services_modules/ace/v3.00_A2/configuration/slb/guide/classlb.html#wp1000929
    If you want ICMP to pass through the ACE tp reach the real servers, you need to allow it in an ACL.
    Hope this helps,
    Dario

  • RV016 Wired 16 Port Cisco Router Port Forwarding Functions

    Thank you for your time. I have created and attached a Word Document discussing the Cisco Model RV016 16 port wired Router port forwarding functions for your review. I would appreciate your time in reviewing it with your comments and suggestions.
    Thank you very much,
    Eddie LeFiles
    850-471-1271

    Thank you for your time. I have created and attached a Word Document discussing the Cisco Model RV016 16 port wired Router port forwarding functions for your review. I would appreciate your time in reviewing it with your comments and suggestions.
    Thank you very much,
    Eddie LeFiles
    850-471-1271

  • Wrt54gs V4 FWv1.06.1 - Port Redirection not supported? Any workarounds?

    My office does not allow any outbound traffic except for port 80 and 443. On my home network I have VNCServer listening on port 5900. I'd like to have the incoming port 443 to go 192.168.1.102 port 5900. I'm able to successfully 'port range forward' port 443 to go to 192.168.1.102 port 443 ( I modified my VNC Server to listen on port 443 ). I am having difficulty when my VNC Server listens on it's normal port of 5900 as no matter what I do in ' port triggering ' it doesn't allow for port redirection, not that I see. Any help would be appreciated.

    I does not support port redirection. I think none of the Linksys routers supports that.

  • Virtual Hosts & Port Redirections

    Hi guys,
    In 10.6 i used to be able to setin the Server Admin GUI settings for the web service. This included Virtual Hosts & Port Redirections. How do i go about doing this on 10.7?
    For example, I need myserver.mycompany.com:80 to redirect to myserver.mycompany.com:8088 & mygreatsite.company.com:80 to redirect to mygreatsite.company.com:9006.
    Both of which are hosted on myserver.mycompany.com.
    Links apprecaited.. i'm guessing i'm in for an Apache lesson?

    I hope that article helps you, maybe you can figure it out and post back for the rest of us!
    I haven't actually read it yet, I just saved it to my Pinboard page for later, because I know eventually I will have to deal with vhosts in Lion.

  • DesktopApp auto update URL port redirection.

    Hi Everyone,
    We are using Filr-1.0.1-HP1 and we are using the port-redirection option to redirect port 80 & 443 to 8080 & 8443 respectively. However this port-redirection doesn't seem to work for the auto update URL. I would rather not open the port 8443 on the firewall. Am i missing some configuration option somewhere?
    https://<baseurl>/Desktopapp
    invalid URL
    https://<baseurl>:8443/Desktopapp
    OK
    Kind Regards,
    Justin Zandbergen
    edit: typo's

    Originally Posted by thsundel
    Justin, take a look here: https://forums.novell.com/showthread...67#post2295867
    Tomas
    Hi Thomas,
    Thanks for the advice, i knew that was an option, but i would have preferred to stick it on filr.<customer>.nl/desktopapp instead of something.<customer>.nl/desktopapp. Ah well, it works now. Thanks!
    Kind Regards,
    Justin Zandbergen

  • Datasocket port redirection

    I need to communicate with a datasocket through a firewall where I can open only 1 port. This article: http://digital.ni.com/public.nsf/websearch/FCF8A1464BD2F6D686256B59007C9A6F?opendocument&Submitted&&node=133020_US explains that datasocket client use, a random port in interval: 1024-65536. Do you know if exists a windows tool for port redirection (or other tricks...)?
    Thank you,
    paolo.

    I haven't tried this, but the first thing that comes to mind is specifing the port after the datasocket address. Something like this...
    dstp://192.192.0.1/getdata:1024
    You use this same format for URLs when you need to use a specific port.
    Ed
    Ed Dickens - Certified LabVIEW Architect - DISTek Integration, Inc. - NI Certified Alliance Partner
    Using the Abort button to stop your VI is like using a tree to stop your car. It works, but there may be consequences.

Maybe you are looking for

  • ITunes will not open after update/reinstall

    I tried to update to the newest version of Itunes when prompted, but since then I have not been able to open the program. I have followed the instructions and uninstalled and re-installed the program multiple times. When I attempt to open Itunes, I s

  • Laserjet Pro 400 MFP M425DN Can not connect to HP Web Services

    I have a Laserjet Pro 400 MFP M425DN  printer on a network running windows 7 and we Can not connect to HP Web Services. When we use the display on the menu it comes back with error "Internal Processing error, try again or check firmware update"  We i

  • BPM as sender service to another BPM

    Hi Experts,                    I have a requirement, where I need to define my first BPM as sender service for second BPM.  abstract interface in last send step of first BPM and abstract interface in first receive step of second BPM has same message

  • Stop, start all nodes.

    To shutdown database instance on all the nodes in a clusterd env/. I use srvctl stop/start database -d dbname Likewise what is the best way for ASM and cluster? Thanks!

  • Disabling the SSID broadcasting on E3000.

    Disabling the SSID broadcasting on E3000, is it necessary, if so what can expect to happen?