Remote port forwarding

Richard E. Silverman res at shore.net
Tue Oct 10 04:04:08 EST 2000


> 	The right behaviour should be to deny the port fordwarding request,
> 	shouldn't it?

No.  From the sshd man page:

 GatewayPorts
   Specifies whether remote hosts are allowed to connect to ports
   forwarded for the client.  The argument must be ``yes'' or
   ``no''. The default is ``no''.

GatewayPorts does not control whether port-forwarding requests are
accepted or not; it controls which addresses are bound for listening.  If
it is "yes," SSH listens on all interfaces; if "no," only the loopback.

-- 
  Richard Silverman
  slade at shore.net






More information about the openssh-unix-dev mailing list