Enabling ssh erase ssh forward ?

If your problem doesn't fall into one of the other categories, report it here.

Moderator: Moderators

Post Reply
MoxFulder
Posts: 8
Joined: Mon Jan 10, 2011 6:11 am

Enabling ssh erase ssh forward ?

Post by MoxFulder »

Hi,

Today, to disable bwmon_gargoyle, I had to enable ssh.

Then, when I had to connect from outside, the router answers...instead of the computer inside the network. Previously, gargoyles forward incoming connections on port 22 to this computer.

it was the first surprise. The second was when I stopped the ssh server on the router, I was thinking the forward setting will be re-activated correctly, but no. Now I can't connect to my network :( It is not a disaster because I'll be at home tonight ;)

The question : why enabling the ssh server on gargoyle bypass the port forwarding rule ?

Eric
Site Admin
Posts: 1443
Joined: Sat Jun 14, 2008 1:14 pm

Re: Enabling ssh erase ssh forward ?

Post by Eric »

Well, you're assigning two services to the same port (port 22). That's a problem. When you do that, it's just a question of which the firewall implementation is going to prioritize, and in this case it's the router's ssh server. If you switched the port number being forwarded or the wan port open for your router's ssh server you wouldn't have the conflict and it would work fine.

MoxFulder
Posts: 8
Joined: Mon Jan 10, 2011 6:11 am

Re: Enabling ssh erase ssh forward ?

Post by MoxFulder »

hi, thanks.
My mistake, I didn't notice the default configuration set the ssh server accessible from the outside.

Eric
Site Admin
Posts: 1443
Joined: Sat Jun 14, 2008 1:14 pm

Re: Enabling ssh erase ssh forward ?

Post by Eric »

By default ssh isn't active on the external (WAN) port -- you have to explicitly turn it on by checking the appropriate box on the settings/router access page.

The ssh server is, by default, always active on the LAN on port 22.

MoxFulder
Posts: 8
Joined: Mon Jan 10, 2011 6:11 am

Re: Enabling ssh erase ssh forward ?

Post by MoxFulder »

thanks again. So I had to enable it without reading !!

Post Reply