118
First select the desired protocol. Specify a single IP address or a network address with
its corresponding netmask if you want to restrict the acceptable source or destination
IPs.
Protocols are defined in menu "Definitions > Protocols".
Non UDP and TCP protocol signatures will be ignored.
12.3.2-L
SSH TCP Forwarding
Secure-shell clients can establish authenticated and encrypted channels, carrying TCP
connections to (usually internal) servers. From the technical point of view an SSH
forwarding is situated somewhere between simple DNAT and VPN. In contrast to DNAT
the connection is secured with authentication and encryption. Compared to VPN, the
SSH tunnel lacks among others transparency in respect of the client application, only
unidirectional TCP connections are supported and inexperienced users might be fooled
easier by man-in-the-middle attacks. In return an SSH forwarding is easier to configure
and maintain.
The corresponding SX-GATE SSH server is available on port 2222. A separate firewall
rule might be necessary for the remote access over the internet. Use the predefined
protocol "SSH-FWD".
Using firewall DNAT rules it is possible to make the server
appear on a different port. You could e.g. redirect HTTPS port
443 to 2222 to make it easier for SSH client to pass firewalls and
proxies.
Public SSH RSA key
Please enter the client's public SSH RSA key. The key starts with "ssh-rsa", followed by
one space character and several hundred letters, digits, slashes, plus and equal signs
in a single long row. Space characters or newlines are not allowed in there. An optional
space character and comment may be appended. Extremely shortened example of a
key: "ssh-rsa AA3x/5+eW48oPvX= Comment".
Permitted connections
The SSH client may connect only to addresses and ports from this list.
Содержание SX-GATE
Страница 1: ...State 2016 12 13 V7 0 2 0 User Guide ...
Страница 92: ...12 1 Setup 92 There s no way to restore a purchased certificate without backup ...
Страница 126: ...12 3 3 Groups 126 12 3 3 C Usage This table show in which settings the definition is used ...
Страница 476: ...15 3 Apple iPhone 476 ...