Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > comp.os.linux.networking > #1425 > unrolled thread

SSH connection through a router applying NAT

Started byMarco <netuse@lavabit.com>
First post2012-05-30 22:12 +0200
Last post2012-06-05 11:30 +0000
Articles 4 on this page of 24 — 12 participants

Back to article view | Back to comp.os.linux.networking


Contents

  SSH connection through a router applying NAT Marco <netuse@lavabit.com> - 2012-05-30 22:12 +0200
    Re: SSH connection through a router applying NAT Pascal Hambourg <boite-a-spam@plouf.fr.eu.org> - 2012-05-30 22:57 +0200
      Re: SSH connection through a router applying NAT Pascal Hambourg <boite-a-spam@plouf.fr.eu.org> - 2012-05-30 22:58 +0200
        Re: SSH connection through a router applying NAT Marco <netuse@lavabit.com> - 2012-05-30 23:12 +0200
          Re: SSH connection through a router applying NAT Pascal Hambourg <boite-a-spam@plouf.fr.eu.org> - 2012-05-31 00:10 +0200
            Re: SSH connection through a router applying NAT Marco <netuse@lavabit.com> - 2012-06-01 00:00 +0200
              Re: SSH connection through a router applying NAT Pascal Hambourg <boite-a-spam@plouf.fr.eu.org> - 2012-06-09 13:04 +0200
    Re: SSH connection through a router applying NAT Rick Jones <rick.jones2@hp.com> - 2012-05-30 22:45 +0000
      Re: SSH connection through a router applying NAT Marco <netuse@lavabit.com> - 2012-05-31 12:44 +0200
        Re: SSH connection through a router applying NAT David Brown <david@westcontrol.removethisbit.com> - 2012-05-31 12:58 +0200
          Re: SSH connection through a router applying NAT Marco <netuse@lavabit.com> - 2012-05-31 13:31 +0200
            Re: SSH connection through a router applying NAT J G Miller <miller@yoyo.ORG> - 2012-05-31 12:55 +0000
            Re: SSH connection through a router applying NAT David Brown <david.brown@removethis.hesbynett.no> - 2012-05-31 15:01 +0200
              Re: SSH connection through a router applying NAT Richard Kettlewell <rjk@greenend.org.uk> - 2012-05-31 14:36 +0100
          Re: SSH connection through a router applying NAT Whiskers <catwheezel@operamail.com> - 2012-05-31 13:45 +0000
            Re: SSH connection through a router applying NAT Marco <netuse@lavabit.com> - 2012-05-31 17:38 +0200
              Re: SSH connection through a router applying NAT Whiskers <catwheezel@operamail.com> - 2012-05-31 18:30 +0000
                Re: SSH connection through a router applying NAT J G Miller <miller@yoyo.ORG> - 2012-05-31 20:07 +0000
        Re: SSH connection through a router applying NAT J G Miller <miller@yoyo.ORG> - 2012-05-31 12:53 +0000
    Re: SSH connection through a router applying NAT Ralph Spitzner <rasp@spitzner.org> - 2012-05-31 09:56 +0200
      Re: SSH connection through a router applying NAT Pascal Hambourg <boite-a-spam@plouf.fr.eu.org> - 2012-06-09 13:06 +0200
    Re: SSH connection through a router applying NAT Chris Davies <chris-usenet@roaima.co.uk> - 2012-05-31 09:04 +0100
    Re: SSH connection through a router applying NAT ein <ein@no.spam> - 2012-06-02 11:40 +0200
    Re: SSH connection through a router applying NAT "Ralph" <ralphzodapn@ymeal.com> - 2012-06-05 11:30 +0000

Page 2 of 2 — ← Prev page 1 [2]


#1473

FromPascal Hambourg <boite-a-spam@plouf.fr.eu.org>
Date2012-06-09 13:06 +0200
Message-ID<jqvan8$2577$2@saria.nerim.net>
In reply to#1431
Ralph Spitzner a écrit :
> Marco wrote:
>> Hi,
>>
>> I want to be able to connect to my home computer via SSH from
>> the outside.
>>
>> The problem is that I am behind a NAT. Everybody in this building
> [...]
> 
> Since you have no access to the router, the simple answer is
> _NO_
> 
> Only possible scenario I could think of is that your 'home'
> initiates a connection, but where to ?

As I wrote : to any VPN provider or tunnel broker which provides a
public/global address with full end-to-end connectivity.

[toc] | [prev] | [next] | [standalone]


#1433

FromChris Davies <chris-usenet@roaima.co.uk>
Date2012-05-31 09:04 +0100
Message-ID<r9lj99x7qs.ln2@news.roaima.co.uk>
In reply to#1425
Marco <netuse@lavabit.com> wrote:
> I want to be able to connect to my home computer via SSH from
> the outside.

> The problem is that I am behind a NAT. [...]

> I have no access to the router [...]

Given these constraints you CANNOT directly get to your home computer
from outside. The only solution is for your own machine to establish a
connection to someone on the outside and use that connection to tunnel
back in again.

One option is to configure your "outside" machine to use one of the
DDNS services (such as dyndns.org) to track its IP address. Then you
can use OpenVPN from your home machine to your dyndns.org based system
to establish the connection. This presupposes that your outside machine
is not behind NAT but is directly on the Internet. If both systems are
behind NAT then you can consider the game over.

There are two important caveats with this:
    1.	You should use UDP connections with OpenVPN (rather than TCP)
    2.  You should set the "--float" option, and have the --keepalive
	(ping and ping-restart) option quite high - I'd recommend
	"--keepalive 120 300".
    
The reasons behind this are principally so that you don't spray other
users of your dynamic address space with your OpenVPN data packets. The
down-side is that it will take up to five minutes for your home server
to connect to your outside machine. (Remember: the average connection
time will be only 2.5 minutes, though.)

Chris

[toc] | [prev] | [next] | [standalone]


#1451

Fromein <ein@no.spam>
Date2012-06-02 11:40 +0200
Message-ID<jqcn2m$m15$1@node1.news.atman.pl>
In reply to#1425
On 05/30/2012 10:12 PM, Marco wrote:
> Hi,
> 
> I want to be able to connect to my home computer via SSH from
> the outside.

I've never tried this, but I've heard that it's possible to forward
traffic through tror network.

[toc] | [prev] | [next] | [standalone]


#1460

From"Ralph" <ralphzodapn@ymeal.com>
Date2012-06-05 11:30 +0000
Message-ID<4fcdedc9$0$1156$5b6aafb4@news.zen.co.uk>
In reply to#1425
Marco wrote:

> Hi,
> 
> I want to be able to connect to my home computer via SSH from
> the outside.
> 
> The problem is that I am behind a NAT. Everybody in this building
> has the same IP to the outside world. Communication within the
> network works. I can ping and connect to other computers. However,
> from the outside I am unable to reach my computer or even ping my
> external IP address.
> 
> I have no access to the router which would enable me to redirect
> incoming requests to a particular port to my computer.
> 
> Is there a possibility to set up access to my computer? If yes, how?
> All instructions I have found suggest reconfiguring the router,
> which is not possible in my case.
> 
> I am willing to provide additional information, just let me know
> what.
> 
> 
> Regards
> 
> Marco

I'm no expert but

Either the ssh executable, or sshd service  can be made to initiate the
connection or to listen.

If you have 2 computers and each can't initiate a connection to each
other, then I suppose you'd need a third one you can both reach and
then you're fine.

But if one can initiate a connection to the other, then you can do it.

If you are unable to ping your home computer, from your work
computer(your work computer behind NAT that you don't control), then, I
don't think that's a NAT issue.

Can you for example do $nmap -P0 -p6423 yourhomecomputerip

Have you gone to an online port scanner while sitting at your home
computer to make sure your home computer's port is open and a server is
running there?

If you are trying to SSH to your home computer, then the only NAT you'd
need to work with, is on that home computer.

   


-- 

[toc] | [prev] | [standalone]


Page 2 of 2 — ← Prev page 1 [2]

Back to top | Article view | comp.os.linux.networking


csiph-web