LinuxQuestions.org
Visit Jeremy's Blog.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Networking
User Name
Password
Linux - Networking This forum is for any issue related to networks or networking.
Routing, network cards, OSI, etc. Anything is fair game.

Notices


Reply
  Search this Thread
Old 09-22-2006, 08:32 AM   #1
mpapet
Member
 
Registered: Nov 2003
Location: Los Angeles
Distribution: debian
Posts: 548

Rep: Reputation: 72
SSH >> DSL Modem Headaches


I've got a basic networking problem that doesn't seem to work using a basic networking config.

I'm trying to ssh from work into my home PC.

Here's the basic layout.
HomePC >> Firewall/Nat/Router>>DSLModem >> Internet
I've given the PC a static IP outside the DHCP pool. The PC connects to the internet just fine.
The firewall/nat/router has a "DMZ" option enabled with the static IP listed below it.

Here's what the PPPOE settings are reporting back:
IP Address: 69.3.114.127
Subnet Mask: 255.0.0.0
Default Gateway: 172.31.255.251

Those values are exact. I installed a web server just to test that the address can be seen.

At this point, I'm thinking the "DMZ" option may be forwarding ports, but not smart enough to do it right in my situation. So, I can turn off DMZ and set up a "virtual server" where I can forward public IP/port to private. Using the public IP and local IP, this doesn't work either.
 
Old 09-22-2006, 09:27 AM   #2
nuxrl
Member
 
Registered: Jun 2006
Location: NY, USA
Distribution: Slackware, Arch
Posts: 176

Rep: Reputation: 35
Do you have direct internet connection from your work PC? Probably you should make sure that you can see the WAN ip assigned to you by your ISP first from work. I have my server behind the firewall and the "virtual server" forwards ssh requests to the local server. It's working fine.
 
Old 09-22-2006, 10:31 AM   #3
mpapet
Member
 
Registered: Nov 2003
Location: Los Angeles
Distribution: debian
Posts: 548

Original Poster
Rep: Reputation: 72
How Do I "See" the WAN IP?

Quote:
Originally Posted by nuxrl
Do you have direct internet connection from your work PC? Probably you should make sure that you can see the WAN ip assigned to you by your ISP first from work. I have my server behind the firewall and the "virtual server" forwards ssh requests to the local server. It's working fine.
An update:
I turned off the dmz setting and used the "virtual server" setting my firewall/router box has to forward ports 22/tcp and 80/tcp&udp to the internal address (Port 80 is temporary)

My ISP (earthlink) says they only block smtp-in connections (24?) otherwise, I should have no problems.

I also explicitly allowed port 22/tcp in and out and port 80 in and out on the firewall.

I'm double-checking if Debian Etch comes with a firewall script today too. In Sarge there was no firewall script in a default install. FYI Etch and the GUI installer work well. Very high quality for a testing branch. Equivalent to a Fedora release.

I can now ping from work and get replies. I'm assuming I'm pinging my IP address. How do I otherwise "see" my ip address from work?

I'm ready to dump the firewall/router at this point because I think the problem is there. It's a dlink with analog telephone adapter built-in. You get what you pay for right?

Thanks for the help.
 
Old 09-22-2006, 12:17 PM   #4
Draygo
Member
 
Registered: May 2004
Location: Frisco, TX
Distribution: Debian Unstable
Posts: 73

Rep: Reputation: 15
Are you getting a connection refused or are you just timing out? Have you tried sshing to your deb box internally from another box on the lan?

Debain in the past ships with an empty hosts.allow file. This in affect stops anyone from connecting to that system that uses tcp wrappers, if I remember correctly. Try renameing /etc/hosts.allow file to hosts.allow.bak as well as the /etc/hosts.deny file to hosts.deny.bak.

Let me know if this works.
 
Old 09-22-2006, 12:45 PM   #5
mpapet
Member
 
Registered: Nov 2003
Location: Los Angeles
Distribution: debian
Posts: 548

Original Poster
Rep: Reputation: 72
Quote:
Originally Posted by Draygo
Are you getting a connection refused or are you just timing out? Have you tried sshing to your deb box internally from another box on the lan?

Debain in the past ships with an empty hosts.allow file. This in affect stops anyone from connecting to that system that uses tcp wrappers, if I remember correctly. Try renameing /etc/hosts.allow file to hosts.allow.bak as well as the /etc/hosts.deny file to hosts.deny.bak.

Let me know if this works.
1. Yes, I can ssh from my laptop to the other PC inside my home LAN.
2. From work: Putty reports a time out. ssh reports time out.
3. I'll check the hosts.allow file tonight.

Thanks again.
 
Old 09-22-2006, 02:09 PM   #6
mpapet
Member
 
Registered: Nov 2003
Location: Los Angeles
Distribution: debian
Posts: 548

Original Poster
Rep: Reputation: 72
Port Scanning Info

I scanned the IP address for port 22 and it replied as "filtered."

It correctly detected the firewall's OS, so I'm sure it's still my IP.

How do I open that port?
 
Old 09-23-2006, 10:25 AM   #7
mpapet
Member
 
Registered: Nov 2003
Location: Los Angeles
Distribution: debian
Posts: 548

Original Poster
Rep: Reputation: 72
ssh >> DSL Solved

I replaced the router/firewall with a netgear fvs114. Works like a charm.

Maybe it's just mine but, Dlink dvg-1402S doesn't forward ports and DMZ IP address settings don't work.

Thanks for all the suggestions.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
D-Link DSL-200 Rev B DSL modem -- success!! ludeKing Linux - Hardware 1 03-11-2007 06:32 PM
ssh to DSL Kdr Kane DamnSmallLinux 3 06-26-2005 03:27 PM
SSH and dsl-g604t Secyritas Linux - Networking 0 06-04-2005 01:18 PM
Dsl Modem Installation -- Aztech Dsl Turbo 100 psganesh Linux - Networking 0 07-01-2004 02:04 AM
SSH problem with DSL jtshaw Linux - Networking 4 05-11-2003 11:44 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Networking

All times are GMT -5. The time now is 08:04 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration