LinuxQuestions.org
Share your knowledge at the LQ Wiki.
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 01-05-2006, 01:23 PM   #1
mattp
Member
 
Registered: Mar 2004
Location: Chicago, USA
Distribution: Slackware 10.2
Posts: 368

Rep: Reputation: 30
Remote access via static NAT


I have a redhat box behind a Cisco PIX 506E. The redhat box has an application on it that local PC's telnet into to do certain things at work. The managers want to be able to complete some work at home. The easiest way in my opinion would be to statically NAT a public IP address to the local IP of the server and allow TELNET in thru the firewall. The telnet daemon asks for a username/password which would keep any unwanted vistors out.

Also, in this network, there is a slackware 10.2 box running as a proxy server. I would like remote access to this box via SSH and am contemplating doing so thru STATIC NAT and allowing SSH thru the firewall.

I am worring about DoS attacks on the servers. Is Static NAT a safe way to achieve remote access?
 
Old 01-06-2006, 11:42 PM   #2
Capt_Caveman
Senior Member
 
Registered: Mar 2003
Distribution: Fedora
Posts: 3,658

Rep: Reputation: 69
Is Static NAT a safe way to achieve remote access?
To some degree yes, but you are opening your LAN to remote access which significantly increases risk. If you take reasonable precautions then it can be done relatively safely. Putting the server in a DMZ is probably an even better solution. Ideally though, you should really think about setting up some kind of VPN access. That way users need to authenticate to the VPN before they even get a chance to send traffic to the LAN server.

I'd also highly recommend against using telnet, expecially on an un-encrypted connection. Sending things like logins in plain-text over the internet is a bad idea. Use SSH as a replacement instead.
 
Old 01-07-2006, 01:35 PM   #3
mattp
Member
 
Registered: Mar 2004
Location: Chicago, USA
Distribution: Slackware 10.2
Posts: 368

Original Poster
Rep: Reputation: 30
I understand your point on the TELNET. If I have a server that runs of the TELNET daemon, how can I get that to use SSH. I have heard of things called a "SHUNNEL" but I am not to familiar with the concept.
 
Old 01-07-2006, 04:10 PM   #4
Capt_Caveman
Senior Member
 
Registered: Mar 2003
Distribution: Fedora
Posts: 3,658

Rep: Reputation: 69
You could do it that way by tunnelling telnet through some form of encryption tunnel (like SSH or SSL) but why not just run a SSH daemon *instead* of the telnet daemon?
 
Old 01-12-2006, 08:27 PM   #5
mattp
Member
 
Registered: Mar 2004
Location: Chicago, USA
Distribution: Slackware 10.2
Posts: 368

Original Poster
Rep: Reputation: 30
The telnet daemon is provided by a different company and I have no control over it. What else do I need to do to have the telnet thru a tunnel?
 
Old 01-13-2006, 07:36 AM   #6
Sir_Limpalot
LQ Newbie
 
Registered: Jan 2006
Location: Norway
Distribution: Debian
Posts: 18

Rep: Reputation: 0
As allready suggested: Run a vpn, that way the telnet-server is not accessible directly from the internet without logging on the vpn first and the telnet-session runs in an encrypted tunnel....
PopTop is relativeliy easy to set up, not the most secure vpn in the world but a hell of a lot better than running clear-text telnet-sessions in the open....

Last edited by Sir_Limpalot; 01-13-2006 at 07:53 AM.
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
ssh to multiple hosts behind remote nat keex Linux - Networking 3 01-05-2006 10:34 AM
Multiple Machines behind single Static IP - failing remote ssh Animalector Linux - Security 8 08-18-2005 06:01 PM
Can't access the net using static IP on Fedora. lindehoff Linux - Networking 5 04-18-2005 04:38 AM
Can't access DNS from PC using NAT/masq wsxyz Linux - Networking 1 01-20-2005 12:20 PM
Static NAT / DMZ / VPN question Funky D Linux - Networking 1 10-22-2004 07:17 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 03:22 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration