There seem to be two ways to allow ssh access from outside the
firewall to a host inside: 1. forward some port on the fw to the host;
2. connect directly to sshd on the fw and use the -Lport:host:port
flag to forward an additional connection to the host.

Is there agreement on which method is better (where "better" means
more secure, I guess)?

The fw and host are at home.  Most of the time I'm connecting from
outside I'm either at work and want to xhost some app, or I want to
transfer a bunch of files.  Occasionally I need to tweak the router,
so picking #1 above wouldn't remove the need to have sshd on the
router's floppy.

Connections are always from machines that have keys in the router's
(and inside host's) .ssh/authorized_keys files.  Password login is
disabled.

I'm running Bering RC2.

Thanks,

--Eric

******************************************************************************
* From the desktop of: Eric House, [EMAIL PROTECTED]                            *
*    Crosswords 4.0 for PalmOS is out!: <http://www.peak.org/~fixin/xwords>  *
******************************************************************************


_______________________________________________________________

Don't miss the 2002 Sprint PCS Application Developer's Conference
August 25-28 in Las Vegas -- http://devcon.sprintpcs.com/adp/index.cfm

------------------------------------------------------------------------
leaf-user mailing list: [EMAIL PROTECTED]
https://lists.sourceforge.net/lists/listinfo/leaf-user
SR FAQ: http://leaf-project.org/pub/doc/docmanager/docid_1891.html

Reply via email to