SSH Remote Forwarding Configuration and GatewayPorts
The GatewayPorts parameter in the SSH daemon configuration (/etc/ssh/sshd_config) determines how the remote server binds sockets during remote port forwarding. Depending on this setting, specific firewall or agent rule exceptions may be required.
Scenario 1: GatewayPorts set to yes
When GatewayPorts is enabled, sshd forces the remote forwarding port to bind to all available interfaces.
· Binding Behavior: The service binds specifically to 0.0.0.0 for IPv4 and :: for IPv6.
· Rule Requirements: If your default policy is to deny all requests, your exceptions must explicitly include 0.0.0.0 (IPv4) and :: (IPv6) in the INTERFACE section.
· Command Override: Any specific interface IP provided in the SSH command (e.g., ssh -R interface_ip:port...) will be ignored; the daemon will still bind to all interfaces.
Scenario 2: GatewayPorts set to clientspecified
This setting allows the client to choose which interface the forwarded port should bind to.
· Binding Behavior: The sshd server respects the specific interface IP provided in the remote forwarding command.
· Rule Requirements: The INTERFACE section of your tunneling rule exceptions should match the specific IP address of the interface on the agent host being utilized.
· Example:
If an agent host has multiple interfaces (e.g., 10.x.x.1 and 10.x.x.2), and a user executes:
ssh -R 10.x.x.1:8443:target_ip:443 user@host
The tunnel will bind only to 10.x.x.1. To permit this traffic, the INTERFACE section of the security rule must be configured to allow 10.x.x.1.