What is SSH Tunneling or SSH Port Forwarding - What are the risks (2024)

SSH Tunneling or SSH Port Forwarding is a technique to send data with an existing SSH Connection. For example a corporate network has an internal web serveR noT accessible from Internet and you want access internal resources securely, the SSH Tunneling or SSH Port Forwarding allows external users to use the SSH Encrypted Tunnel to send Web Traffic to the internal server. Basically you will send a non-SSH traffic over the SSH Tunnel, this is why it is referred to SSH Tunneling, you tunnel a non-SSH traffic inside an SSH Tunnel.

If we take an analogy or a comparison, the remote access VPN has the same logic.

Remote access VPN connects securely external users to internal resources through a VPN Gateway which can be a Firewall or a Router.

External PC <-> VPN Gateway <-> Internal Web Server.

SSH Tunneling works the same ways.

External PC <-> SSH Server <-> Internal Web Server.

The SSH Server will act like a VPN Gateway.

Let's take an example with Putty Application.

In this topology we have a Web Server in the internal network which not accessible from Internet. The SSH Server is accessible from Internet using for example a Static NAT, and an external client located in the outside world.

What is SSH Tunneling or SSH Port Forwarding - What are the risks (1)

The goal is to allow the external client to reach the web server through the SSH Server.

So first open the Putty application to access the command line of the SSH Server 192.168.1.61.

What is SSH Tunneling or SSH Port Forwarding - What are the risks (2)

In the Tunnels field, you enter the destination IP Address of the web server 10.1.6.150 and the port it listens to.

In the Source Port field select any port you desire, for example 8888.

What is SSH Tunneling or SSH Port Forwarding - What are the risks (3)What is SSH Tunneling or SSH Port Forwarding - What are the risks (4)

The first step when you click the Open button, you connect to the SSH Server.

What is SSH Tunneling or SSH Port Forwarding - What are the risks (5)

But in the background when you type 127.0.0.1:8888 in the web browser on the external client, you are redirected to the web server 10.1.6.150. Below the SSH Server and the netstat output.

What is SSH Tunneling or SSH Port Forwarding - What are the risks (6)

What is SSH Tunneling or SSH Port Forwarding - What are the risks (7)

What is SSH Tunneling or SSH Port Forwarding - What are the risks (8)

But there are security risks with The SSH Tunneling, if you allow SSH using port-based filtering with the standard port 22, bad actors can use the SSH Port Forwarding as an evasion technique to send non-ssh traffic inside the SSH tunnel, which increases the attack surface because any application can use an open port.

Using the port-based filtering to allow the standard SSH Port, any application, SSH or not is allowed, so what if inside the SSH Tunnel there is threat or non-legitimate connection to your internal resources ? This is why, it's alway recommended to create policy rules based on application, not port.

So when you used SSH application in your policy rule as a matching criteria to allow SSH. Any application that is not identified as SSH is blocked, denying any attempt to do SSH Port Forwarding, therefore you reduce attack surface.

What is SSH Tunneling or SSH Port Forwarding - What are the risks (2024)
Top Articles
P/E 30 Ratio: Formula, Meaning, and Examples
Top 10 Best Companies for Work-From-Home
Omega Pizza-Roast Beef -Seafood Middleton Menu
Canya 7 Drawer Dresser
Mate Me If You May Sapir Englard Pdf
Mama's Kitchen Waynesboro Tennessee
Mlifeinsider Okta
Over70Dating Login
Horned Stone Skull Cozy Grove
414-290-5379
Inside California's brutal underground market for puppies: Neglected dogs, deceived owners, big profits
2024 Non-Homestead Millage - Clarkston Community Schools
Industry Talk: Im Gespräch mit den Machern von Magicseaweed
Kaomoji Border
Steamy Afternoon With Handsome Fernando
Uktulut Pier Ritual Site
Aris Rachevsky Harvard
Costco Great Oaks Gas Price
Atdhe Net
Homeaccess.stopandshop
Betaalbaar naar The Big Apple: 9 x tips voor New York City
Brbl Barber Shop
Home
Hdmovie2 Sbs
Foolproof Module 6 Test Answers
Papa Johns Mear Me
800-695-2780
Wku Lpn To Rn
Keshi with Mac Ayres and Starfall (Rescheduled from 11/1/2024) (POSTPONED) Tickets Thu, Nov 1, 2029 8:00 pm at Pechanga Arena - San Diego in San Diego, CA
Chicago Pd Rotten Tomatoes
Heavenly Delusion Gif
Aliciabibs
Kazwire
Hindilinks4U Bollywood Action Movies
Winco Money Order Hours
Felix Mallard Lpsg
Legit Ticket Sites - Seatgeek vs Stubhub [Fees, Customer Service, Security]
Xxn Abbreviation List 2023
The best specialist spirits store | Spirituosengalerie Stuttgart
Online-Reservierungen - Booqable Vermietungssoftware
Cch Staffnet
Tacos Diego Hugoton Ks
CrossFit 101
Lebron James Name Soundalikes
Argus Leader Obits Today
Every Type of Sentinel in the Marvel Universe
Concentrix + Webhelp devient Concentrix
Wvu Workday
Congressional hopeful Aisha Mills sees district as an economical model
Dcuo Wiki
Karen Kripas Obituary
211475039
Latest Posts
Article information

Author: Annamae Dooley

Last Updated:

Views: 6717

Rating: 4.4 / 5 (45 voted)

Reviews: 92% of readers found this page helpful

Author information

Name: Annamae Dooley

Birthday: 2001-07-26

Address: 9687 Tambra Meadow, Bradleyhaven, TN 53219

Phone: +9316045904039

Job: Future Coordinator

Hobby: Archery, Couponing, Poi, Kite flying, Knitting, Rappelling, Baseball

Introduction: My name is Annamae Dooley, I am a witty, quaint, lovely, clever, rich, sparkling, powerful person who loves writing and wants to share my knowledge and understanding with you.