Where to Put SSH Server?
DComTalk.com Forum Index DComTalk.com
Discussion of VoIP, VPN, Video Conferencen, DSL and other data commucations.
 
 FAQFAQ   MemberlistMemberlist     RegisterRegister 
 ProfileProfile   Log in to check your private messagesLog in to check your private messages   Log inLog in 
 
Google
 
Web dcomtalk.com
Where to Put SSH Server?

 
Post new topic   Reply to topic    DComTalk.com Forum Index -> Firewalls
Author Message
Guest






Posted: Fri Dec 16, 2005 7:13 am    Post subject: Where to Put SSH Server? Reply with quote

I'm setting up a network with a private network and a DMZ. I want to be
able to access machines in the private network via SSH from the
Internet. Should I put the SSH server on a machine on the private
network or on a machine in the DMZ?

I'm thinking the DMZ because then I'll need to SSH from there to the
private network and so will any attacker and breaking two SSH links is
more difficult than breaking only one if I SSH directly into the
private network from the Internet.

Is my reasoning sound, or should I put the Internet-visible SSH server
on the private network?
Back to top
Volker Birk
Guest





Posted: Fri Dec 16, 2005 9:23 am    Post subject: Re: Where to Put SSH Server? Reply with quote

Quote:
I'm setting up a network with a private network and a DMZ. I want to be
able to access machines in the private network via SSH from the
Internet. Should I put the SSH server on a machine on the private
network or on a machine in the DMZ?

You could SSH the firewall implementation between DMZ and private zone,
and from there into the private zone. Usually, you should control, from
where those ssh requests come, too.

Quote:
I'm thinking the DMZ because then I'll need to SSH from there to the
private network and so will any attacker and breaking two SSH links is
more difficult than breaking only one if I SSH directly into the
private network from the Internet.

Yes. Especially, if you're only using PSK, i.e. DSA, and your both
SSH implementations are different programs, so an exploit in one of
them does not lead to making your private network unsecure.

Yours,
VB.
--
"Ich bin ein freier Mensch und werde jetzt von meinen Freiheitsrechten
Gebrauch machen - und zwar ausgiebig - natürlich nur in dem Rahmen, den
Otto Schily mir noch zur Verfügung stellt."
Wolfgang Clement am 10.10.05 als Noch-Superminister
Back to top
 
Post new topic   Reply to topic    DComTalk.com Forum Index -> Firewalls All times are GMT
Page 1 of 1

 
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum




VoIP Solutions: Telephone Systems Electronics Satellite TV Tech & Gadgets
Powered by phpBB