Technical Discussion
  >> Home Networking, Internet Connection Sharing, etc.


Register (or login) on our website and you will not see this ad.


These posts have been archived and can no longer be replied to or modified.
  Print Thread
Standard User ambaqua
(newbie) Wed 24-Nov-10 16:12:17
Print Post

Firewalling remote SSH access


[link to this post]
 
Hi all,

This is a question about firewalling on an O2 router, not really about mac issues, but the background includes information about the mac stuff to motivate why I want to configure the router in this way.

so...

I have a mac at home that I often access using SSH from my work or my parents' house. To do this, I have opened up port 22 on my O2 Wireless Box II. So far so good.

I also have a Time Capsule and Snow Leopard running on the mac. These two together mean I can have the mac be asleep most of the time, and will only wake up automatically when an SSH request comes in.

However, my mac has become an iMac, well - an insomniac Mac! It never sleeps, and if I do put it to sleep, it just wakes up again almost immediately. If I turn off the port forwarding on the router, the mac will sleep soundly.

So, I wondered what was coming in to keep it awake and ran WireShark overnight one night. I can see that I am recieving hundreds of access attempts over SSH, trying to get into the mac. They don't succeed, but simply by trying they are keeping my mac awake and so running up my electricity bill by quite a lot.

I tried changing the incoming port to a different port to port 22. However, my work only allows ssh outgoing over port 22 through their firewall, so ruining most of the point of having an ssh server at home at all! Furthermore, after about a week of using the different port, the access requests started again.

On an old netgear router I had, you could restrict port forwarding to certain WAN IP addresses. This means I could whitelist my work and parents' IPs, and block everyone else from ssh-ing in. I tried this, and it worked successfully. However, my old netgear only syncs at about 4Mb/s, whereas my O2 box syncs at about 12Mb/s. So I would much, much rather use my O2 box!
I would like to know how to restrict access to open ports to certain WAN IPs on my O2 Wireless Box II (rebranded Thomson Speedtouch 585v7).
I am quite at ease with the CLI if that is required to configure the firewall!

thanks in advance!!
Standard User deleted
(deleted) Fri 26-Nov-10 15:06:21
Print Post

Re: Firewalling remote SSH access


[re: ambaqua] [link to this post]
 
Can't help. Might be worth looking through http://www.thomsonbroadbandpartner.com/getfile.php?i...
Standard User deleted
(deleted) Wed 01-Dec-10 16:53:56
Print Post

Re: Firewalling remote SSH access


[re: ambaqua] [link to this post]
 
Google for: apple 'mac os x' firewalling

(or something similar)

There will be away to firewall the MAC itself, allowing you to still use the o2 router. I can't give you any more information than that as my background in terms of *nix based systems is Linux (which uses iptables) - I think MAC uses ipfw instead.

Maybe someone more knowledgeable on MAC firewalling can help you out with that.


Register (or login) on our website and you will not see this ad.

Standard User deleted
(deleted) Wed 01-Dec-10 18:34:25
Print Post

Re: Firewalling remote SSH access


[re: ambaqua] [link to this post]
 
Hmm tricky... because putting the firewall at the MAC end will still mean the box wakes up.

Looks like it's either buy an enterprise firewall to go between your MAC and Router (which will probably make more noise than your MAC lol) or buy a new router which supports ADSL 2 and more advance Firewall policies.

Grab a new Wireless N Netgear or something.

Either way you should'nt really be port forwarding. VPN always smile
  Print Thread

Jump to