You are not logged in. Login Now
 0-24   25-49   50-74   75-99   100-124   125-149   150-174   175-199   194-218 
 219-223          
 
Author Message
5 new of 223 responses total.
tonster
response 219 of 223: Mark Unseen   Nov 16 19:04 UTC 2020

My guess is that it might have to do with the method now used for
accessing Grex. I recently canceled my AT&T service, which allowed me to
have static IP's at home. With that now gone, I've established a VPN
between my servers in Azure and home, and am routing grex (and m-net)
via static IP's I've got in Azure and home over that VPN tunnel. Exactly
why this is working without incident for some ssh clients and not others
I'm unsure, but that is the change that was made in the past week when
this started.
tod
response 220 of 223: Mark Unseen   Nov 18 02:18 UTC 2020

re #219
This is excellent - curious how that is setup.
I have a nat behind a nat at my office and want the pi there available
for sshd from home and elsewhere.  Not sure how to go about it.
tonster
response 221 of 223: Mark Unseen   Dec 5 22:10 UTC 2020

resp:220: What I did was created a vm at home to route the tunnel, and
established a strongswan tunnel between the two sites. I then created an
iptables rule to create a route to my network via the tunnel:

-A POSTROUTING -s 10.0.0.0/24 -d 192.168.0.0/20 -j MASQUERADE

and the opposite on the other end of the tunnel:

-A POSTROUTING -s 192.168.0.0/20 -d 10.0.0.0/24  -j MASQUERADE

For the Azure side, I also route the additional bound IP's over the
tunnel back home via:

-A PREROUTING -d 10.0.0.9/32 -j DNAT --to-destination 192.168.0.110
-A POSTROUTING -d 192.168.0.110/32 -j SNAT --to-source 10.0.0.9

strongswan starts on boot, and I've put the iptables rules in the
appropriate file for the OS (ubuntu/centos), so everything comes up on
boot and strongswan monitors the tunnel so it automatically restarts
should it drop. It ended up working out quite well, and it was much
easier to get it running than I'd expected.
tod
response 222 of 223: Mark Unseen   Dec 12 05:40 UTC 2020

re #221
Very tidy, indeed.  Thanks for the rundown!
kentn
response 223 of 223: Mark Unseen   Feb 21 16:19 UTC 2023

The machine grex is running on had more disk space added yesterday. That
took it offline and made it appear the SSH security info had changed.
It's back up now and everything should be back the way it was before the
changes.  Thanks go to Tony for keeping grex going.
 0-24   25-49   50-74   75-99   100-124   125-149   150-174   175-199   194-218 
 219-223          
Response Not Possible: You are Not Logged In
 

- Backtalk version 1.3.30 - Copyright 1996-2006, Jan Wolter and Steve Weiss