From owner-freebsd-questions@FreeBSD.ORG Mon Oct 27 17:04:48 2008 Return-Path: Delivered-To: freebsd-questions@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:4f8:fff6::34]) by hub.freebsd.org (Postfix) with ESMTP id 970591065674 for ; Mon, 27 Oct 2008 17:04:48 +0000 (UTC) (envelope-from kadmin@ezekiel.daleco.biz) Received: from ezekiel.daleco.biz (southernuniform.com [66.76.92.18]) by mx1.freebsd.org (Postfix) with ESMTP id 380EB8FC1F for ; Mon, 27 Oct 2008 17:04:47 +0000 (UTC) (envelope-from kadmin@ezekiel.daleco.biz) Received: from ezekiel.daleco.biz (localhost [127.0.0.1]) by ezekiel.daleco.biz (8.14.2/8.14.2) with ESMTP id m9RH4k8W001089; Mon, 27 Oct 2008 12:04:46 -0500 (CDT) (envelope-from kadmin@ezekiel.daleco.biz) Received: (from kadmin@localhost) by ezekiel.daleco.biz (8.14.2/8.13.1/Submit) id m9RH4kdJ001088; Mon, 27 Oct 2008 12:04:46 -0500 (CDT) (envelope-from kadmin) Date: Mon, 27 Oct 2008 12:04:46 -0500 From: Kevin Kinsey To: freebsd-questions@freebsd.org Message-ID: <20081027170446.GA946@ezekiel.daleco.biz> Mime-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline User-Agent: Mutt/1.4.2.3i Cc: daleco@daleco.biz Subject: SSH Port forwarding when "PermitRootLogin"==no ? X-BeenThere: freebsd-questions@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: User questions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Mon, 27 Oct 2008 17:04:48 -0000 Hello, I'm (still) trying to work around a limitation I've encountered with a new service provider (cf. "MTA on non-standard port"). As root: # ssh -L 24:server:52525 server fails because root logins aren't permitted in /etc/sshd_config on the server. Also as root: # ssh -L 24:server:52525 user@server fails - an terminal session is established, but when I telnet localhost:24 I receive this in the terminal: channel 3: open failed: administratively prohibited: open failed I was kinda under the impression this should work, since the port on the remote server is a dynamic port. Any suggestions how I might get this to work? TIA, Kevin Kinsey