12.07.2015 Views

Red Hat Enterprise Linux 5 Administration Unleashed

Red Hat Enterprise Linux 5 Administration Unleashed

Red Hat Enterprise Linux 5 Administration Unleashed

SHOW MORE
SHOW LESS
  • No tags were found...

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

366CHAPTER 17Securing Remote Logins with OpenSSHThe destination host allows connections from the SSH server through the firewall, but thefirewall does not allow connections from the source host. So, an encrypted SSH tunnel isestablished between the source host and the SSH server. Then, packets intended for thedestination host are sent over the encrypted tunnel to the SSH server and then forwardedto the destination host on the other side of the firewall. The connection between the SSHserver and the destination host is not necessarily encrypted because ‘an SSH tunnel hasnot been established between them. However, the connection can be secured with additionalsoftware such as a VPN solution. If the destination host is another SSH server, theconnection between the connecting SSH server and the destination host is encryptedbecause of the SSH connection.TIPTo disable port forwarding on an OpenSSH server, add the following line to/etc/ssh/sshd_config:AllowTcpForwarding noLogging ConnectionsBy default, the OpenSSH daemon (sshd) uses syslog to write messages to /var/log/messages when sessions are opened and closed for users as well as when an authenticationattempt has failed.To modify the type of messages logged, set the LogLevel directive in the /etc/ssh/sshd_config file. By default, it is set to INFO. The possible values in order of verbosity areQUIET, FATAL, ERROR, INFO, VERBOSE, DEBUG, DEBUG1, DEBUG2, and DEBUG3. DEBUG and DEBUG1are the same. Logging with any of the DEBUG levels violates user privacy and is not recommended.SummaryWhen administering UNIX-based systems such as those running <strong>Red</strong> <strong>Hat</strong> <strong>Enterprise</strong><strong>Linux</strong>, SSH tools such as the OpenSSH suite are essential. It can help you perform avariety of tasks such as logging in to a system to monitor system performance, remotelyrunning graphical configuration tools, applying system updates, or even checking email.It can also allow you to display a graphical application remotely with X11 forwarding andredirect requests to a different server using port forwarding.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!