Enabling Port Forwarding Over SSH When It's "administratively Prohibited"
Posted3 months agoActive3 months ago
blog.computers.picturesTechstory
calmpositive
Debate
20/100
SSHNetworkingSecurity
Key topics
SSH
Networking
Security
The post describes a technique to enable port forwarding over SSH even when it's administratively prohibited, and the discussion revolves around the usefulness and potential security implications of this technique.
Snapshot generated from the HN discussion
Discussion Activity
Light discussionFirst comment
17m
Peak period
2
0-2h
Avg / period
1.3
Key moments
- 01Story posted
Oct 15, 2025 at 12:43 PM EDT
3 months ago
Step 01 - 02First comment
Oct 15, 2025 at 1:00 PM EDT
17m after posting
Step 02 - 03Peak activity
2 comments in 0-2h
Hottest window of the conversation
Step 03 - 04Latest activity
Oct 16, 2025 at 7:36 AM EDT
3 months ago
Step 04
Generating AI Summary...
Analyzing up to 500 comments to identify key contributors and discussion patterns
ID: 45595212Type: storyLast synced: 11/17/2025, 10:08:07 AM
Want the full context?
Jump to the original sources
Read the primary article or dive into the live Hacker News thread when you're ready.
Hardening in sshd_config to prevent arbitrary network access behind the firewall where the firewall would otherwise not permit. If one can get around this then the host itself may be missing proper outbound owner-based firewall rules varies by compliance requirements.
Another option to read up on is "Match" which can modify options for specific users, groups, networks or ports. For example we can disable port forwarding for Bob and enable port forwarding for Alice.
To further limit what that host can talk to one can use the Netfilter "owner" module to limit outbound connections by user or group. So for example only the LDAP user can talk to the LDAP server.
Each org may have different audit and regulatory requirements that determine which if any of these options are utilized. Development orgs and small startups rarely use any of them due to perception of friction.[1] - https://man7.org/linux/man-pages/man5/sshd_config.5.html