83
Chapter 6: Secure SSH Tunneling & SDT Connector
6.1 Configuring for SDT Tunneling to Hosts
TosetuptheConsoleServertoSDTaccessanetworkattachedhost,thehost and the permitted services that are to be used
inaccessingthathostneedtobeconguredonthegateway,andUseraccessprivilegesneedtobespecied:
• Addthenewhost and the permitted services using the Serial & Network: Network Hosts menu as detailed in Network
Hosts(Chapter 4.4).Onlythesepermitted serviceswillbeforwardedbySDTtothehost.Allotherservices(TCP/UDPports)
will be blocked.
Note: Following are some of the TCP Ports used by SDT in the Console Server:
22 SSH (All SDT Tunneled connections)
23 Telnet on local LAN (forwarded inside tunnel)
80 HTTP on local LAN (forwarded inside tunnel)
3389 RDP on local LAN (forwarded inside tunnel)
5900 VNC on local LAN (forwarded inside tunnel)
73XX RDP over serial from local LAN – where XX is the serial port number (i.e. 7301to 7348)
79XX VNC over serial from local LAN – where XX is the serial port number
• AddthenewUsers using Serial & Network: Users & Groups menu as detailed in Network Hosts(Chapter 4.4).Users
canbeauthorizedtoaccesstheConsoleServerportsandspeciednetwork-attachedhosts.Tosimplifyconguration,
the Administrator can first set up Groupswithgroupaccesspermissions,thenUserscanbeclassiedasmembersof
particular Groups.