3 ms·
I am not sure to understand what this is this achieving compared to just assigning a ip + port per vm?
by Eikon 7mo ago
I am not sure to understand what this is this achieving compared to just assigning a ip + port per vm?
- otterley 7mo agoNot needing a different port. Middleboxes sometimes block ssh on nonstandard ports. Also, to preserve the alignment between the SSH hostname and the web service hostname, as though the user was accessing a single host at a single public address. Usability is key for them.
- Charon77 7mo agoThey don't want each vm to have different public IP
- deleted 7mo ago[deleted]
- gsich 7mo agoMiddleboxes are not relevant in this scenario.
- otterley 7mo agoUh, why not? Unless your SSH client is on the same network as theirs, there are going to be middleboxes somewhere in the path.
- gsich 7mo agoBecause your ISP should (and most do not) alter traffic.
- otterley 7mo agoBut you’re not considering the many business environments that do.
- gsich 7mo agoI don't because that would be impossible. Every business has different rules. But if you (as a business) want to to use this, you will find a way to make the changes to those "middleboxes". It's not your network, it's your business's network.
- otterley 7mo agoLarge multi-national corporations, by way of their sheer size, tend to force their vendors to bend towards their needs, not to adapt to meet their vendors' unusual networking requirements.
- gsich 7mo agoThankfully SSH on non-22 is not unusual.
- otterley 7mo agoOf all the SSH servers in the world, what percentage are listening on a port other than 22? To answer this question, you can visit https://data-status.shodan.io/ports.html https://data-status.shodan.io/ports.html and see for yourself. By "unusual," I literally mean "not usual/not typical." Not "never happens."
- gsich 7mo agoI fail to see how this is relevant.
- otterley 7mo agoI'll explain it once again, then leave this thread: Companies frequently put egress network policies in place that confine certain protocols like SSH and HTTP to certain ports. They do this in order to achieve compliance with regulations, to achieve security or operational certifications, or simply because they're paranoid. It's not necessarily the least restrictive means of accomplishing their goals, but that's what they do. And if they're big enough, they're going to use the size of the deal and their brand equity to persuade their vendors, who might ordinarily prefer to offer a service on a nonstandard port, to provide it on the customer's preferred port instead. If you still don't understand, I'm sorry, but I cannot assist further.
- Dylan16807 7mo agoWhy would anyone configure it to do that? Like, I understand the really restrictive ones that only allow web browsing. But why allow outgoing ssh to port 22 but not other ports? Especially when port 22 is arguably the least secure option. At that point let people connect to any port except for a small blacklist.
- otterley 7mo agoI’m not a network security expert, so I don’t know the threat model. I just know that this is a thing companies do sometimes.
- josephcsible 7mo agoMiddlebox operators aren't known for making reasonable or logical decisions.
- 9dev 7mo agoAsking back, when I limit the outgoing connections from a network, why would I account for any nonstandard port and make the ruleset unwieldy, just in case someone wanted to do something clever?
- Dylan16807 7mo agoA simple ruleset would only block a couple dangerous ports and leave everything else connectable. Whitelisting outgoing destination ports is more complicated and more annoying to deal with for no benefit. The only place you should be whitelisting destination ports is when you're looking at incoming connections.
- 9dev 7mo agoI definitely block outgoing ports on all our servers by default; Established connections, HTTP(S), DNS, NTP, plus infra-specific rules. There is really no legitimate reason to connect to anything else. The benefit is defence against exfiltration.
- CGamesPlay 7mo agoUsing nonstandard ports would break the `ssh foo.exe.dev` pattern. This could also have been solved by requiring users to customize their SSH config (coder does this once per machine, and it applies to all workspaces), but I guess the exe.dev guys are going for a "zero-config, works anywhere" experience.
- w-ll 7mo ago-p ?
- deleted 7mo ago[deleted]
- hrmtst93837 7mo ago[flagged]
- CGamesPlay 7mo agoSSH configs support wildcards, so if you couple it with a ProxyCommand you can an arbitrary level of dynamism for a host pattern (like *.exe.dev). But yeah, everything is a trade-off.
- KomoD 7mo agoToo bad most SSH clients don't seem to support SRV records, they would've been perfect for this: ;; Domain: mydomain.com. ;; SSH running on port 2999 at host 1.2.3.4 ;; A Record vm1928.mydomain.com. 1 IN A 1.2.3.4 ;; SRV Record _ssh._tcp.vm1928.mydomain.com. 1 IN SRV 0 0 2999 vm1928.mydomain.com. If supported it would result in just being able to do "ssh vm1928.mydomain.com" without having to add "-p 1928"