Re: My home ISP blocking ssh protocol

Christopher Schultz <[email protected]> Thu, 12 Dec 2019 11:43:25 -0500
Newsgroups gmane.network.stunnel.user
Message-ID <[email protected]>
This is an OpenPGP/MIME signed message (RFC 4880 and 3156)
--===============7366661787259635572==
Content-Type: multipart/signed; micalg=pgp-sha256;
 protocol="application/pgp-signature";
 boundary="p1PzbPEEpwV8gxYCUpJPCLYSpC509VtyA"

This is an OpenPGP/MIME signed message (RFC 4880 and 3156)
--p1PzbPEEpwV8gxYCUpJPCLYSpC509VtyA
Content-Type: multipart/mixed; boundary="CZvk4HeAbOQoyU1UqpLj64gdDGLHWlH62";
 protected-headers="v1"
From: Christopher Schultz <[email protected]>
To: [email protected]
Message-ID: <[email protected]>
Subject: Re: [stunnel-users] My home ISP blocking ssh protocol
References: <CADn9Oo2-CvAUAqojP2=nNsOQyZ85NhRpr52hPoKg42fSMF1wRA@mail.gmail.com>
 <[email protected]>
 <CADn9Oo2fwGdnQPyhG9VV-_M_4zAi1ifvdzszgBvuLKpyMKOxag@mail.gmail.com>
In-Reply-To: <CADn9Oo2fwGdnQPyhG9VV-_M_4zAi1ifvdzszgBvuLKpyMKOxag@mail.gmail.com>

--CZvk4HeAbOQoyU1UqpLj64gdDGLHWlH62
Content-Type: text/plain; charset=utf-8
Content-Language: en-US
Content-Transfer-Encoding: quoted-printable

Matt,

On 12/12/19 11:01, Matt Thomas wrote:
> Server is 192.168.0.10
> Router is 192.168.0.1
>=20
> It works fine internally:)=20
>=20
> I add a port forward in the router for port 22 pointed at .0.10. Router=
s
> firewall all ready is configured to accept ssh on port 22 from any any.=
=20
>=20
> When ever anyone attempts to connect to the server, a pop up shows on m=
y
> screen. When i try to have my friends or co-workers try from there hous=
e
> or i try from public place, no pop up or hits on the server log. Just
> times out.=20
>=20
> But if i put minecraft on port 22, it works. So certain traffic is
> making it through. Even hamachi vpn works fine BUT i cant install that
> on public PC's haha

I was about to say "this is clearly an issue with the port number, pick
something other than 22" but if you say you can run Minecraft over port
22, then that's ... strange.

I wasn't aware that Minecraft servers could have their ports changed
like that. You can really set up your Minecraft server to listen on
localhost:22 and it doesn't use UPnP or anything like that to
reconfigure your firewall/router?

My advice is to try configuring things like this:

Router: 192.168.0.1
Forward WAN connections to port e.g. 1022 -> 192.168.0.10:1022

Server: 192.68.0.1
Accept stunnel connections on port 1022
accept=3D:1022
connect=3Dlocalhost:22

If that works, I might even try just changing the port number of your
ssh/sftp service from the "standard" port to something else and trying
again without stunnel in the mix.

I've never encountered an ISP which does deep packet inspection to block
services. They usually just block ports.

-chris

> On Thu, Dec 12, 2019, 7:58 AM Christopher Schultz
> <[email protected] <mailto:[email protected]>> wr=
ote:
>=20
>     Matt,
>=20
>     On 12/11/19 17:53, Matt Thomas wrote:
>     > I need to know if Stunnel is going to accomplish what i need to d=
o. My
>     > home ISP blocks protocol HTTP and SSH from coming in so that
>     people cant
>     > run their own website from home without paying the ISP for a
>     "Business" line
>     >
>     > All i am trying to do is have a SFTP server that i can access my =
dang
>     > files from while i am at school, work, friends house, library or
>     > wherever. I have tried ssh on multiple random ports and made sure=
 all
>     > firewall rules and port forward rules were correct in my home
>     router. I
>     > know they work because i even went as far as setting up a minecra=
ft
>     > server to just test the port forward rules out and sure enough, m=
y
>     > friend 200 miles away can connect just fine to my home minecraft
>     > server.. But he can not connect to the ssh server. No logs are ev=
er
>     > created on the server either because something is stoping the pac=
ket
>     > from even hitting my router, that something is my ISP
>     >
>     > Would stunnel allow me to make ssh traffic look like regular http=
s
>     > traffic, thus allowing me to connect to my server at home so i ca=
n
>     do my
>     > homework??
>=20
>     Those other servers probably use TLS or plaintext connections. stun=
nel
>     uses TLS, but ssh/sftp use a slightly different protocol that may
>     possibly be distinguishable by a determined ISP.
>=20
>     I would think that using stunnel to tunnel SFTP/SSH would be possib=
le,
>     though not strictly necessary. I suspect some other problem is
>     preventing you from succeeding.
>=20
>     Can you be more specific about exactly what you did for configurati=
on?
>     Port numbers, specific things you did, etc? You don't have to discl=
ose
>     your public IP address, but perhaps give the local IPs of your rout=
er
>     and home server, etc?
>=20
>     -chris
>=20
>     _______________________________________________
>     stunnel-users mailing list
>     [email protected] <mailto:[email protected]>
>     https://www.stunnel.org/cgi-bin/mailman/listinfo/stunnel-users
>=20


--CZvk4HeAbOQoyU1UqpLj64gdDGLHWlH62--

--p1PzbPEEpwV8gxYCUpJPCLYSpC509VtyA
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: OpenPGP digital signature
Content-Disposition: attachment; filename="signature.asc"

-----BEGIN PGP SIGNATURE-----
Comment: Using GnuPG with Thunderbird - https://www.enigmail.net/

iQIzBAEBCAAdFiEEMmKgYcQvxMe7tcJcHPApP6U8pFgFAl3ybi0ACgkQHPApP6U8
pFjaaRAAh0XWaA84zVU36QYOmDGBcTdNbUZtKKVLLinc/M22H6WonuLv3OLh9Dlg
qEXDA7/AJXoiVCsQwtpbCs0OUGdlHh1/ZCfMNSLCRm4v8hLTQaE/29o2lEYIAAL/
YTIaeyGV151mVGM53IBYkmaLkBhoq3z2aDk5ikr1GdcB8PmaCQtYXtS6+S3+JqK/
pwh32MHcD/7nLOlhXDVwWDSYlaVNFO+epUAv+HciAdHZMjIin79m9jhrd7FrfIc6
tU983cunAJ+Lweo1D281bml7bjAF+KvKnaiQszXaGzesm0RzKI7N6YsDDTbJcbhh
M0bHq8x/zonCphko0+oI9UrLNnmBarg/Vf+jF3hD1eqVPWU1ExW5av5OCDPhNO/i
wxpZuBZ709PxicIteZ1Cn6a8iUReSRpnhFfex2JIXOG3DmoHjj0qfr8vckTzQ0+w
HPWYzqAxgany+zq0obn4W+gtoGmcyl/JLYN966kF1Hidt6blu3+3ZHQgnL3Rblm+
CUDQ8uwr0Tw5DmLfpYNDw7kE4sq0JglHjchJAuCJ6dkkgXyQNNMcJxMO74PiKlBK
K/9H7OKNSCNefFe4CPW1b2GYK3hJMcCjwfcbyus7tJjsYrGaBOiiL415TC57yjFA
Q968JfOL0Y/mxrxvKGXG8FZ6VeF4pZ4GMoF4MKCTTnwaR8muRFw=
=DW+t
-----END PGP SIGNATURE-----

--p1PzbPEEpwV8gxYCUpJPCLYSpC509VtyA--

--===============7366661787259635572==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________
stunnel-users mailing list
[email protected]
https://www.stunnel.org/cgi-bin/mailman/listinfo/stunnel-users

--===============7366661787259635572==--