<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Need help with security issue in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/need-help-with-security-issue/m-p/1414042#M742717</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You can auth proxy one ip address only going to one port if you want.&lt;/P&gt;&lt;P&gt;Wouldn't that solve the problem?&lt;/P&gt;&lt;P&gt;If not there has to be something in the middle that will inspect authenticate the application, I don't see any other way.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PK&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 03 Mar 2010 17:03:42 GMT</pubDate>
    <dc:creator>Panos Kampanakis</dc:creator>
    <dc:date>2010-03-03T17:03:42Z</dc:date>
    <item>
      <title>Need help with security issue</title>
      <link>https://community.cisco.com/t5/network-security/need-help-with-security-issue/m-p/1414039#M742620</link>
      <description>&lt;P&gt;I have a security incident were someone is using putty to get around our internet filter.&amp;nbsp; What they are doing is tunneling through on port 8080 and 443 to an outside server that acts as a proxy.&amp;nbsp; I can't block port 8080 or 443 for this group of users becuase they still need to get to the internet.&amp;nbsp; I can't block the public IP addess that they are tunneling to becuase they will just change the address. Does anyone have any ideas that may help me.&amp;nbsp; Thanks for any help you might provide.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jason&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 17:17:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/need-help-with-security-issue/m-p/1414039#M742620</guid>
      <dc:creator>jason-calbert_2</dc:creator>
      <dc:date>2019-03-11T17:17:13Z</dc:date>
    </item>
    <item>
      <title>Re: Need help with security issue</title>
      <link>https://community.cisco.com/t5/network-security/need-help-with-security-issue/m-p/1414040#M742644</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Interesting issue:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What you can do is use auth-proxy to authenticate that user. As soon as he authenticates he will allowed to open that port. If it is one ip address that does it then I believe it is fine. The authenticated user will not need to reauthenticate until the authentication expires.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope it helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PK&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 03 Mar 2010 16:15:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/need-help-with-security-issue/m-p/1414040#M742644</guid>
      <dc:creator>Panos Kampanakis</dc:creator>
      <dc:date>2010-03-03T16:15:54Z</dc:date>
    </item>
    <item>
      <title>Re: Need help with security issue</title>
      <link>https://community.cisco.com/t5/network-security/need-help-with-security-issue/m-p/1414041#M742680</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I don't think that will be an option for us to authenticate as there are over 65,000 of these types of users who we would not be able to force them to authenticate.&amp;nbsp; Below is an internet site that discusses how to use this method to get around a firewall/internet filter.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;DIV align="center"&gt;&lt;TABLE border="0" cellpadding="0" cellspacing="0" class="MsoNormalTable" style="width: 570pt; mso-cellspacing: 0in; mso-yfti-tbllook: 1184; mso-padding-alt: 0in 0in 0in 0in;" width="760"&gt;&lt;TBODY&gt;&lt;TR style="height: 0.25in; mso-yfti-irow: 0; mso-yfti-firstrow: yes;"&gt;&lt;TD style="background-color: transparent; height: 0.25in; border: #000000; padding: 0in;"&gt;&lt;P class="MsoNormal" style="line-height: normal; margin: 0in 0in 0pt;"&gt;&lt;A name="prereqs"&gt;&lt;/A&gt;&lt;STRONG style=": ; Courier New&amp;quot;: ; color: black; font-size: 10pt; font-family: &amp;quot; mso-fareast-font-family: 'Times New Roman'; "&gt;Prerequisites&lt;/STRONG&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR style="mso-yfti-irow: 1;"&gt;&lt;TD style="background-color: transparent; border: #000000; padding: 0in;"&gt;&lt;P class="MsoNormal" style="line-height: normal; margin: 0in 0in 0pt;"&gt;&lt;SPAN style="font-family: &amp;quot;Courier New&amp;quot;; color: black; font-size: 10pt; mso-fareast-font-family: 'Times New Roman';"&gt;To use this method, you need the following; &lt;/SPAN&gt;&lt;/P&gt;&lt;UL type="disc"&gt;&lt;LI class="MsoNormal" style="line-height: normal; margin: 0in 0in 10pt; color: black; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-list: l4 level1 lfo1; tab-stops: list .5in;"&gt;&lt;SPAN style="font-family: &amp;quot;Courier New&amp;quot;; font-size: 10pt; mso-fareast-font-family: 'Times New Roman';"&gt;A decent computer at home that you can leave connected to the Internet all day while you're at work. &lt;/SPAN&gt;&lt;/LI&gt;&lt;LI class="MsoNormal" style="line-height: normal; margin: 0in 0in 10pt; color: black; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-list: l4 level1 lfo1; tab-stops: list .5in;"&gt;&lt;SPAN style="font-family: &amp;quot;Courier New&amp;quot;; font-size: 10pt; mso-fareast-font-family: 'Times New Roman';"&gt;A fast Internet connection at home; usually cable or DSL. (Technically, this can work with a dialup modem connection, but it may cause problems and it's really slow.) &lt;/SPAN&gt;&lt;/LI&gt;&lt;LI class="MsoNormal" style="line-height: normal; margin: 0in 0in 10pt; color: black; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-list: l4 level1 lfo1; tab-stops: list .5in;"&gt;&lt;SPAN style="font-family: &amp;quot;Courier New&amp;quot;; font-size: 10pt; mso-fareast-font-family: 'Times New Roman';"&gt;Microsoft Windows NT, 2000, or XP installed on your computer at home and any flavor of Windows on your computer at work. You may be able to get this to work with 95, 98, or ME, but I can't say for sure. You definitely can get this to work with Linux or Unix. I don't know about Macintosh. &lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P class="MsoNormal" style="line-height: normal; margin: 0in 0in 12pt;"&gt;&lt;SPAN style="font-family: &amp;quot;Courier New&amp;quot;; color: black; font-size: 10pt; mso-fareast-font-family: 'Times New Roman';"&gt;Alternatively, if you don't meet the prereqs or don't want to leave your computer on all day, you can try &lt;A href="http://www.http-tunnelclient.com/"&gt;&lt;SPAN style="color: blue; mso-bidi-font-size: 11.0pt;"&gt;HTTP-Tunnel&lt;/SPAN&gt;&lt;/A&gt;, a commerical alternative that lets you do everything here and more. &lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR style="mso-yfti-irow: 2;"&gt;&lt;TD style="background-color: transparent; border: #000000; padding: 0in;"&gt;&lt;P class="MsoNormal" style="line-height: normal; margin: 0in 0in 0pt;"&gt;&lt;A name="wont_work"&gt;&lt;/A&gt;&lt;STRONG style=": ; Courier New&amp;quot;: ; color: black; font-size: 10pt; font-family: &amp;quot; mso-fareast-font-family: 'Times New Roman'; "&gt;When won't this work?&lt;/STRONG&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR style="mso-yfti-irow: 3;"&gt;&lt;TD style="background-color: transparent; border: #000000; padding: 0in;"&gt;&lt;P class="MsoNormal" style="line-height: normal; margin: 0in 0in 0pt;"&gt;&lt;SPAN style="font-family: &amp;quot;Courier New&amp;quot;; color: black; font-size: 10pt; mso-fareast-font-family: 'Times New Roman';"&gt;Please notice the title of this page starts "How To Bypass &lt;EM&gt;Most&lt;/EM&gt; Firewall Restrictions... I say most because the method I describe here will not work for everyone, even if you meet the pre-requisites above. If any of the following are true for you, you probably can't use this method successfully; &lt;/SPAN&gt;&lt;/P&gt;&lt;UL type="disc"&gt;&lt;LI class="MsoNormal" style="line-height: normal; margin: 0in 0in 10pt; color: black; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-list: l0 level1 lfo2; tab-stops: list .5in;"&gt;&lt;SPAN style="font-family: &amp;quot;Courier New&amp;quot;; font-size: 10pt; mso-fareast-font-family: 'Times New Roman';"&gt;You can not access any external Internet websites; only internal websites or none at all. &lt;/SPAN&gt;&lt;/LI&gt;&lt;LI class="MsoNormal" style="line-height: normal; margin: 0in 0in 10pt; color: black; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-list: l0 level1 lfo2; tab-stops: list .5in;"&gt;&lt;SPAN style="font-family: &amp;quot;Courier New&amp;quot;; font-size: 10pt; mso-fareast-font-family: 'Times New Roman';"&gt;You can access a few specific Internet websites, but no others at all. &lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P class="MsoNormal" style="line-height: normal; margin: 0in 0in 12pt;"&gt;&lt;SPAN style="font-family: &amp;quot;Courier New&amp;quot;; color: black; font-size: 10pt; mso-fareast-font-family: 'Times New Roman';"&gt;If either of the 2 lines above apply to you, your network administrator is working hard because they are using a "pessimistic" blocking strategy. In other words, they have decided to block &lt;EM&gt;everything&lt;/EM&gt;, and probably only allow specific access. The problem with that strategy however, is that it requires much more work and maintenance than using an "optimistic" strategy, in which they allow access to everything and block only certain "things". &lt;BR /&gt;&lt;BR /&gt;The method I describe on this page will not work with a pessimistic blocking strategy because it depends on being able to access your home computer from work. 9 times of 10, if you can't get to &lt;A href="https://community.cisco.com/www.amazon.com" target="_blank"&gt;www.amazon.com&lt;/A&gt;, you won't be able to your home computer either. If for some reason you CAN access your home computer, then great.. proceed If not, you may want to talk to your network administrator. Ask him if they would punch a hole in the firewall so you can SSH to your computer at home. Or come up with some excuse to get access to 1 port on your home computer, then run the SSH server on that port. &lt;BR /&gt;&lt;BR /&gt;Or... maybe you ARE the network administrator and are just curious about how this works. &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR style="mso-yfti-irow: 4;"&gt;&lt;TD style="background-color: transparent; border: #000000; padding: 0in;"&gt;&lt;P class="MsoNormal" style="line-height: normal; margin: 0in 0in 0pt;"&gt;&lt;A name="addresses"&gt;&lt;/A&gt;&lt;STRONG style=": ; Courier New&amp;quot;: ; color: black; font-size: 10pt; font-family: &amp;quot; mso-fareast-font-family: 'Times New Roman'; "&gt;Addresses&lt;/STRONG&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR style="mso-yfti-irow: 5;"&gt;&lt;TD style="background-color: transparent; border: #000000; padding: 0in;"&gt;&lt;P class="MsoNormal" style="line-height: normal; margin: 0in 0in 0pt;"&gt;&lt;SPAN style="font-family: &amp;quot;Courier New&amp;quot;; color: black; font-size: 10pt; mso-fareast-font-family: 'Times New Roman';"&gt;Before we start installing and configuring software, you need to find out the following things; &lt;/SPAN&gt;&lt;/P&gt;&lt;UL type="disc"&gt;&lt;LI class="MsoNormal" style="line-height: normal; margin: 0in 0in 10pt; color: black; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-list: l1 level1 lfo3; tab-stops: list .5in;"&gt;&lt;SPAN style="font-family: &amp;quot;Courier New&amp;quot;; font-size: 10pt; mso-fareast-font-family: 'Times New Roman';"&gt;Your home IP Address &lt;/SPAN&gt;&lt;/LI&gt;&lt;LI class="MsoNormal" style="line-height: normal; margin: 0in 0in 10pt; color: black; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-list: l1 level1 lfo3; tab-stops: list .5in;"&gt;&lt;SPAN style="font-family: &amp;quot;Courier New&amp;quot;; font-size: 10pt; mso-fareast-font-family: 'Times New Roman';"&gt;Your work/school external IP Address &lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P class="MsoNormal" style="line-height: normal; margin: 0in 0in 12pt;"&gt;&lt;SPAN style="font-family: &amp;quot;Courier New&amp;quot;; color: black; font-size: 10pt; mso-fareast-font-family: 'Times New Roman';"&gt;The easiest way to get your IP Addresses is to go to &lt;A href="http://www.whatismyip.com"&gt;&lt;SPAN style="color: blue; mso-bidi-font-size: 11.0pt;"&gt;www.whatismyip.com&lt;/SPAN&gt;&lt;/A&gt; at home and at work. Write down the numbers. &lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR style="mso-yfti-irow: 6;"&gt;&lt;TD style="background-color: transparent; border: #000000; padding: 0in;"&gt;&lt;P class="MsoNormal" style="line-height: normal; margin: 0in 0in 0pt;"&gt;&lt;A name="software"&gt;&lt;/A&gt;&lt;STRONG style=": ; Courier New&amp;quot;: ; color: black; font-size: 10pt; font-family: &amp;quot; mso-fareast-font-family: 'Times New Roman'; "&gt;Software&lt;/STRONG&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR style="mso-yfti-irow: 7;"&gt;&lt;TD style="background-color: transparent; border: #000000; padding: 0in;"&gt;&lt;P class="MsoNormal" style="line-height: normal; margin: 0in 0in 12pt;"&gt;&lt;SPAN style="font-family: &amp;quot;Courier New&amp;quot;; color: black; font-size: 10pt; mso-fareast-font-family: 'Times New Roman';"&gt;We're going to be using 2 fairly simple pieces of software; an SSH Server and an SSH Client. &lt;BR /&gt;&lt;BR /&gt;There are a few flavors of SSH Server's out there, but we're going to be using OpenSSH because it's free. The website for OpenSSH is &lt;A href="http://www.openssh.com"&gt;&lt;SPAN style="color: blue; mso-bidi-font-size: 11.0pt;"&gt;http://www.openssh.com&lt;/SPAN&gt;&lt;/A&gt; . But wait! OpenSSH doesn't run on Windows unfortunately... But there is a site that converted OpenSSH to run on Windows, which is what we want! &lt;A href="http://sshwindows.sourceforge.net/"&gt;&lt;SPAN style="color: blue; mso-bidi-font-size: 11.0pt;"&gt;http://sshwindows.sourceforge.net/&lt;/SPAN&gt;&lt;/A&gt; . &lt;BR /&gt;&lt;BR /&gt;Download OpenSSH for Windows from &lt;A href="http://sshwindows.sourceforge.net/"&gt;&lt;SPAN style="color: blue; mso-bidi-font-size: 11.0pt;"&gt;http://sshwindows.sourceforge.net&lt;/SPAN&gt;&lt;/A&gt; . The version I wrote this document using was 3.7.1p1-1. The latest version should work for you, plus it will have less security holes. &lt;BR /&gt;&lt;BR /&gt;For the SSH Client I recommend using Putty. Putty is a small single executable SSH client with the ability to setup a tunnel. The newer version also support Dynamic Forwarding, which is essential. It's possible to use OpenSSH as your client as well as your server, but Putty is much easier to setup and use. Download putty.exe from &lt;A href="http://www.chiark.greenend.org.uk/~sgtatham/putty/download.html"&gt;&lt;SPAN style="color: blue; mso-bidi-font-size: 11.0pt;"&gt;http://www.chiark.greenend.org.uk/~sgtatham/putty/download.html&lt;/SPAN&gt;&lt;/A&gt; . &lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR style="mso-yfti-irow: 8;"&gt;&lt;TD style="background-color: transparent; border: #000000; padding: 0in;"&gt;&lt;P class="MsoNormal" style="line-height: normal; margin: 0in 0in 0pt;"&gt;&lt;A name="install_ssh"&gt;&lt;/A&gt;&lt;STRONG style=": ; Courier New&amp;quot;: ; color: black; font-size: 10pt; font-family: &amp;quot; mso-fareast-font-family: 'Times New Roman'; "&gt;Install the SSH Server&lt;/STRONG&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR style="mso-yfti-irow: 9;"&gt;&lt;TD style="background-color: transparent; border: #000000; padding: 0in;"&gt;&lt;P class="MsoNormal" style="line-height: normal; margin: 0in 0in 12pt;"&gt;&lt;SPAN style="font-family: &amp;quot;Courier New&amp;quot;; color: black; font-size: 10pt; mso-fareast-font-family: 'Times New Roman';"&gt;The OpenSSH installer comes in a zip file. Unzip the file, then run setupssh.exe. Choose to install both the Client and the Server. It will ask you to install into C:\Program Files\OpenSSH. If you choose to install into a different location, that fine, but be aware I will use the above path in this document. &lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR style="mso-yfti-irow: 10;"&gt;&lt;TD style="background-color: transparent; border: #000000; padding: 0in;"&gt;&lt;P class="MsoNormal" style="line-height: normal; margin: 0in 0in 0pt;"&gt;&lt;A name="windows"&gt;&lt;/A&gt;&lt;STRONG style=": ; Courier New&amp;quot;: ; color: black; font-size: 10pt; font-family: &amp;quot; mso-fareast-font-family: 'Times New Roman'; "&gt;Configure Windows&lt;/STRONG&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR style="mso-yfti-irow: 11;"&gt;&lt;TD style="background-color: transparent; border: #000000; padding: 0in;"&gt;&lt;P class="MsoNormal" style="line-height: normal; margin: 0in 0in 0pt;"&gt;&lt;SPAN style="font-family: &amp;quot;Courier New&amp;quot;; color: black; font-size: 10pt; mso-fareast-font-family: 'Times New Roman';"&gt;OpenSSH for Windows uses Windows' user database for login authentication. That mean you must have a User name and Password setup to login to your home computer. If you don't, you have 2 choices. 1, set a password on your Windows account, or 2, create a new local account that you will use to login from SSH. I know a lot of people out there don't use logins or passwords on their home computer, but if you're using NT, 2000, or XP, the functionality is there, even if you don't use it. &lt;BR /&gt;&lt;BR /&gt;There are many different flavors of Windows, with different methods of creating a local user. There's no way I can cover all of them, but here are a few examples; &lt;BR /&gt;&lt;BR /&gt;To create a new account on your home machine (Windows XP): &lt;/SPAN&gt;&lt;/P&gt;&lt;UL type="disc"&gt;&lt;LI class="MsoNormal" style="line-height: normal; margin: 0in 0in 10pt; color: black; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-list: l2 level1 lfo4; tab-stops: list .5in;"&gt;&lt;SPAN style="font-family: &amp;quot;Courier New&amp;quot;; font-size: 10pt; mso-fareast-font-family: 'Times New Roman';"&gt;Start Menu, open Control Panel, then User Accounts. &lt;/SPAN&gt;&lt;/LI&gt;&lt;LI class="MsoNormal" style="line-height: normal; margin: 0in 0in 10pt; color: black; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-list: l2 level1 lfo4; tab-stops: list .5in;"&gt;&lt;SPAN style="font-family: &amp;quot;Courier New&amp;quot;; font-size: 10pt; mso-fareast-font-family: 'Times New Roman';"&gt;Click Advanced tab, then the Advanced button. &lt;/SPAN&gt;&lt;/LI&gt;&lt;LI class="MsoNormal" style="line-height: normal; margin: 0in 0in 10pt; color: black; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-list: l2 level1 lfo4; tab-stops: list .5in;"&gt;&lt;SPAN style="font-family: &amp;quot;Courier New&amp;quot;; font-size: 10pt; mso-fareast-font-family: 'Times New Roman';"&gt;Highlight Users, then click Actions, then New User. &lt;/SPAN&gt;&lt;/LI&gt;&lt;LI class="MsoNormal" style="line-height: normal; margin: 0in 0in 10pt; color: black; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-list: l2 level1 lfo4; tab-stops: list .5in;"&gt;&lt;SPAN style="font-family: &amp;quot;Courier New&amp;quot;; font-size: 10pt; mso-fareast-font-family: 'Times New Roman';"&gt;Enter a User name, and a Password twice. I recommend you use a User name and Password that is different than anything you have ever used at work. Obviously, your employer probably knows your password, so there's no security if you use the same password at home. &lt;/SPAN&gt;&lt;/LI&gt;&lt;LI class="MsoNormal" style="line-height: normal; margin: 0in 0in 10pt; color: black; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-list: l2 level1 lfo4; tab-stops: list .5in;"&gt;&lt;SPAN style="font-family: &amp;quot;Courier New&amp;quot;; font-size: 10pt; mso-fareast-font-family: 'Times New Roman';"&gt;Deselect User must change password at next logon. &lt;/SPAN&gt;&lt;/LI&gt;&lt;LI class="MsoNormal" style="line-height: normal; margin: 0in 0in 10pt; color: black; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-list: l2 level1 lfo4; tab-stops: list .5in;"&gt;&lt;SPAN style="font-family: &amp;quot;Courier New&amp;quot;; font-size: 10pt; mso-fareast-font-family: 'Times New Roman';"&gt;Check Password never expires. &lt;/SPAN&gt;&lt;/LI&gt;&lt;LI class="MsoNormal" style="line-height: normal; margin: 0in 0in 10pt; color: black; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-list: l2 level1 lfo4; tab-stops: list .5in;"&gt;&lt;SPAN style="font-family: &amp;quot;Courier New&amp;quot;; font-size: 10pt; mso-fareast-font-family: 'Times New Roman';"&gt;Click Create. &lt;/SPAN&gt;&lt;/LI&gt;&lt;LI class="MsoNormal" style="line-height: normal; margin: 0in 0in 10pt; color: black; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-list: l2 level1 lfo4; tab-stops: list .5in;"&gt;&lt;SPAN style="font-family: &amp;quot;Courier New&amp;quot;; font-size: 10pt; mso-fareast-font-family: 'Times New Roman';"&gt;Close the Windows, close Control Panel. &lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P class="MsoNormal" style="line-height: normal; margin: 0in 0in 12pt;"&gt;&lt;SPAN style="font-family: &amp;quot;Courier New&amp;quot;; color: black; font-size: 10pt; mso-fareast-font-family: 'Times New Roman';"&gt;You should now have a new local Windows user on your home machine. Remember the Login name and password for later. &lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR style="mso-yfti-irow: 12;"&gt;&lt;TD style="background-color: transparent; border: #000000; padding: 0in;"&gt;&lt;P class="MsoNormal" style="line-height: normal; margin: 0in 0in 0pt;"&gt;&lt;A name="config_ssh"&gt;&lt;/A&gt;&lt;STRONG style=": ; Courier New&amp;quot;: ; color: black; font-size: 10pt; font-family: &amp;quot; mso-fareast-font-family: 'Times New Roman'; "&gt;Configure the SSH Server&lt;/STRONG&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR style="mso-yfti-irow: 13;"&gt;&lt;TD style="background-color: transparent; border: #000000; padding: 0in;"&gt;&lt;P class="MsoNormal" style="line-height: normal; margin: 0in 0in 12pt;"&gt;&lt;SPAN style="font-family: &amp;quot;Courier New&amp;quot;; color: black; font-size: 10pt; mso-fareast-font-family: 'Times New Roman';"&gt;We want to configure your SSH server to allow access using User name and Passwords, and to listen on port 443 instead of port 22. &lt;BR /&gt;&lt;BR /&gt;&lt;EM&gt;Why port 443 instead of port 22? In most cases your employer will block almost all outgoing network ports except for port 80 and port 443, which are the 2 ports that webservers run on. I used to tell people to run SSH on port 80 because that's the standard webserver port, but now I recommend you run it on 443. Port 443 is used for encrypted websites, which is what your shunnel traffic will look like as it passes through the firewall. If you have trouble on port 443, try it on port 80 instead. If neither work, you're probably out of luck.&lt;/EM&gt; &lt;BR /&gt;&lt;BR /&gt;Open Windows Explorer, navigate to C:\Program Files\OpenSSH\etc. Open the file sshd_config using Wordpad. (That's sshd_config not ssh_config!) &lt;/SPAN&gt;&lt;/P&gt;&lt;TABLE border="0" cellpadding="0" cellspacing="0" class="MsoNormalTable" style="width: 100%; mso-cellspacing: 0in; mso-yfti-tbllook: 1184; mso-padding-alt: 0in 0in 0in 0in;" width="100%"&gt;&lt;TBODY&gt;&lt;TR style="mso-yfti-irow: 0; mso-yfti-firstrow: yes; mso-yfti-lastrow: yes;"&gt;&lt;TD style="background-color: transparent; width: 90%; border: #000000; padding: 0in;" width="90%"&gt;&lt;P class="MsoNormal" style="line-height: normal; margin: 0in 0in 12pt;"&gt;&lt;SPAN style="font-family: &amp;quot;Courier New&amp;quot;; color: black; font-size: 10pt; mso-fareast-font-family: 'Times New Roman';"&gt;Change the line &lt;BR /&gt;&lt;BR /&gt;#Port 22 &lt;BR /&gt;&lt;BR /&gt;to &lt;BR /&gt;&lt;BR /&gt;Port 443 &lt;BR /&gt;&lt;BR /&gt;Save the file. &lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P class="MsoNormal" style="line-height: normal; margin: 0in 0in 12pt;"&gt;&lt;SPAN style="font-family: &amp;quot;Courier New&amp;quot;; color: black; font-size: 10pt; mso-fareast-font-family: 'Times New Roman';"&gt;Now open a command prompt. Change to C:\Program Files\OpenSSH\bin. We are going to create a user and group database from your Windows user database. Type the following; &lt;BR /&gt;&lt;BR /&gt;mkgroup -l &amp;gt; ..\etc\group &lt;BR /&gt;&lt;BR /&gt;Then &lt;BR /&gt;&lt;BR /&gt;mkpasswd -l &amp;gt; ..\etc\passwd &lt;BR /&gt;&lt;BR /&gt;These 2 commands will create group and password files at C:\Program File\OpenSSH\etc &lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR style="mso-yfti-irow: 14;"&gt;&lt;TD style="background-color: transparent; border: #000000; padding: 0in;"&gt;&lt;P class="MsoNormal" style="line-height: normal; margin: 0in 0in 0pt;"&gt;&lt;A name="start_stop"&gt;&lt;/A&gt;&lt;STRONG style=": ; Courier New&amp;quot;: ; color: black; font-size: 10pt; font-family: &amp;quot; mso-fareast-font-family: 'Times New Roman'; "&gt;Start/Stoping the SSH Server&lt;/STRONG&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR style="mso-yfti-irow: 15;"&gt;&lt;TD style="background-color: transparent; border: #000000; padding: 0in;"&gt;&lt;P class="MsoNormal" style="line-height: normal; margin: 0in 0in 12pt;"&gt;&lt;SPAN style="font-family: &amp;quot;Courier New&amp;quot;; color: black; font-size: 10pt; mso-fareast-font-family: 'Times New Roman';"&gt;On your home computer, open a command prompt. To start your SSH server, type the following: &lt;BR /&gt;&lt;BR /&gt;net start opensshd &lt;BR /&gt;&lt;BR /&gt;To stop your SSH server, type the following: &lt;BR /&gt;&lt;BR /&gt;net stop opensshd &lt;BR /&gt;&lt;BR /&gt;To make it easy, you can create a .bat file that will this command. If you make a shortcut to the .bat file in your Windows Startup program group, then when you turn on your home computer in the morning, the servers will startup automatically, and be ready for you when you get to work. &lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR style="mso-yfti-irow: 16;"&gt;&lt;TD style="background-color: transparent; border: #000000; padding: 0in;"&gt;&lt;P class="MsoNormal" style="line-height: normal; margin: 0in 0in 0pt;"&gt;&lt;A name="router"&gt;&lt;/A&gt;&lt;STRONG style=": ; Courier New&amp;quot;: ; color: black; font-size: 10pt; font-family: &amp;quot; mso-fareast-font-family: 'Times New Roman'; "&gt;If you have a wired or wireless router at home (Linksys, D-Link, Netgear, etc)&lt;/STRONG&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR style="mso-yfti-irow: 17;"&gt;&lt;TD style="background-color: transparent; border: #000000; padding: 0in;"&gt;&lt;P class="MsoNormal" style="line-height: normal; margin: 0in 0in 12pt;"&gt;&lt;SPAN style="font-family: &amp;quot;Courier New&amp;quot;; color: black; font-size: 10pt; mso-fareast-font-family: 'Times New Roman';"&gt;Some routers call it port forwarding and others call it virtual servers, but the setup is very similar no matter what brand you use. You will need to configure your router to route port 443 to the computer where you're running the SSH server. I not going to go into details, but there is usually a browser based interface directly to the router, which will have a page to setup virtual servers. Configure it to forward port 443 to your SSH server computer, port 443. &lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR style="mso-yfti-irow: 18;"&gt;&lt;TD style="background-color: transparent; border: #000000; padding: 0in;"&gt;&lt;P class="MsoNormal" style="line-height: normal; margin: 0in 0in 0pt;"&gt;&lt;A name="setup_putty"&gt;&lt;/A&gt;&lt;STRONG style=": ; Courier New&amp;quot;: ; color: black; font-size: 10pt; font-family: &amp;quot; mso-fareast-font-family: 'Times New Roman'; "&gt;Setup Putty at Work/School&lt;/STRONG&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR style="mso-yfti-irow: 19;"&gt;&lt;TD style="background-color: transparent; border: #000000; padding: 0in;"&gt;&lt;P class="MsoNormal" style="line-height: normal; margin: 0in 0in 12pt;"&gt;&lt;SPAN style="font-family: &amp;quot;Courier New&amp;quot;; color: black; font-size: 10pt; mso-fareast-font-family: 'Times New Roman';"&gt;Copy putty.exe to somewhere on your hard drive at work. c:\ will do fine, or anywhere else you want. Your desktop is convenient but kind of obvious. If you don't have permissions to write files to your hard drive, just copy putty.exe and shunnel.bat to a floppy disk or burn them onto a CD. Take the disk to work and run Putty from the appropriate drive. &lt;BR /&gt;&lt;BR /&gt;Open Notepad and copy the following into it, change the bold part where necessary; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="line-height: normal; margin: 0in 0in 0pt;"&gt;&lt;SPAN style="font-family: &amp;quot;Courier New&amp;quot;; color: black; font-size: 10pt; mso-fareast-font-family: 'Times New Roman';"&gt;putty -D 8080 -P 443 -ssh &lt;STRONG&gt;homeIP&lt;/STRONG&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;UL type="disc"&gt;&lt;LI class="MsoNormal" style="line-height: normal; margin: 0in 0in 10pt; color: black; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-list: l3 level1 lfo5; tab-stops: list .5in;"&gt;&lt;SPAN style="font-family: &amp;quot;Courier New&amp;quot;; font-size: 10pt; mso-fareast-font-family: 'Times New Roman';"&gt;homeIP should be the IP address of your home machine that you wrote down in the Addresses section above. &lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P class="MsoNormal" style="line-height: normal; margin: 0in 0in 12pt;"&gt;&lt;SPAN style="font-family: &amp;quot;Courier New&amp;quot;; color: black; font-size: 10pt; mso-fareast-font-family: 'Times New Roman';"&gt;Save the file as shunnel.bat in the same directory that you saved putty.exe. &lt;BR /&gt;&lt;BR /&gt;&lt;EM&gt;Note for advanced users: If your computer at work is already configured to use a proxy server, you need to configure Putty a little differently, but this may still work.&lt;BR /&gt;&lt;BR /&gt;Open Putty in graphical mode, input your connection setting, and also copy the proxy settings from Internet Explorer to Putty's proxy configuration screen. Putty should now create a secure tunnel through the proxy at work to your computer at home... pretty neat trick.&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR style="mso-yfti-irow: 20;"&gt;&lt;TD style="background-color: transparent; border: #000000; padding: 0in;"&gt;&lt;P class="MsoNormal" style="line-height: normal; margin: 0in 0in 0pt;"&gt;&lt;A name="create_tunnel"&gt;&lt;/A&gt;&lt;STRONG style=": ; Courier New&amp;quot;: ; color: black; font-size: 10pt; font-family: &amp;quot; mso-fareast-font-family: 'Times New Roman'; "&gt;Create your tunnel&lt;/STRONG&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR style="mso-yfti-irow: 21;"&gt;&lt;TD style="background-color: transparent; border: #000000; padding: 0in;"&gt;&lt;P class="MsoNormal" style="line-height: normal; margin: 0in 0in 12pt;"&gt;&lt;SPAN style="font-family: &amp;quot;Courier New&amp;quot;; color: black; font-size: 10pt; mso-fareast-font-family: 'Times New Roman';"&gt;At work, simply double click shunnel.bat to initiate the shunnel. A Putty window will popup asking for a login name and password. Type the user name and password you created above on the Windows account. If it works, you will be presented with a DOS prompt waiting for a command. This is actually a command prompt to your HOME machine. You can use it if you want, but as long as this command prompt is open, your tunnel is alive. To close the tunnel, type exit or close the window. &lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR style="mso-yfti-irow: 22;"&gt;&lt;TD style="background-color: transparent; border: #000000; padding: 0in;"&gt;&lt;P class="MsoNormal" style="line-height: normal; margin: 0in 0in 0pt;"&gt;&lt;A name="advanced"&gt;&lt;/A&gt;&lt;STRONG style=": ; Courier New&amp;quot;: ; color: black; font-size: 10pt; font-family: &amp;quot; mso-fareast-font-family: 'Times New Roman'; "&gt;For Advanced Users&lt;/STRONG&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR style="mso-yfti-irow: 23;"&gt;&lt;TD style="background-color: transparent; border: #000000; padding: 0in;"&gt;&lt;P class="MsoNormal" style="line-height: normal; margin: 0in 0in 12pt;"&gt;&lt;SPAN style="font-family: &amp;quot;Courier New&amp;quot;; color: black; font-size: 10pt; mso-fareast-font-family: 'Times New Roman';"&gt;If you are very familiar with SSH and know what you are doing, you can set this up so you don't have to enter a password each time you create the shunnel. You have to install OpenSSH as your SSH client and then setup key based authentication by creating a public and private key on your work computer. Install the public key on the SSH server on your home computer. Thanks to Robert W. for this suggestion. I may go into more detail on how do set this up in the future. &lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR style="mso-yfti-irow: 24;"&gt;&lt;TD style="background-color: transparent; border: #000000; padding: 0in;"&gt;&lt;P class="MsoNormal" style="line-height: normal; margin: 0in 0in 0pt;"&gt;&lt;A name="ie"&gt;&lt;/A&gt;&lt;STRONG style=": ; Courier New&amp;quot;: ; color: black; font-size: 10pt; font-family: &amp;quot; mso-fareast-font-family: 'Times New Roman'; "&gt;Configure Internet Explorer&lt;/STRONG&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR style="mso-yfti-irow: 25; mso-yfti-lastrow: yes;"&gt;&lt;TD style="background-color: transparent; border: #000000; padding: 0in;"&gt;&lt;P class="MsoNormal" style="line-height: normal; margin: 0in 0in 0pt;"&gt;&lt;SPAN style="font-family: &amp;quot;Courier New&amp;quot;; color: black; font-size: 10pt; mso-fareast-font-family: 'Times New Roman';"&gt;Now we have to configure Internet Explorer at work to use a SOCKS proxy server. &lt;BR /&gt;&lt;BR /&gt;First, at school/work, go to &lt;A href="http://www.whatismyip.com"&gt;&lt;SPAN style="color: blue; mso-bidi-font-size: 11.0pt;"&gt;http://www.whatismyip.com&lt;/SPAN&gt;&lt;/A&gt; . Write down the number. This is your IP address WITHOUT your shunnel enabled. &lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/DIV&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 10pt;"&gt;&lt;SPAN style="font-family: Calibri; color: #000000; font-size: 12pt;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 03 Mar 2010 16:48:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/need-help-with-security-issue/m-p/1414041#M742680</guid>
      <dc:creator>jason-calbert_2</dc:creator>
      <dc:date>2010-03-03T16:48:06Z</dc:date>
    </item>
    <item>
      <title>Re: Need help with security issue</title>
      <link>https://community.cisco.com/t5/network-security/need-help-with-security-issue/m-p/1414042#M742717</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You can auth proxy one ip address only going to one port if you want.&lt;/P&gt;&lt;P&gt;Wouldn't that solve the problem?&lt;/P&gt;&lt;P&gt;If not there has to be something in the middle that will inspect authenticate the application, I don't see any other way.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PK&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 03 Mar 2010 17:03:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/need-help-with-security-issue/m-p/1414042#M742717</guid>
      <dc:creator>Panos Kampanakis</dc:creator>
      <dc:date>2010-03-03T17:03:42Z</dc:date>
    </item>
    <item>
      <title>Re: Need help with security issue</title>
      <link>https://community.cisco.com/t5/network-security/need-help-with-security-issue/m-p/1414043#M742737</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Jason&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As PK says, you are going to need something to intercept and inspect the application traffic if you are not prepared to authenticate.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sometimes though a technical solution is not always either available or the best solution. You seem to have an idea of which group of users it might be. Are you not able to narrow it down any more to maybe a specific user or couple of users ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Have you outlined the issues with bypassing the firewall and presented this to your line manager ?&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Jon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 03 Mar 2010 17:19:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/need-help-with-security-issue/m-p/1414043#M742737</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2010-03-03T17:19:01Z</dc:date>
    </item>
  </channel>
</rss>

