Recommended Posts

Is it possible to access SSH/FTP through port tunnelling or proxy or something?

I'm not exactly sure what i'm asking for but the problem i'm facing is: i want to access my home NAS (linux) box from work. However my works proxy is pretty much locked down i can't ftp, ssh, ftps.. everything is pretty much blocked.

I can WebDAV into the box, as expected as this is port 80.. so is there any way i can access ssh/ftp over port 80? Obviously i can't listen on port 80 since it's already in use but i can change the ports to anything else not in use.

WebDAV would be suitable but since it treats all files like http requests it's hard to do web development from the box, if there is an error in the PHP file. then opening the file will just display the error, rather than the code. It's the same with .htaccess files and such, they are blocked from direct http access.

I'm not sure if either solution would be possible:

- Make WebDAV work like FTP... may be some apache configs or something?

- Port tunnelling or some sort of service to allow access to FTP/SSH over a proxy?

I don't need a lecture about trying to go outside of company networks, policies or going around firewalls. I manage the whole network it is the external firewalls whats blocking but the guys who manage it are a nightmare ignore emails and never get the job done. I've been complaining about FTP access for years as we struggle to update our own website, they say it should work, logs say otherwise.. They haven't given me full access to the proxy firewall, even though they should, i've given up trying and want to see if there is another method?

Who said anything about the NAS running on 443? Have you router forward 443 to 22. Use a different box to tunnel into your network, then access what you want over that tunnel. Use openvpn to your router/otherbox on 443, then connect to whatever you want, etc.

What router do you have? if you have one that runs Tomato or DDWRT you could run the SSH server on port 443 then forward ports to services running on your nas.

I do this as a quick and secure way of connecting to my home server.

I use openvpn over 443 to my router, then I can access anything I want on my local network. What is nice about openvpn is you can even bounce it off a proxy if all they do is allow your proxy to access the internet.

Sure you can use ssh as your poor mans vpn, tunnel through it to what you want. If all you need is access to a couple of devices/services on the remote network that works fine. But its much easier when you have access to everything on the remote network without having to create specific tunnels through the ssh connection.

As to your ftp not working -- are you using active or passive? If your running through a double nat - ie your end and the remote end. And there is no helpers on the firewalls to change ports. Server not setup correctly to hand out its public ip, etc. etc. Then yeah you can have issues with that.

Can you not even get the control connection on port 21? Are you trying to use ftps? What ports?

Here is a good writeup on how active and passive ftp work, once you understand how the connections are made in each method it can help you figure out what is not setup correctly on your ftp server to allow access, etc.

http://slacksite.com/other/ftp.html

I have a rubbish Virgin Media SuperHub which is a NETGEAR VMDG480 so i'm not sure what capabilities it will have i'll check when i return home.

VPN will require some reading i'm not 100% on it never done it before however my NAS does have a VPN server capabilities no sure if that would help?

FTP i've tried passive and active;

Blocked logs just show this:

May 30 13:59:20  reject_Trusted/Internet LAN 1? 10.83.112.36 59277 81.100.2X7.XX 21 TCP[/CODE]

Also does this for 22.

Where did you pull that log entry from? Your locations firewall/proxy?

Yeah never going to work if you can not connect to the control port. What nas do you have? If it has vpn, I would guess some proprietary vpn -- maybe its openvpn?

Would have to check the manual for your router - but if some modified device for use with a specific isp, they might have removed the bells and whistle type features. Not sure I would call forwarding port X to private ip port Y a bell or even a whistle. But yeah that would make it a bit more difficult if not there, would have to then change the actual listen port on the device running the service -- which might not be an option if some appliance type nas? Do you have any other PC or something you could use to run either SSH or openvpn? So for example you can pickup like a pogo for like $25.

Where did you pull that log entry from? Your locations firewall/proxy?

Yeah never going to work if you can not connect to the control port. What nas do you have? If it has vpn, I would guess some proprietary vpn -- maybe its openvpn?

Would have to check the manual for your router - but if some modified device for use with a specific isp, they might have removed the bells and whistle type features. Not sure I would call forwarding port X to private ip port Y a bell or even a whistle. But yeah that would make it a bit more difficult if not there, would have to then change the actual listen port on the device running the service -- which might not be an option if some appliance type nas? Do you have any other PC or something you could use to run either SSH or openvpn? So for example you can pickup like a pogo for like $25.

That log is from my works cachepilot/proxy from when i try to connect to anything except http/https on my works network.

I have a QNAP TS219P II and it has OpenVPN - the information on that: http://docs.qnap.com/nas/en/vpn_service.htm?zoom_highlightsub=vpn

My router definitely has some sort of port forwarding features.

Well I would hope it have port forwarding ;) But can you forward port X to port Y is the question, this is not an uncommon feature - really should be standard type setup.. But you never know with these isp modified devices.

If your nas supports - the question is can you get it to listen on tcp port X vs the standard udp openvpn 1194 port.

If you can get it to listen and use tcp on 443 then you should be be good to go with openvpn setup.

I'm not sure here is the admin screens:

http://screenshots.portforward.com/routers/Virgin_Media/CG3101D/Port_Forwarding.jpg

http://1.bp.blogspot.com/-Het12XEXyVM/Tw24KPP0bBI/AAAAAAAAAcA/TCwzuTkPdR0/s1600/001%252520%25282%2529%255B3%255D.png

When i try to set OpenVPN Server port to TCP 443 on the NAS it says the same 'This port is reserved for other services' - That's so annoying considering i've disabled everything it uses.

Are you sure you're forwarding your ports properly? SImply tried rebooting or updating the firmware?

Next to that, I'm not sure whether you've got a consumer or business membership, but I suspect Virgin might be using the port for some sort of remote management of the router. Have you to just use tcp port 80 or tried using another router? I'd like to suggest using a router that can be flashed with DD-WRT or OpenWRT or a professional router with Cisco IOS (not the SOHO/SMB crap), because it offers advanced options and lets you mimic most requirements or special settings required by an ISP (not sure how closed down Virgin is).

Another 'dirty' solution would be using a reverse NAT based rule that would publish your data to another external (3rd party) service that offers access through the webbrowser in case you really need it, but securitywise this is generally not a good idea.

Another 'dirty' solution would be just to open a port on the router (not forwarding it to anything, if your router supports it), then connect to your router on that source port and sort of re-direct the traffic to another destination port (with an SSH client or some sort of client which would support it ofc).

Yes forwarding ports correctly the NAS does it automatically as soon as i change port on a service it automatically updates on the router i've confirmed it works. rebooted yes firmware is latest.

i think VM use 8080 for remote.

I've tried connecting to VPN on some known unused ports but no joy at all, i need 443 but the stupid NAS won't take it.

I'm going to check on their support forums to see if there is a way to free it or change from the command line.

Other than that i think my only option is tunneling on port 80 or 443? to 22 or whatever on my NAS. but still struggling with this?

The SuperHub port forwarding is hopeless and does not support what you want for mapping external port to different internal port better to just get your own router really.

For tunnelling you could use FreeProxy.

http://www.handcraftedsoftware.org/index.php?page=download&op=getFile&id=2&title=FreeProxy-Internet-Suite

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • It had gone weeks ago. Although thinking about it I'm on the beta.
    • They thought value of their goods would forever only drop like it used to and didn't account for sudden increase in price because of all the Ai hype. Tough luck Samsung, don't try to weasel this one out. Also American customer protection laws are a**. In Europe, you need to be compensated for a functioning product of same or better characteristics (not same price point as when it was originally bought!) if it can't be repaired and when you receive a replacement product your warranty starts from scratch because you received a different item than you previously had and old warranty thus cannot apply to it anymore. If your actual item was successfully repaired, warranty gets extended for the period the item was in service. If item is repaired to a significant extent, warranty also starts over from scratch because major part of it was replaced. Americans need to fight to get this kind of consumer protections because they are constantly getting screwed over.
    • Microsoft releases new Windows 11 Media Creation Tool with the latest updates by Taras Buria Patch Tuesday updates arrive every month, bringing users new features and security updates. To make sure customers have access to the most recent images, Microsoft also releases updates to the Media Creation Tool app, its official utility for Windows 11 installation. Today, the company pushed new ISOs to Media Creation Tool, allowing you to create images with the June 2026 Patch Tuesday updates. With the latest update, the Media Creation Tool now downloads KB5094126. It is Windows 11 version 25H2, build 26200.8655, which is also available via Windows Update. Note that the app itself remains on the previous version, which you can check in Properties > Details. The only change is that it now downloads a more recent Windows 11 build, so the only way to check is to download an ISO. The June 2026 Patch Tuesday update is a special release for Windows 11, as it brings a new performance profile to make the operating system more responsive and snappier when rendering various user interface surfaces, including the Start menu, quick settings, and more. It does so by spiking processor speeds for a brief moment, resulting in higher loads for a second or two. The so-called “Low latency profile” is rolling out gradually, but you can force-enable it with the ViVeTool app. Other changes include webcam improvements, Task Manager updates, shared audio support, and more. You can download the Media Creation Tool app from the official Microsoft website using this link. Besides MCT, Microsoft lets you download Windows 11 ISO as a file directly from the official Windows 11 website. However, you will need a third-party app to write it to your USB drive. Check out this guide if you want to know how to do that.
    • Louis Rossmann suing Samsung over "990 Pro SSD warranty scam" by Sayan Sen Back in 2023, if you recall, Neowin reviewer Robbie Khan had a dispute with Samsung over his 990 Pro SSD, which was rapidly losing its health. After significant back and forth, the tech giant had finally released firmware to "stop" the issue. Interestingly, its previous flagship at the time, the 980 Pro was also facing problems leading to two consecutive sets of firmware fixes. Three years later, it looks like a similar conflict has now broken out between tech repair entrepreneur YouTuber Louis Rossmann and Samsung, as it has escalated into a threatened lawsuit after the company allegedly refused to appropriately replace a failing 990 Pro SSD that remained under warranty. According to Rossmann, a 4TB Samsung 990 Pro NVMe SSD purchased for approximately $330 less than two years ago, began experiencing major hiccups and issues, even though he claims it had been operated under ideal cooling conditions. It was installed in a RAID 1 array and cooled by a heatsink and dual high-speed fans. However the drive reportedly started dropping out of the array, exhibiting controller-level failures that eventually became not useable in any meaningful way. Rossmann said Samsung’s support process was marked by delays and confusion from the very start. After initially contacting the wrong regional support channel, he was redirected to Samsung’s memory support division where he submitted detailed diagnostics, logs, and proof of purchase. Rossmann runs a repair company and owns an ACE Lab PC-3000 machine, which is a professional-grade data recovery equipment. As such, he had been confident in his diagnostics. Samsung even seemingly acknowledged that later. Regardless, Rossmann claims that his initial support ticket was automatically closed before a full 24-hour response window had elapsed, forcing him to reopen the case and resubmit documentation. The controversy however intensified further from here after Samsung accepted the drive for warranty evaluation but later returned it with a repair report stating that the drive had passed its testing and that the SSD had been verified as functional. Rossmann strongly disputed those claims citing that his own independent testing on PC-3000 showed write speeds reducing to as low as 40–60 MB/s before the drive failed entirely. Samsung subsequently informed him that the SSD had been reset and reflashed, passing internal stress tests. However, the company also stated that replacement units were unavailable due to an industry-wide memory shortage and suggested that a refund process could be initiated if further testing confirmed the fault. Thus, to settle, the company offered a refund of $330, the amount that was initially paid by him to make the purchase. Here, Rossmann pointed out the seeming hypocrisy of the tech giant as in how no Samsung drive was apparently allocated for warranty replacements, but they were abundantly available for retail sales especially when using business accounts. As you can see, Rossmann is indeed right, there are Samsung 990 Pro 4TB SSDs on Amazon currently for $950 (shipped and sold by first-party Amazon US itself), and they are also available on Samsung's own store too, albeit for an even higher price of $1100. Thus Rossmann argues that Samsung’s inability or unwillingness to provide a replacement while the same model remains available for purchase at significantly higher market prices reflects a failure to honor its warranty obligations. He has issued a formal 60-day notice and says he intends to file suit in Texas small claims court, asserting that companies should face greater costs for denying legitimate warranty claims than for fulfilling them. You can check out the full video titled "Samsung's 990 Pro SSD warranty policy is a scam; I'm taking them to court," at the link below. Source and image: Louis Rossmann (YouTube) As an Amazon Associate we earn from qualifying purchases
  • Recent Achievements

    • Week One Done
      davidbazooked earned a badge
      Week One Done
    • One Month Later
      Jamswaz earned a badge
      One Month Later
    • Week One Done
      Jamswaz earned a badge
      Week One Done
    • Rookie
      Marzoid went up a rank
      Rookie
    • Community Regular
      coch went up a rank
      Community Regular
  • Popular Contributors

    1. 1
      +primortal
      509
    2. 2
      PsYcHoKiLLa
      184
    3. 3
      +Edouard
      158
    4. 4
      Steven P.
      83
    5. 5
      ATLien_0
      75
  • Tell a friend

    Love Neowin? Tell a friend!