Recommended Posts

Greetings Neowin,

Hopefully this is an easy one for someone; I have not had this issue (using OpenSSH) in the past so I'm just drawing a blank.

I have set up my first FreeNAS server and have everything running smoothly; all is well on my LAN. However, I would like to access my FreeNAS box remotely through SSH. I am having issues connecting to the built-in SSH server from the WAN side, though.

I only have one interface active on the FreeNAS box and it has no issue reaching the WAN from my gateway (I could receive ping echos, anyway). I have the SSH daemon listening on some arbitrary port (TCP 3612, for example) and verified using netstat that it was, in fact, listening. I have created a port forward rule for inbound TCP:3612 traffic to hit my FreeNAS box. I checked a few different sites to see if port 3612 was visible (it is). I played with a few different ports (including 22) and all the ports were apparently visible from the outside, but no go.

I can reach the box via SSH internally using PuTTY and do what I need to do, but externally, I receive "Connection Refused" from my PuTTY client. I can't make the connection from the inside by going out to my public IP and trying to open a session nor can I make the connection from an alternate Internet connection altogether.

Nothing is logged by my firewall and nothing is in FreeNAS' SSH log.

Any suggestions?

Link to comment
https://www.neowin.net/forum/topic/703598-freenas-remote-ssh/
Share on other sites

Well if your freenas logs sshd and or its firewall logs are not showing anything -- then you are not getting there.

What devices do you have between your freenas and the internet? You could be double natting.

edit: Ok I just grabbed a copy of freenas -- and in like 30 seconds had ssh access from the outside my network. Here is from the freenas ssh log

post-14624-1227968166_thumb.png

First connection is from my local box, next connection is from outside.

If your not seeing anything in your freenas ssh log -- then your not getting there. You have double nat, your port forward is wrong, your using the wrong public IP to try and get there, etc.

Edited by BudMan

You would think it would be aware if he had created a hosts.deny file, which btw has been deprecated for quite some time.. Both allow and deny rules have been in the hosts.allow file for quite some time.

Freenas does not have that file out of the box - nor do I think it would use it if was created.

And even if it did - it would log that it did so in its ssh log.. He has stated there is nothing in the logs -- which clearly points to he is not even getting to the freenas box.

BudMan is right, there is no hosts.deny file.

All is working now; it had nothing to do with FreeNAS' config itself, incorrect port forwards or using the wrong WAN IP, it was just a dumbass move on my part with a client-side firewall config. ;)

All is well now, thanks for the suggestions though. :)

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • I noticed this was already happening within my organization; my teams location will change between remote and on-site without me having to do anything. Is it possible this is live already for select customers?
    • I wonder what it will show when I'm plugged in with my ethernet cable at home and not using WiFi.
    • While LibreOffice is not pleased to see a new competitor, they are absolutely correct in stating that Euro-Office using a MS file standard as a default is not being truly "European." Using a MS standard just means Euro-Office is just a "bastardized MS Office Suite." (Wasn't a major purpose of Euro-Office was to get away from being captive and enslaved to MS's Office Suite??)
    • Microsoft continues its long-term policy of spying on their users--despite vehement denials. That feature will be disabled (or removed) either "elegantly" with MS providing a true way to disable it, or "quick and dirty" via a third-party who WILL come up with a way to disable it. Your choice MS...
    • Helium Browser 0.13.3.1 by Razvan Serea Helium is a private, fast, and honest Chromium-based web browser — built for people, with love. It offers the best privacy by default, unbiased ad-blocking, and a clean experience free from bloat and noise. Proudly based on Ungoogled-Chromium, Helium removes Google’s clutter while keeping a fast, efficient development pipeline. With thoughtful touches like native !bangs and split view, Helium is a people-first, fully open-source browser that puts control back in your hands. Privacy, security, and control come first. Ads, trackers, and third-party cookies are blocked automatically, HTTPS is enforced everywhere, and all Chromium extensions work seamlessly — while Google can’t track your activity. Helium’s 13,000+ offline-ready !bangs let you jump straight to sites or AI tools like ChatGPT instantly. Open-source, people-first, and unbiased, Helium delivers a browsing experience that’s fast, secure, and free from noise, ads, and compromises. Helium Browser key features: Performance Fast, efficient, and lightweight — built on Chromium’s optimized engine. Energy-saving and consistent — stays fast over time without slowing down. No bloat — stripped of unnecessary components for maximum speed. Minimalist interface — compact, clean, and distraction-free. Customizable toolbar — hide elements you don’t need. Smooth and stable — no flicker, lag, or animation glitches. Comfort-focused experience — intuitive and unobtrusive. Privacy & Security Best privacy by default — blocks ads, trackers, phishing, and third-party cookies. Unbiased ad-blocking — powered by community filters and uBlock Origin. No telemetry or analytics — zero background web requests on first launch. Strict HTTPS enforcement — warns for insecure sites. Passkeys supported — modern authentication made simple. No built-in password manager or cloud sync — your data stays yours. Extension Compatibility Full Chromium extension support — including MV2 extensions. Anonymized Chrome Web Store requests — Google can’t track extension installs. Extended MV2 support — maintained for as long as possible. Smart Features Native !bangs — browse faster using 13,000+ offline-ready shortcuts. AI integration — use !chatgpt and others directly from the address bar. Offline functionality — bangs work without an Internet connection. Philosophy People-first design — open source, transparent, and community-driven. No ads, no noise, no bias — privacy and honesty over profit. Helium Browser 0.13.3.1 changelog: f53b28d update: helium 0.13.3.1 (#292) b3cbb2ba revision: bump to 3 (#1925) bcacb8c7 chromium: update to 149.0.7827.114 (#1924) Download: Helium 64-bit | Portable 64-bit |~100.0 MB (Open Source) Download: Helium ARM64 | Portable ARM64 Links: Helium Home Page | macOS | Linux | Screenshot Get alerted to all of our Software updates on Twitter at @NeowinSoftware
  • Recent Achievements

    • Week One Done
      ssd21345 earned a badge
      Week One Done
    • Contributor
      MarkHughes4096 went up a rank
      Contributor
    • Dedicated
      jordanspringer earned a badge
      Dedicated
    • Rookie
      Rimplesnort went up a rank
      Rookie
    • One Year In
      Markus94287 earned a badge
      One Year In
  • Popular Contributors

    1. 1
      +primortal
      507
    2. 2
      +Edouard
      179
    3. 3
      PsYcHoKiLLa
      140
    4. 4
      ATLien_0
      91
    5. 5
      Steven P.
      78
  • Tell a friend

    Love Neowin? Tell a friend!