[ubuntu-za] SSH restrictions/config per INCOMING host connection

Michael milegrin at gmail.com
Wed Mar 5 08:30:10 GMT 2008


Greetings

  I know that you can create host specific and user specific configs
in OpenSSH for outgoing connections (see ssh_config and the "Match
User <username>" stanzas in sshd_config)

  I however need to restrict incoming access based on the originating
IP/Hostname and I have exhausted google and my own ideas.

  Basically have a restricted user that may only accept incoming SSH
connections from 3 specific hosts.  I suspect is has summin to do the
the "Match User <username>" stanza in /etc/ssh/sshd_config but I have
not been successful in getting it to work.

Eg :
HostA is permitted to SSH to HostB as OPS user
HostC is NOT permitted to SSH to HostB as OPS user and should get a login denied
BUT all others users should not be affected by this restriction.

  Any ideas would be most most welcome and greatly appreciated.

Regards
Michael L Griffin



More information about the ubuntu-za mailing list