ssh ethernet tunneling as normal user












1















I would like to connect 2 tap-devices. The tap-device on the remote server is owned by "user". This is my test-command:



# ssh -oTunnel=ethernet -w0:0 user@server


But it does not work, I get this error:



channel 0: open failed: administratively prohibited: open failed


How could I solve this problem?



distro: openSUSE, location: France










share|improve this question









New contributor




user918546 is a new contributor to this site. Take care in asking for clarification, commenting, and answering.
Check out our Code of Conduct.
















  • 1





    Hi. What distro and location?

    – Time4Tea
    9 hours ago











  • I am little confused. I was about to answer "not" because I remember it once said in the man page that you require root privileges on your client to create a tun or tap device, but I cant find that remark i neither ssh nor ssh_config man pages. So I guess I don't have an answer for you. :-(

    – Bananguin
    7 hours ago






  • 1





    The tap already exists and is owned by the user. ssh just has to attach to it. As root, there is no problem, but I prefer to use a normal user.

    – user918546
    7 hours ago











  • As you say, the easiest way is doing as root on both sides. I also do not feel confy doing it.

    – Rui F Ribeiro
    6 hours ago











  • @Bananguin & all sshd_config : PermitTunnel ... Independent of this setting ... device must allow access to the user. so seems possible as non root. what about SELinux/Apparmor ?

    – A.B
    4 hours ago
















1















I would like to connect 2 tap-devices. The tap-device on the remote server is owned by "user". This is my test-command:



# ssh -oTunnel=ethernet -w0:0 user@server


But it does not work, I get this error:



channel 0: open failed: administratively prohibited: open failed


How could I solve this problem?



distro: openSUSE, location: France










share|improve this question









New contributor




user918546 is a new contributor to this site. Take care in asking for clarification, commenting, and answering.
Check out our Code of Conduct.
















  • 1





    Hi. What distro and location?

    – Time4Tea
    9 hours ago











  • I am little confused. I was about to answer "not" because I remember it once said in the man page that you require root privileges on your client to create a tun or tap device, but I cant find that remark i neither ssh nor ssh_config man pages. So I guess I don't have an answer for you. :-(

    – Bananguin
    7 hours ago






  • 1





    The tap already exists and is owned by the user. ssh just has to attach to it. As root, there is no problem, but I prefer to use a normal user.

    – user918546
    7 hours ago











  • As you say, the easiest way is doing as root on both sides. I also do not feel confy doing it.

    – Rui F Ribeiro
    6 hours ago











  • @Bananguin & all sshd_config : PermitTunnel ... Independent of this setting ... device must allow access to the user. so seems possible as non root. what about SELinux/Apparmor ?

    – A.B
    4 hours ago














1












1








1








I would like to connect 2 tap-devices. The tap-device on the remote server is owned by "user". This is my test-command:



# ssh -oTunnel=ethernet -w0:0 user@server


But it does not work, I get this error:



channel 0: open failed: administratively prohibited: open failed


How could I solve this problem?



distro: openSUSE, location: France










share|improve this question









New contributor




user918546 is a new contributor to this site. Take care in asking for clarification, commenting, and answering.
Check out our Code of Conduct.












I would like to connect 2 tap-devices. The tap-device on the remote server is owned by "user". This is my test-command:



# ssh -oTunnel=ethernet -w0:0 user@server


But it does not work, I get this error:



channel 0: open failed: administratively prohibited: open failed


How could I solve this problem?



distro: openSUSE, location: France







ssh-tunneling privileges






share|improve this question









New contributor




user918546 is a new contributor to this site. Take care in asking for clarification, commenting, and answering.
Check out our Code of Conduct.











share|improve this question









New contributor




user918546 is a new contributor to this site. Take care in asking for clarification, commenting, and answering.
Check out our Code of Conduct.









share|improve this question




share|improve this question








edited 6 hours ago









Rui F Ribeiro

39.5k1479133




39.5k1479133






New contributor




user918546 is a new contributor to this site. Take care in asking for clarification, commenting, and answering.
Check out our Code of Conduct.









asked 9 hours ago









user918546user918546

62




62




New contributor




user918546 is a new contributor to this site. Take care in asking for clarification, commenting, and answering.
Check out our Code of Conduct.





New contributor





user918546 is a new contributor to this site. Take care in asking for clarification, commenting, and answering.
Check out our Code of Conduct.






user918546 is a new contributor to this site. Take care in asking for clarification, commenting, and answering.
Check out our Code of Conduct.








  • 1





    Hi. What distro and location?

    – Time4Tea
    9 hours ago











  • I am little confused. I was about to answer "not" because I remember it once said in the man page that you require root privileges on your client to create a tun or tap device, but I cant find that remark i neither ssh nor ssh_config man pages. So I guess I don't have an answer for you. :-(

    – Bananguin
    7 hours ago






  • 1





    The tap already exists and is owned by the user. ssh just has to attach to it. As root, there is no problem, but I prefer to use a normal user.

    – user918546
    7 hours ago











  • As you say, the easiest way is doing as root on both sides. I also do not feel confy doing it.

    – Rui F Ribeiro
    6 hours ago











  • @Bananguin & all sshd_config : PermitTunnel ... Independent of this setting ... device must allow access to the user. so seems possible as non root. what about SELinux/Apparmor ?

    – A.B
    4 hours ago














  • 1





    Hi. What distro and location?

    – Time4Tea
    9 hours ago











  • I am little confused. I was about to answer "not" because I remember it once said in the man page that you require root privileges on your client to create a tun or tap device, but I cant find that remark i neither ssh nor ssh_config man pages. So I guess I don't have an answer for you. :-(

    – Bananguin
    7 hours ago






  • 1





    The tap already exists and is owned by the user. ssh just has to attach to it. As root, there is no problem, but I prefer to use a normal user.

    – user918546
    7 hours ago











  • As you say, the easiest way is doing as root on both sides. I also do not feel confy doing it.

    – Rui F Ribeiro
    6 hours ago











  • @Bananguin & all sshd_config : PermitTunnel ... Independent of this setting ... device must allow access to the user. so seems possible as non root. what about SELinux/Apparmor ?

    – A.B
    4 hours ago








1




1





Hi. What distro and location?

– Time4Tea
9 hours ago





Hi. What distro and location?

– Time4Tea
9 hours ago













I am little confused. I was about to answer "not" because I remember it once said in the man page that you require root privileges on your client to create a tun or tap device, but I cant find that remark i neither ssh nor ssh_config man pages. So I guess I don't have an answer for you. :-(

– Bananguin
7 hours ago





I am little confused. I was about to answer "not" because I remember it once said in the man page that you require root privileges on your client to create a tun or tap device, but I cant find that remark i neither ssh nor ssh_config man pages. So I guess I don't have an answer for you. :-(

– Bananguin
7 hours ago




1




1





The tap already exists and is owned by the user. ssh just has to attach to it. As root, there is no problem, but I prefer to use a normal user.

– user918546
7 hours ago





The tap already exists and is owned by the user. ssh just has to attach to it. As root, there is no problem, but I prefer to use a normal user.

– user918546
7 hours ago













As you say, the easiest way is doing as root on both sides. I also do not feel confy doing it.

– Rui F Ribeiro
6 hours ago





As you say, the easiest way is doing as root on both sides. I also do not feel confy doing it.

– Rui F Ribeiro
6 hours ago













@Bananguin & all sshd_config : PermitTunnel ... Independent of this setting ... device must allow access to the user. so seems possible as non root. what about SELinux/Apparmor ?

– A.B
4 hours ago





@Bananguin & all sshd_config : PermitTunnel ... Independent of this setting ... device must allow access to the user. so seems possible as non root. what about SELinux/Apparmor ?

– A.B
4 hours ago










0






active

oldest

votes











Your Answer








StackExchange.ready(function() {
var channelOptions = {
tags: "".split(" "),
id: "106"
};
initTagRenderer("".split(" "), "".split(" "), channelOptions);

StackExchange.using("externalEditor", function() {
// Have to fire editor after snippets, if snippets enabled
if (StackExchange.settings.snippets.snippetsEnabled) {
StackExchange.using("snippets", function() {
createEditor();
});
}
else {
createEditor();
}
});

function createEditor() {
StackExchange.prepareEditor({
heartbeatType: 'answer',
autoActivateHeartbeat: false,
convertImagesToLinks: false,
noModals: true,
showLowRepImageUploadWarning: true,
reputationToPostImages: null,
bindNavPrevention: true,
postfix: "",
imageUploader: {
brandingHtml: "Powered by u003ca class="icon-imgur-white" href="https://imgur.com/"u003eu003c/au003e",
contentPolicyHtml: "User contributions licensed under u003ca href="https://creativecommons.org/licenses/by-sa/3.0/"u003ecc by-sa 3.0 with attribution requiredu003c/au003e u003ca href="https://stackoverflow.com/legal/content-policy"u003e(content policy)u003c/au003e",
allowUrls: true
},
onDemand: true,
discardSelector: ".discard-answer"
,immediatelyShowMarkdownHelp:true
});


}
});






user918546 is a new contributor. Be nice, and check out our Code of Conduct.










draft saved

draft discarded


















StackExchange.ready(
function () {
StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2funix.stackexchange.com%2fquestions%2f495259%2fssh-ethernet-tunneling-as-normal-user%23new-answer', 'question_page');
}
);

Post as a guest















Required, but never shown

























0






active

oldest

votes








0






active

oldest

votes









active

oldest

votes






active

oldest

votes








user918546 is a new contributor. Be nice, and check out our Code of Conduct.










draft saved

draft discarded


















user918546 is a new contributor. Be nice, and check out our Code of Conduct.













user918546 is a new contributor. Be nice, and check out our Code of Conduct.












user918546 is a new contributor. Be nice, and check out our Code of Conduct.
















Thanks for contributing an answer to Unix & Linux Stack Exchange!


  • Please be sure to answer the question. Provide details and share your research!

But avoid



  • Asking for help, clarification, or responding to other answers.

  • Making statements based on opinion; back them up with references or personal experience.


To learn more, see our tips on writing great answers.




draft saved


draft discarded














StackExchange.ready(
function () {
StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2funix.stackexchange.com%2fquestions%2f495259%2fssh-ethernet-tunneling-as-normal-user%23new-answer', 'question_page');
}
);

Post as a guest















Required, but never shown





















































Required, but never shown














Required, but never shown












Required, but never shown







Required, but never shown

































Required, but never shown














Required, but never shown












Required, but never shown







Required, but never shown







Popular posts from this blog

Loup dans la culture

How to solve the problem of ntp “Unable to contact time server” from KDE?

Connection limited (no internet access)