Welcome to the VanDyke Software Forums

Join the discussion today!

Go Back   VanDyke Software Forums > General


Thread Tools Display Modes
Old 09-08-2020, 04:50 PM
mr.dk mr.dk is offline
Registered User
Join Date: Nov 2016
Posts: 16
Unhappy Ignored - Port Forward Filter - Version 8.7.3


Not sure if I'm doing this correctly...
SecureCRT - Version 8.7.3 (x64 build 2279)

I'm trying to allow another guest to access the SecureCRT local port forwarding.

[PC (A) TELNET] -- > [PC (B) SecureCRT port 6200 ] -- > [Server Port 6200]

I have setup port forwarding from PC (B) to the server ... however from reading and testing i can see the listen port Reading I see that I will need to further modify <session>.ini and modify the following...


S:"Port Forward Filter"=allow,,0 deny,,0
S:"Reverse Forward Filter"=allow,,0 deny,,0


S:"Port Forward Filter"=allow,,0 allow,,6200
S:"Reverse Forward Filter"=allow,,0 allow,,6200

However testing ( and logging ) I can verify the port is only opened for listening on and not to allow for connections?

I also tested changing the,0 to,0 <- and the port remained open on and did not move to as expected. Thus from the data it seems this version of SecureCRT does not work as intended OR am I just missing configuration needed?

Working Log:
telnet 6200

Welcome to Microsoft Telnet Client Escape Character is 'CTRL+]'

[LOCAL] : Starting port forward from on local to remote wtllab-productlicense-1.phaedrus.sandvine.com:6200.
[LOCAL] : SEND[1]: Send SSH_MSG_CHANNEL_OPEN("direct-tcpip")
[LOCAL] : SEND[1]: channel close
[LOCAL] : RECV[1]: channel close.
[LOCAL] : RECV[1]: SSH_MSG_CHANNEL_CLOSE, closing socket.

Non-Working Log:

telnet 6200
Connecting To not open connection to the host, on port 6200: Connect failed


^^ Nothing

Hummm .... Any thoughts?

Thank you.

OS Name Microsoft Windows 10 Pro
Version 10.0.14393 Build 14393
Processor Intel(R) Core(TM) i7-6700K CPU @ 4.00GHz, 4001 Mhz, 4 Core(s), 8 Logical Processor(s)
Installed Physical Memory (RAM) 64.0 GB
SecureCRT Version 8.7.0 (x64 build 1183) - Official Release - September 8, 2016
Reply With Quote
Old 09-08-2020, 06:24 PM
jjh jjh is offline
VanDyke Customer Support
Join Date: Feb 2004
Posts: 815
Hello mr.dk.

When you configure standard SSH2 port forwarding in your session, you are configuring SecureCRT to listen on the specified port and forward the traffic along through the SSH2 server that you are connected to, to the target machine.

So for example, if you are connected to a server named "Server1" with your SecureCRT session and the machine that uses port 6200 is on a machine named "Server2", you would connect to localhost on port 6200 and the traffic would be forwarded through Server1 and end up at server2.

The default port forward filter looks like the following, which would allow the traffic from the local loopback addresses in the range:

S:"Port Forward Filter"=allow,,0 deny,,0

All other IP addresses would be denied.

I would expect that if you edited the port forward filter to look like the following, the IP address would be allowed on all ports:

S:"Port Forward Filter"=allow,,0 allow,,0 deny,,0

I would not recommend the change that you made to the reverse forward filter.

I would have expected the change that you made to be successful, but it seems too permissive. The "Allow" that you made for would be redundant because you are already allowing connections from all IP addresses on all ports.

The other part of the problem you are experiencing is that SecureCRT is listening on the local loopback address only (IP address, which is only accessible to the local machine. You will need to change the port forward settings to listen on (all IP addresses that belong to your machine, both the localhost IP addresses and the LAN private IP address), so that other machines on the network will have access to the port forward.

In the "Local" section of the "Local port forward properties" dialog you can enable the "Manually select local IP address on which to allow connections", then enter as the IP address.

I have attached a screenshot of what I am referring to.

What does your port forward look like for the session?

Thank you.

Attached Images
File Type: png SCRT_LocalPortForwardingConfigurationExample.png (392.7 KB, 268 views)

Last edited by jjh; 09-11-2020 at 01:32 PM. Reason: Edited to provide more information
Reply With Quote

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump

All times are GMT -6. The time now is 06:05 AM.