-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Jerry Westrick wrote:
Yes, you can turn off the tunneling in /etc/ssh/sshd_config with the parameter "AllowTcpForwarding no"
Please see man:/sshd_config (Type that URL in Konqueror, for a decent formatting of the man page). See comments about this parameter...
Jerry
Thanks for the suggestion. I try it since yesterday, though not look to the result yet. For James, thanks also for suggestion, but I try to avoid to eliminate specific address from within the firewall. Our user still use ssh for other task to the server though. edwin -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.0 (MingW32) iD8DBQFEPGEqkaMcq796kjoRApnzAKC5dT1xXklEJHKToCf4AY6Lx8YTIACfSxu/ rh8Yur+l4gmHTW9PoPaoyOE= =51cB -----END PGP SIGNATURE-----