Enabling port forwarding over SSH when it's "administratively prohibited"
blog.computers.pictures
blog.computers.pictures
Hardening in sshd_config to prevent arbitrary network access behind the firewall where the firewall would otherwise not permit. If one can get around this then the host itself may be missing proper outbound owner-based firewall rules varies by compliance requirements.
Another option to read up on is "Match" which can modify options for specific users, groups, networks or ports. For example we can disable port forwarding for Bob and enable port forwarding for Alice.
To further limit what that host can talk to one can use the Netfilter "owner" module to limit outbound connections by user or group. So for example only the LDAP user can talk to the LDAP server.
# sshd -T | grep permit[l-o]
permitopen 10.10.1.1:80
permitlisten 10.10.1.1:80
Each org may have different audit and regulatory requirements that determine which if any of these options are utilized. Development orgs and small startups rarely use any of them due to perception of friction.[1] - https://man7.org/linux/man-pages/man5/sshd_config.5.html