Port Forwarding an inbound SSH connection request on Sonicwall TZ210

Canadacorps1

Commendable
Oct 26, 2016
6
0
1,510
Hi there, I need to configure port forwarding (for an Inbound SSH connection) from the Public IP of our network to a target device (private IP) on our network. I have a Sonicwall TZ210 router. I'm not sure how to do this... I have enough knowledge of networking to be dangerous, which is why I'm asking for advice and not attempting this myself without guidance. Any help or a guide would be appreciated.
 

gbb0330

Reputable
Apr 28, 2015
1,498
0
5,960
log into sonicwall
on the lefthand side click on firewall -> address objects. create address object for device on the local network (private IP)
on the lefthand side click on firewall -> access rules -> add

from WAN to LAN
destination is the address object created in first step
SSH is a standard service, should be listed under Service
 

Canadacorps1

Commendable
Oct 26, 2016
6
0
1,510


What should the source be if I want to access this device from outside my network?
 

gbb0330

Reputable
Apr 28, 2015
1,498
0
5,960


any IP
unless you are accessing it from a location with a static IP. in this case you can specify the source IP address, its more secure.
 

Canadacorps1

Commendable
Oct 26, 2016
6
0
1,510


So I've completed this, but when I try to use a terminal application, such as Tera-term with connection pointed at my public IP specifying TCP connection on Port 22, I still run into the login prompt for the router itself, instead of the port forwarding passing me through the network to the device I want...
 

gbb0330

Reputable
Apr 28, 2015
1,498
0
5,960
try putty instead
P.S.
if the router has SSH, you are going to have to make some changes, either use a different port for router or internal device, or use different public IP (if you have more than 1) for the internal device
 

Canadacorps1

Commendable
Oct 26, 2016
6
0
1,510
Nope. Is it possible that there could be some kind of conflicting setting that may be pre-empting this? Like a stock management setting that tells it to manage the router via SSH that pre-empts my other rule?
 

gbb0330

Reputable
Apr 28, 2015
1,498
0
5,960


yes. if the router has SSH, you are going to have to make some changes, either use a different port for router or internal device, or use different public IP (if you have more than 1) for the internal device
 

Canadacorps1

Commendable
Oct 26, 2016
6
0
1,510
So it turns out the problem is that the router has SSH management on port 22 but the internal device also uses management on port 22.. So I need to setup a different port to access on the router that forwards to port 22 of the destination device inside the network. Problem is, I have zero expertise with Sonicwall routers...
 

gbb0330

Reputable
Apr 28, 2015
1,498
0
5,960


you have several options.
create a custom service, port 222 from outside will go to port 22 on the inside.
another option is to change router's management port
third option is to change the internal device port
may have to do some reading, some trial and error, but its doable. other option is to pay someone to do it for you