Skip to content

Allow teleport administrator to restrict which ports are allowed to be forwarded #32504

Open

Description

This is a feature request for the addition of equivalent functionality to the PermitOpen sshd_config option in Teleport. The purpose of this feature is to limit what ports a user can forward when port forwarding is allowed.

Currently, Teleport allows enabling or disabling TCP port forwarding. However, it does not currently offer a feature allowing restrictions on specific ports during port forwarding. This feature would be a beneficial addition to the existing functionality of Teleport.

Even though a user would still have the ability to sidestep the restriction, it would create a barrier that they would need to intentionally bypass, which can be helpful in a multi-layered security approach.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Assignees

No one assigned

    Labels

    c-haInternal Customer Referencefeature-requestUsed for new features in Teleport, improvements to current should be #enhancementsssh

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions