A web application on your laptop listens on 127.0.0.1:3000. Your laptop can reach the shared host halof, but a colleague can only reach halof and not your laptop. halof's sshd is configured with GatewayPorts yes. You want the colleague to open the application as halof:8585. Which command, run from your laptop, sets that up?

LPIC-1 Exam 102-500, objective 110. Security hard

Machine-checked — no person has signed for it. This question was read against the source cited below by an automated pass, which found no contradiction. That is a weaker claim than it sounds: the same kind of process wrote the question, so it can confirm its own mistake.

Treat it as a good draft rather than as settled fact, and read the source below before you rely on it. It is not used in mock exams here — only questions a person has signed for are.

How these questions are written — where each question comes from, what the verification ledger records, and what happens when one is found wrong.

The options

Correct ssh -R 8585:localhost:3000 user@halof

Correct. -R asks the remote host to listen on port 8585 and to send anything arriving there back down the SSH connection, where the local client hands it to localhost:3000 on your laptop.

Not correct ssh -L 8585:localhost:3000 user@halof

Wrong direction. -L opens the listening port on your laptop and forwards to a destination reached from halof, so it would let you talk to something on halof, not the other way round.

Not correct ssh -L 3000:halof:8585 user@halof

Wrong. This is again a local forward: it would try to open port 3000 on your laptop, which the application itself already occupies, and forward onward to halof:8585, where nothing is listening. Nothing is published on halof either way.

Not correct ssh -D 8585 user@halof

Wrong. -D creates a SOCKS proxy on your laptop's port 8585, through which your own applications can reach anything halof can reach. It publishes nothing on halof.

Why

Read a forwarding specification as listen:destination_host:destination_port and then ask which end does the listening: -L listens locally, -R listens on the remote host. In both cases the destination is resolved by the machine at the far end of the tunnel, which is why localhost in a -R specification means the laptop. By default sshd binds a remote forward to the remote loopback only, so reaching halof:8585 from a third machine also needs GatewayPorts yes in /etc/ssh/sshd_config.

Where this comes from

Cited
manual page ssh(1)

Practise this

Reading one question is not practice. The trainer will draw a short set from objective 110 and space the ones you get wrong.

Practise LPIC-1 Exam 102-500

More questions on this objective

All questions on Security

Practise LPIC-1 Exam 102-500