how sps works combination of session-shell and local forward options

Hello,
If you organize the following scheme:

User(connect via ssh socks) --> SPS (enabled options for User: session-shell & local forward) --> Jump --> (remote server 1 & remote server 2)

SPS has session-shell and local forward options enabled for the User, what information can we record when setting these options?

I think SPS will record the session-shell terminal, but given that the user is connecting via ssh socks. SPS won't be able to see all user traffic and will it record raw data?

Parents Reply
  • I looked into this further and found another case where Safeguard Desktop Player did not replay forwarded SSH channels, except x11. The reason is that the software cannot be prepared to parse any custom traffic in those channels as you can forward theoretically any communication over the network, and the player would not support such undefined scenarios.

    You can however use the PCAP export option, which is in Safeguard Desktop Player, under Export / Export pcap and you'll get the raw network data from all channels for further processing.

    Thanks!

Children
No Data