I want to be able to offer SSH accounts on my Linux server for people to be able to use for SSH tunnelling. All accounts will be locked down with no interactive shell, for tunnelling / port forwarding purposes only. My problem is that I don't want them to be able to access services that are bound to localhost only by doing port forwards like the following:
ssh account@server -L 9999:127.0.0.1:3306 & telnet localhost 9999
This would give them access to the default MySQL database port. How can I stop this?
I see options in the configuration file for OpenSSH to allow specific ports/hosts, but not to block them. Any help would be greatly appreciated!