Forum Moderators: bakedjake
Thank you so much for the help (You guys are more help than the tech support from my ISP!)
-Phil
PS. If you allow port forwarding with ssh users whose shell is /bin/false will still be able to do port forwarding. Just wanted to let you know that as I though they woulndn't be able to.
Before you go adding /bin/false to the list, though, I suggest you make a copy of /bin/false called "/bin/ftponly" instead. Put that in /etc/shells, and assign it to the FTP only users. That way you know who your FTP users are, and can still use /bin/false to deny ftp and shell.
Sean