3 ms·
Both of the comments about VPN support within SSH seem to be heavily downvoted with no reason why. As far as I can see, their points are correct: > OpenSSH ha
by codefined 9y ago
Both of the comments about VPN support within SSH seem to be heavily downvoted with no reason why. As far as I can see, their points are correct:
> OpenSSH has built-in TUN/TAP support using -w<local-tun-number>:<remote-tun-number>. Here, a layer 3/point-to-point/ TUN tunnel is described. It is also possible to create a layer 2/ethernet/TAP tunnel.[0]
Just with invalid terminology (s/ssh/OpenSSH) and the likelihood of the added slowdown mentioned in the article.
[0] https://wiki.archlinux.org/index.php/VPN_over_SSH https://wiki.archlinux.org/index.php/VPN_over_SSH
- lloeki 9y agoThis is one of those Arch wiki pages that I find lacking, so I personally always refer to the man pages: man 1 ssh: -w local_tun[:remote_tun] Requests tunnel device forwarding with the specified tun(4) devices between the client (local_tun) and the server (remote_tun). The devices may be specified by numerical ID or the keyword ``any'', which uses the next available tunnel device. If remote_tun is not specified, it defaults to ``any''. See also the Tunnel and TunnelDevice directives in ssh_config(5). If the Tunnel directive is unset, it is set to the default tunnel mode, which is ``point-to-point''. man 5 ssh_config: Tunnel Request tun(4) device forwarding between the client and the server. The argument must be yes, point-to-point (layer 3), ethernet (layer 2), or no (the default). Specifying yes requests the default tunnel mode, which is point-to-point. TunnelDevice Specifies the tun(4) devices to open on the client (local_tun) and the server (remote_tun). The argument must be local_tun[:remote_tun]. The devices may be specified by numerical ID or the keyword any, which uses the next available tunnel device. If remote_tun is not specified, it defaults to any. The default is any:any. man 5 sshd_config: PermitTunnel Specifies whether tun(4) device forwarding is allowed. The argu- ment must be yes, point-to-point (layer 3), ethernet (layer 2), or no. Specifying yes permits both point-to-point and ethernet. The default is no. Independent of this setting, the permissions of the selected tun(4) device must allow access to the user.