4 ms·
SSH tunnels adds hassle to deploy and maintain. Compared to openvpn once your server is up you just need to deploy software and install certs and byebye! It is
by askz 9y ago
SSH tunnels adds hassle to deploy and maintain. Compared to openvpn once your server is up you just need to deploy software and install certs and byebye! It is my prefered solution for devices since it takes 5min to deploy. And you have instant access to all ports of the device(s)
- drchickensalad 9y agoSsh local forwarding gives you pretty simple access to all ports though?
- magnetic 9y agoYes, but: 1) you have to know which ports you want to forward before you ssh into the remote host and 2) you have to change configurations (hostname and ports) in all the programs you use (for example, instead of pointing your browser to http://foo http://foo, you're going to have to go and type http://localhost:8888 http://localhost:8888 - not to mention all the scripts or other pieces of software that "just work" using the canonical name and standardized port to connect, and would require customizations to change that)
- Fnoord 9y agoWith Sshuttle you got access to all TCP ports. You can add hosts in /etc/hosts, ~/.ssh/ssh_config, /etc/ssh/ssh_config, dnsmasq, or aliases in your favourite shell. If you prefer port 80 and it is being used on local host already you can manually do what ZeroTier does: add a /32 or /128 to an interface and route it. I just tried ZeroTier yesterday and it is nice indeed, basically an advanced, open source Hamachi. But it is not rocket science. What I especially like is that you can completely self host.
- rsync 9y ago"SSH tunnels adds hassle to deploy and maintain." Agreed. That is why I love sshuttle: https://github.com/sshuttle/sshuttle https://github.com/sshuttle/sshuttle Any host that is running plain old sshd is now a potential VPN endpoint. No config or settings (or even permission) necessary. Supports --dns.