3 ms·
found a couple of cool tricks in the article, mainly using the -t flag to set up a chain of servers to pass through when machines are NATed or firewalled. Seem
by stenius 16y ago
found a couple of cool tricks in the article, mainly using the -t flag to set up a chain of servers to pass through when machines are NATed or firewalled.
Seems kind of weird in the tunnel section that the -D flag was not mentioned which creates a dynamic tunnel that can go to multiple hosts when set up as a socks proxy in a web browser.
- mcmatterson 16y agoShame on me for not reading that section in closer detail. The -t method of forwarding SSH through has a number of limitations, and isn't really the golden path for getting past gateway servers. What you instead want to do is add the following as a config option for the host you're trying to reach: "ProxyCommand ssh <gateway_machine> nc %h %p" You can do this by adding the above line in the relevant place in ~/.ssh/config, or on the command line like so: ssh -o "ProxyCommand ssh <gateway_machine> nc %h %p" user@destination_machine
- ernesth 16y agoIn fact what you really want is not to use nc but ssh's -W option: ProxyCommand ssh -W %h:%p <gateway_machine
- mcmatterson 16y agoInteresting -- I did not know about this one. Looks like it was implemented in OpenSSH 5.4, which isn't yet in Ubuntu LTS or OS X (the two environments where I spend most of my days), so it may be a little bleeding edge for general use just yet. Good to know, however.