3 ms·
I wish I could use mosh, but unfortunately it can't use ProxyJump to tunnel through a bastion host which is how I always use SSH, which makes sense as it's use
by ilovecaching 4y ago
I wish I could use mosh, but unfortunately it can't use ProxyJump to tunnel through a bastion host which is how I always use SSH, which makes sense as it's use Proxy commands itself.
- loeg 4y agoMosh runs directly over UDP, and that's sort of essential to how it works, which is why it can't run through a (SSH + TCP) proxy host.
- LinuxBender 4y agoThere is a way [1] but the first hop will be ssh/tcp which may defeat the point of doing this if the first hop has high loss or the IP changes constantly. ncat from nmap can also be used within SSH vs their suggested fifo method. Both have some caveats. Here [2] is some further discussion. [1] - https://superuser.com/questions/53103/udp-traffic-through-ssh-tunnel https://superuser.com/questions/53103/udp-traffic-through-ss... [2] - https://teddit.sethforprivacy.com/r/linuxadmin/comments/xeqpc9/udp_tunneling_over_reverse_ssh_netcatsocat_not/ https://teddit.sethforprivacy.com/r/linuxadmin/comments/xeqp...
- loeg 4y agoYeah, I think that defeats much of the purpose of using mosh. :)
- LinuxBender 4y agoAgreed. I think the only use cases would be that your fist hop is stable but you want to proxy to another region over a lossy link but I can't imagine that would be very common. Maybe when using a satellite link or a inter-continental connection has a single over-saturated link but that would be a very fringe case. Perhaps when Starlink gets over-subscribed that could be a case.
- rollcat 4y agoI have very mixed feelings about bastion hosts in general. It usually feels like moving the problem around, eventually you end up adding even more complexity just to do your job. Wireguard (or Zerotier/Tailscale, depending on your threat model) might end up being simpler. Complex is the enemy of secure - if it's hard to use, then it's easy to make a mistake.
- cgb_ 4y agoI tend to agree with you, but we don't always have control over the networks we access, and fitting in with other org's policies is often required. ProxyJump is very handy for that.