Reverse SSH Tunnel: Difference between revisions

From Leo's Notes
This page was last edited on 15 June 2023, at 16:27.
Created page with "Suppose you are inside a network that has no public IP address. If you are working on machineA, and you need to SSH in from outside the network, say from machineB, run the fol..."
 
No edit summary
 
(6 intermediate revisions by the same user not shown)
Line 1: Line 1:
Read more about [[SSH#Tunnels|other types of SSH tunnels]].
=== Quick summary ===
Suppose you are inside a network that has no public IP address. If you are working on machineA, and you need to SSH in from outside the network, say from machineB, run the following on machineA:
Suppose you are inside a network that has no public IP address. If you are working on machineA, and you need to SSH in from outside the network, say from machineB, run the following on machineA:


machineA$ ssh -R 22222:localhost:22 user@machineB
{{highlight|lang=terminal|code=
machineA$ ssh -R 22222:localhost:22 user@machineB
}}


On machineB, you can now SSH to machineA by running:
On machineB, you can now SSH to machineA by running:
{{highlight|lang=terminal|code=
machineB$ ssh user@localhost -p 22222
}}
The first command creates a SSH tunnel which will listen on <code>127.0.0.1:22222</code> on machineB that tunnels to <code>localhost:22</code> on machineA.  You should now be able to access <code>machineB:22</code> by connecting to <code>127.0.0.1:22222</code> on machineA.
You can make the tunnel target a remote host by replacing {{code|localhost}} with another server.
You may make the tunnel bind on all addresses instead of {{code|127.0.0.1}} by ensuring that {{code|1=GatewayPorts = yes}} or {{code|1=GatewayPorts = clientspecified}} on machineB's SSH server and then specifying the bind address when connecting. Eg.
{{highlight|lang=terminal|code=
machineA$ ssh -R 0.0.0.0:22222:localhost:22 user@machineB
}}
=== SSH reverse tunnel with Systemd ===
I use the following reverse SSH tunnel service file to start the SSH reverse tunnel. This is useful if the server you're working on is behind half a dozen firewalls. Make sure to change the path to the private key, the desired tunnel port, and the server.
{{Highlight
| code = # cat <<EOF >/etc/systemd/system/ssh-reverse.service
[Unit]
Description=SSH Reverse Tunnel
After=network-online.target
Wants=network-online.target
After=sshd.service


machineB$ ssh user@localhost -p 22222
[Service]
Type=simple
User=root
ExecStart=/bin/bash -c "/usr/bin/ssh -i /home/leo/.ssh/id_rsa -N -R 42069:localhost:22 leo@home.server"
RestartSec=300
Restart=always


The first command creates a SSH tunnel which opens port 22222 on machineB that tunnels to machineA:22. You may extend this by replacing localhost with another host on the internal network in order to SSH in remotely to another host.
[Install]
WantedBy=multi-user.target
EOF
# systemctl daemon-reload
# systemctl start ssh-reverse
# systemctl enable ssh-reverse
| lang = terminal
}}


{{Navbox Linux}}
[[Category:Linux]]
[[Category:Linux]]

Latest revision as of 16:27, 15 June 2023

Read more about other types of SSH tunnels.

Quick summary

Suppose you are inside a network that has no public IP address. If you are working on machineA, and you need to SSH in from outside the network, say from machineB, run the following on machineA:

machineA$ ssh -R 22222:localhost:22 user@machineB

On machineB, you can now SSH to machineA by running:

machineB$ ssh user@localhost -p 22222

The first command creates a SSH tunnel which will listen on 127.0.0.1:22222 on machineB that tunnels to localhost:22 on machineA. You should now be able to access machineB:22 by connecting to 127.0.0.1:22222 on machineA.

You can make the tunnel target a remote host by replacing localhost with another server.

You may make the tunnel bind on all addresses instead of 127.0.0.1 by ensuring that GatewayPorts = yes or GatewayPorts = clientspecified on machineB's SSH server and then specifying the bind address when connecting. Eg.

machineA$ ssh -R 0.0.0.0:22222:localhost:22 user@machineB

SSH reverse tunnel with Systemd

I use the following reverse SSH tunnel service file to start the SSH reverse tunnel. This is useful if the server you're working on is behind half a dozen firewalls. Make sure to change the path to the private key, the desired tunnel port, and the server.

# cat <<EOF >/etc/systemd/system/ssh-reverse.service
[Unit]
Description=SSH Reverse Tunnel
After=network-online.target
Wants=network-online.target
After=sshd.service

[Service]
Type=simple
User=root
ExecStart=/bin/bash -c "/usr/bin/ssh -i /home/leo/.ssh/id_rsa -N -R 42069:localhost:22 leo@home.server"
RestartSec=300
Restart=always

[Install]
WantedBy=multi-user.target
EOF
# systemctl daemon-reload
# systemctl start ssh-reverse
# systemctl enable ssh-reverse