Pre-condition for ssh reverse tunnel
- The current computer that you have can connect to port 12000 (or any other) on the middle server.
- The middle is running an ssh daemon willing to do port-forwarding (enabled by default in OpenSSH) and the GatewayPorts feature is enabled
- You can open an ssh connection from target to the middle in advance and leave it open.
- The SSH daemon is running on target on port 22. In fact the port can be arbitrary and the daemon does not have to allow port forwarding. You can even establish your own (not root) ssh daemon.
- Create a tunnel from middle to target and leave it open when you are still at the office. You cn also ask your colleague at the office to do this. The below command will open port 12000 on middle for listening and forward all request on port 12000 on middle to port 22 of target
- user@target $ ssh -R 12000:localhost:22 middleuser@middle
- Now you can access to port 12000 on middle from current and you will be forwarded to port 22 on target
- user@current $ ssh targetuser@middle -p 12000
- If somehow you cannot access, access middle first, then connect to port 12000 of localhost
- user@current $ ssh middleuser@middle
- user@middle $ ssh targetuser@localhost -p 12000
- You are now in the target server
Nice article you got here. It would be great to read more about this matter. Thank you for sharing that info.
ReplyDeleteSexy Lady
Escort London