tunnel port 8080 over jumpserver using ssh - socks5 proxy?setting up a proxy to mirror an SSH SOCKS connectionNoMachine over SSH/Netcat proxySSH tunnel as proxy - no data returnedReverse SSH tunnel: how can I send my port number to the server?port forwarding with socks over proxyAccessing a host's SSH tunnel from a guest VM in VMWare FusionSSH Tunneling and LAMP at same timehow to setup a ssh tunnel while remote server itself has to configure http_proxy to access webpage?How to debug a SSH socks tunnel connection?how to tunnel SOCKS proxy?
Looking after a wayward brother in mother's will
Creating Fictional Slavic Place Names
Can I ask a publisher for a paper that I need for reviewing
Why is Colorado so different politically from nearby states?
If a massive object like Jupiter flew past the Earth how close would it need to come to pull people off of the surface?
what's the equivalent of helper in LWC?
What is the most important characteristic of New Weird as a genre?
What is the right way to float a home lab?
Strange math syntax in old basic listing
Why does my electric oven present the option of 40A and 50A breakers?
Why does the UK have more political parties than the US?
Do adult Russians normally hand-write Cyrillic as cursive or as block letters?
Slide Partition from Rowstore to Columnstore
How to detach yourself from a character you're going to kill?
The qvolume of an integer
Elegant way to prove congruence
What TV show or movie did I watch on TV years ago where diseased people are exiled to a spaceship?
Why is there a need to modify system call tables in Linux?
What is a simple, physical situation where complex numbers emerge naturally?
Opposite of "Squeaky wheel gets the grease"
Modern approach to radio buttons
What if you don't bring your credit card or debit for incidentals?
Is there a term for this?
Accidentally cashed a check twice
tunnel port 8080 over jumpserver using ssh - socks5 proxy?
setting up a proxy to mirror an SSH SOCKS connectionNoMachine over SSH/Netcat proxySSH tunnel as proxy - no data returnedReverse SSH tunnel: how can I send my port number to the server?port forwarding with socks over proxyAccessing a host's SSH tunnel from a guest VM in VMWare FusionSSH Tunneling and LAMP at same timehow to setup a ssh tunnel while remote server itself has to configure http_proxy to access webpage?How to debug a SSH socks tunnel connection?how to tunnel SOCKS proxy?
.everyoneloves__top-leaderboard:empty,.everyoneloves__mid-leaderboard:empty,.everyoneloves__bot-mid-leaderboard:empty height:90px;width:728px;box-sizing:border-box;
I have this setup:
LocalPC - Jumpserver - Webserver with page only accessible on this machine via
localhost:8080
LocalPC and Webserver are not connected - Jumpserver has to be used.
Jumpserver doesn't have access to the Webpage on Webserver
I want to use Firefox to view this webpage on LocalPC.
I know how to make socks proxy to Jumpserver - normally this is enough but not in this case
ssh -TD 8080 me@jumpserver
and
I know how to tunnel one specific port over Jumpserver
ssh -f -N -q -L 2222:me@target:22 me@jumpserver
But using the first method only makes a tunnel to Jumpserver and using the second method with ports 8081:me@webserver:8080 doesn't give error but results in 404 for
http://localhost:8081
in firefox...
So how will I see the website on LocalPC?
And for security reasons:
I need both connections encrypted and let no other users on Jumpserver use the tunnel.
(Sry for codeblocks - I am not allowed to write word localhost...)
web-server ssh-tunnel dmz socks
add a comment |
I have this setup:
LocalPC - Jumpserver - Webserver with page only accessible on this machine via
localhost:8080
LocalPC and Webserver are not connected - Jumpserver has to be used.
Jumpserver doesn't have access to the Webpage on Webserver
I want to use Firefox to view this webpage on LocalPC.
I know how to make socks proxy to Jumpserver - normally this is enough but not in this case
ssh -TD 8080 me@jumpserver
and
I know how to tunnel one specific port over Jumpserver
ssh -f -N -q -L 2222:me@target:22 me@jumpserver
But using the first method only makes a tunnel to Jumpserver and using the second method with ports 8081:me@webserver:8080 doesn't give error but results in 404 for
http://localhost:8081
in firefox...
So how will I see the website on LocalPC?
And for security reasons:
I need both connections encrypted and let no other users on Jumpserver use the tunnel.
(Sry for codeblocks - I am not allowed to write word localhost...)
web-server ssh-tunnel dmz socks
add a comment |
I have this setup:
LocalPC - Jumpserver - Webserver with page only accessible on this machine via
localhost:8080
LocalPC and Webserver are not connected - Jumpserver has to be used.
Jumpserver doesn't have access to the Webpage on Webserver
I want to use Firefox to view this webpage on LocalPC.
I know how to make socks proxy to Jumpserver - normally this is enough but not in this case
ssh -TD 8080 me@jumpserver
and
I know how to tunnel one specific port over Jumpserver
ssh -f -N -q -L 2222:me@target:22 me@jumpserver
But using the first method only makes a tunnel to Jumpserver and using the second method with ports 8081:me@webserver:8080 doesn't give error but results in 404 for
http://localhost:8081
in firefox...
So how will I see the website on LocalPC?
And for security reasons:
I need both connections encrypted and let no other users on Jumpserver use the tunnel.
(Sry for codeblocks - I am not allowed to write word localhost...)
web-server ssh-tunnel dmz socks
I have this setup:
LocalPC - Jumpserver - Webserver with page only accessible on this machine via
localhost:8080
LocalPC and Webserver are not connected - Jumpserver has to be used.
Jumpserver doesn't have access to the Webpage on Webserver
I want to use Firefox to view this webpage on LocalPC.
I know how to make socks proxy to Jumpserver - normally this is enough but not in this case
ssh -TD 8080 me@jumpserver
and
I know how to tunnel one specific port over Jumpserver
ssh -f -N -q -L 2222:me@target:22 me@jumpserver
But using the first method only makes a tunnel to Jumpserver and using the second method with ports 8081:me@webserver:8080 doesn't give error but results in 404 for
http://localhost:8081
in firefox...
So how will I see the website on LocalPC?
And for security reasons:
I need both connections encrypted and let no other users on Jumpserver use the tunnel.
(Sry for codeblocks - I am not allowed to write word localhost...)
web-server ssh-tunnel dmz socks
web-server ssh-tunnel dmz socks
edited Nov 6 '14 at 14:57
eye
asked Nov 6 '14 at 11:22
eyeeye
12
12
add a comment |
add a comment |
2 Answers
2
active
oldest
votes
I didn't know that you could daisy chain ssh tunnels but I just tried it out & it works just fine. This is my test environment
- 192.168.1.10 (HearNoEvil) Browser
- 192.168.1.20 (SeeNoEvil) Piggy in the middle
- 192.168.1.30 (SpeakNoEvil) Server
Daisy chains looks like this
- Tunnel
192.168.1.30:8080 <-> 192.168.1.20:8081
SeeNoEvil:~# ssh -f -L 8081:127.0.0.1:8080 user@SpeakNoEvil -N
- Tunnel
192.168.1.20:8081 <-> 192.168.1.10:8082
HearNoEvil:~# ssh -f -L 8082:127.0.0.1:8081 root@SeeNoEvil -N
Socks Proxy 127.0.0.1:8082
https://HearNoEvil.testy.test:8082
I'm working of course backwards for the outside in & SpeakNoEvil is my Server. HearNoEvil being my browser. Hope this was helpful. (^_^)
Will everybody on "SeeNoEvil" be able to use this tunnel or is it just me? Just asking for security reasons...
– eye
Nov 6 '14 at 14:20
Ok I figured out everybody actually can use this tunnel - so I can't do it this way - but it works.
– eye
Nov 6 '14 at 15:40
By using 127.0.0.1 as the address you have effectively started a service which is only reachable from localhost. So the answer would have to be every user on SeeNoEvil will have access to this local service.
– Eamonn Travers
Nov 6 '14 at 15:43
add a comment |
Ok found my solution with help of the first answer to this question:
https://stackoverflow.com/questions/1010808/ssh-tunnelling-chain#1122282
If I build this tunnel chains in ssh-config I can then use ssh -TD 8080 webserver and build a dynamic tunnel. Then I just have to add 127.0.0.1:8080 as socks5 proxy in Firefox and be happy.
add a comment |
Your Answer
StackExchange.ready(function()
var channelOptions =
tags: "".split(" "),
id: "2"
;
initTagRenderer("".split(" "), "".split(" "), channelOptions);
StackExchange.using("externalEditor", function()
// Have to fire editor after snippets, if snippets enabled
if (StackExchange.settings.snippets.snippetsEnabled)
StackExchange.using("snippets", function()
createEditor();
);
else
createEditor();
);
function createEditor()
StackExchange.prepareEditor(
heartbeatType: 'answer',
autoActivateHeartbeat: false,
convertImagesToLinks: true,
noModals: true,
showLowRepImageUploadWarning: true,
reputationToPostImages: 10,
bindNavPrevention: true,
postfix: "",
imageUploader:
brandingHtml: "Powered by u003ca class="icon-imgur-white" href="https://imgur.com/"u003eu003c/au003e",
contentPolicyHtml: "User contributions licensed under u003ca href="https://creativecommons.org/licenses/by-sa/3.0/"u003ecc by-sa 3.0 with attribution requiredu003c/au003e u003ca href="https://stackoverflow.com/legal/content-policy"u003e(content policy)u003c/au003e",
allowUrls: true
,
onDemand: true,
discardSelector: ".discard-answer"
,immediatelyShowMarkdownHelp:true
);
);
Sign up or log in
StackExchange.ready(function ()
StackExchange.helpers.onClickDraftSave('#login-link');
);
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
StackExchange.ready(
function ()
StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fserverfault.com%2fquestions%2f642466%2ftunnel-port-8080-over-jumpserver-using-ssh-socks5-proxy%23new-answer', 'question_page');
);
Post as a guest
Required, but never shown
2 Answers
2
active
oldest
votes
2 Answers
2
active
oldest
votes
active
oldest
votes
active
oldest
votes
I didn't know that you could daisy chain ssh tunnels but I just tried it out & it works just fine. This is my test environment
- 192.168.1.10 (HearNoEvil) Browser
- 192.168.1.20 (SeeNoEvil) Piggy in the middle
- 192.168.1.30 (SpeakNoEvil) Server
Daisy chains looks like this
- Tunnel
192.168.1.30:8080 <-> 192.168.1.20:8081
SeeNoEvil:~# ssh -f -L 8081:127.0.0.1:8080 user@SpeakNoEvil -N
- Tunnel
192.168.1.20:8081 <-> 192.168.1.10:8082
HearNoEvil:~# ssh -f -L 8082:127.0.0.1:8081 root@SeeNoEvil -N
Socks Proxy 127.0.0.1:8082
https://HearNoEvil.testy.test:8082
I'm working of course backwards for the outside in & SpeakNoEvil is my Server. HearNoEvil being my browser. Hope this was helpful. (^_^)
Will everybody on "SeeNoEvil" be able to use this tunnel or is it just me? Just asking for security reasons...
– eye
Nov 6 '14 at 14:20
Ok I figured out everybody actually can use this tunnel - so I can't do it this way - but it works.
– eye
Nov 6 '14 at 15:40
By using 127.0.0.1 as the address you have effectively started a service which is only reachable from localhost. So the answer would have to be every user on SeeNoEvil will have access to this local service.
– Eamonn Travers
Nov 6 '14 at 15:43
add a comment |
I didn't know that you could daisy chain ssh tunnels but I just tried it out & it works just fine. This is my test environment
- 192.168.1.10 (HearNoEvil) Browser
- 192.168.1.20 (SeeNoEvil) Piggy in the middle
- 192.168.1.30 (SpeakNoEvil) Server
Daisy chains looks like this
- Tunnel
192.168.1.30:8080 <-> 192.168.1.20:8081
SeeNoEvil:~# ssh -f -L 8081:127.0.0.1:8080 user@SpeakNoEvil -N
- Tunnel
192.168.1.20:8081 <-> 192.168.1.10:8082
HearNoEvil:~# ssh -f -L 8082:127.0.0.1:8081 root@SeeNoEvil -N
Socks Proxy 127.0.0.1:8082
https://HearNoEvil.testy.test:8082
I'm working of course backwards for the outside in & SpeakNoEvil is my Server. HearNoEvil being my browser. Hope this was helpful. (^_^)
Will everybody on "SeeNoEvil" be able to use this tunnel or is it just me? Just asking for security reasons...
– eye
Nov 6 '14 at 14:20
Ok I figured out everybody actually can use this tunnel - so I can't do it this way - but it works.
– eye
Nov 6 '14 at 15:40
By using 127.0.0.1 as the address you have effectively started a service which is only reachable from localhost. So the answer would have to be every user on SeeNoEvil will have access to this local service.
– Eamonn Travers
Nov 6 '14 at 15:43
add a comment |
I didn't know that you could daisy chain ssh tunnels but I just tried it out & it works just fine. This is my test environment
- 192.168.1.10 (HearNoEvil) Browser
- 192.168.1.20 (SeeNoEvil) Piggy in the middle
- 192.168.1.30 (SpeakNoEvil) Server
Daisy chains looks like this
- Tunnel
192.168.1.30:8080 <-> 192.168.1.20:8081
SeeNoEvil:~# ssh -f -L 8081:127.0.0.1:8080 user@SpeakNoEvil -N
- Tunnel
192.168.1.20:8081 <-> 192.168.1.10:8082
HearNoEvil:~# ssh -f -L 8082:127.0.0.1:8081 root@SeeNoEvil -N
Socks Proxy 127.0.0.1:8082
https://HearNoEvil.testy.test:8082
I'm working of course backwards for the outside in & SpeakNoEvil is my Server. HearNoEvil being my browser. Hope this was helpful. (^_^)
I didn't know that you could daisy chain ssh tunnels but I just tried it out & it works just fine. This is my test environment
- 192.168.1.10 (HearNoEvil) Browser
- 192.168.1.20 (SeeNoEvil) Piggy in the middle
- 192.168.1.30 (SpeakNoEvil) Server
Daisy chains looks like this
- Tunnel
192.168.1.30:8080 <-> 192.168.1.20:8081
SeeNoEvil:~# ssh -f -L 8081:127.0.0.1:8080 user@SpeakNoEvil -N
- Tunnel
192.168.1.20:8081 <-> 192.168.1.10:8082
HearNoEvil:~# ssh -f -L 8082:127.0.0.1:8081 root@SeeNoEvil -N
Socks Proxy 127.0.0.1:8082
https://HearNoEvil.testy.test:8082
I'm working of course backwards for the outside in & SpeakNoEvil is my Server. HearNoEvil being my browser. Hope this was helpful. (^_^)
answered Nov 6 '14 at 12:05
Eamonn TraversEamonn Travers
604411
604411
Will everybody on "SeeNoEvil" be able to use this tunnel or is it just me? Just asking for security reasons...
– eye
Nov 6 '14 at 14:20
Ok I figured out everybody actually can use this tunnel - so I can't do it this way - but it works.
– eye
Nov 6 '14 at 15:40
By using 127.0.0.1 as the address you have effectively started a service which is only reachable from localhost. So the answer would have to be every user on SeeNoEvil will have access to this local service.
– Eamonn Travers
Nov 6 '14 at 15:43
add a comment |
Will everybody on "SeeNoEvil" be able to use this tunnel or is it just me? Just asking for security reasons...
– eye
Nov 6 '14 at 14:20
Ok I figured out everybody actually can use this tunnel - so I can't do it this way - but it works.
– eye
Nov 6 '14 at 15:40
By using 127.0.0.1 as the address you have effectively started a service which is only reachable from localhost. So the answer would have to be every user on SeeNoEvil will have access to this local service.
– Eamonn Travers
Nov 6 '14 at 15:43
Will everybody on "SeeNoEvil" be able to use this tunnel or is it just me? Just asking for security reasons...
– eye
Nov 6 '14 at 14:20
Will everybody on "SeeNoEvil" be able to use this tunnel or is it just me? Just asking for security reasons...
– eye
Nov 6 '14 at 14:20
Ok I figured out everybody actually can use this tunnel - so I can't do it this way - but it works.
– eye
Nov 6 '14 at 15:40
Ok I figured out everybody actually can use this tunnel - so I can't do it this way - but it works.
– eye
Nov 6 '14 at 15:40
By using 127.0.0.1 as the address you have effectively started a service which is only reachable from localhost. So the answer would have to be every user on SeeNoEvil will have access to this local service.
– Eamonn Travers
Nov 6 '14 at 15:43
By using 127.0.0.1 as the address you have effectively started a service which is only reachable from localhost. So the answer would have to be every user on SeeNoEvil will have access to this local service.
– Eamonn Travers
Nov 6 '14 at 15:43
add a comment |
Ok found my solution with help of the first answer to this question:
https://stackoverflow.com/questions/1010808/ssh-tunnelling-chain#1122282
If I build this tunnel chains in ssh-config I can then use ssh -TD 8080 webserver and build a dynamic tunnel. Then I just have to add 127.0.0.1:8080 as socks5 proxy in Firefox and be happy.
add a comment |
Ok found my solution with help of the first answer to this question:
https://stackoverflow.com/questions/1010808/ssh-tunnelling-chain#1122282
If I build this tunnel chains in ssh-config I can then use ssh -TD 8080 webserver and build a dynamic tunnel. Then I just have to add 127.0.0.1:8080 as socks5 proxy in Firefox and be happy.
add a comment |
Ok found my solution with help of the first answer to this question:
https://stackoverflow.com/questions/1010808/ssh-tunnelling-chain#1122282
If I build this tunnel chains in ssh-config I can then use ssh -TD 8080 webserver and build a dynamic tunnel. Then I just have to add 127.0.0.1:8080 as socks5 proxy in Firefox and be happy.
Ok found my solution with help of the first answer to this question:
https://stackoverflow.com/questions/1010808/ssh-tunnelling-chain#1122282
If I build this tunnel chains in ssh-config I can then use ssh -TD 8080 webserver and build a dynamic tunnel. Then I just have to add 127.0.0.1:8080 as socks5 proxy in Firefox and be happy.
edited May 23 '17 at 12:41
Community♦
1
1
answered Nov 6 '14 at 15:39
eyeeye
12
12
add a comment |
add a comment |
Thanks for contributing an answer to Server Fault!
- Please be sure to answer the question. Provide details and share your research!
But avoid …
- Asking for help, clarification, or responding to other answers.
- Making statements based on opinion; back them up with references or personal experience.
To learn more, see our tips on writing great answers.
Sign up or log in
StackExchange.ready(function ()
StackExchange.helpers.onClickDraftSave('#login-link');
);
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
StackExchange.ready(
function ()
StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fserverfault.com%2fquestions%2f642466%2ftunnel-port-8080-over-jumpserver-using-ssh-socks5-proxy%23new-answer', 'question_page');
);
Post as a guest
Required, but never shown
Sign up or log in
StackExchange.ready(function ()
StackExchange.helpers.onClickDraftSave('#login-link');
);
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
Sign up or log in
StackExchange.ready(function ()
StackExchange.helpers.onClickDraftSave('#login-link');
);
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
Sign up or log in
StackExchange.ready(function ()
StackExchange.helpers.onClickDraftSave('#login-link');
);
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown