ssh login with a tunnel through intermediate server in a single command? Announcing the arrival of Valued Associate #679: Cesar Manara Planned maintenance scheduled April 17/18, 2019 at 00:00UTC (8:00pm US/Eastern) 2019 Community Moderator Election Results Why I closed the “Why is Kali so hard” questionHow to copy remote NAS file behind a routerRemote desktop over SSH reverse tunnel to replace TeamViewerSingle command to login to SSH and run program?Why SSH login works in shell but fails in all third parties via ssh tunnel?Correct ssh config file settings to tunnel to a 3rd machineSSH tunnel via MySQL WorkbenchSSH ProxyCommand one host to reach anotherConnect DMZ database using SSH tunnelPasswordless ssh tunnelJava KVM Console with an SSH Tunnel Through a JumphostCreating a ssh config for a reverse tunnel + local forward

What are the out-of-universe reasons for the references to Toby Maguire-era Spider-Man in ITSV

Maximum summed powersets with non-adjacent items

What does "lightly crushed" mean for cardamon pods?

Do jazz musicians improvise on the parent scale in addition to the chord-scales?

Would "destroying" Wurmcoil Engine prevent its tokens from being created?

What is the longest distance a player character can jump in one leap?

Is grep documentation wrong?

Is it cost-effective to upgrade an old-ish Giant Escape R3 commuter bike with entry-level branded parts (wheels, drivetrain)?

How to answer "Have you ever been terminated?"

How could we fake a moon landing now?

What do you call the main part of a joke?

What is the meaning of the new sigil in Game of Thrones Season 8 intro?

If a contract sometimes uses the wrong name, is it still valid?

Is this homebrew Lady of Pain warlock patron balanced?

Do I really need to have a message in a novel to appeal to readers?

Why wasn't DOSKEY integrated with COMMAND.COM?

Do square wave exist?

Amount of permutations on an NxNxN Rubik's Cube

When a candle burns, why does the top of wick glow if bottom of flame is hottest?

What does the "x" in "x86" represent?

What causes the direction of lightning flashes?

Is it ethical to give a final exam after the professor has quit before teaching the remaining chapters of the course?

What is homebrew?

Generate an RGB colour grid



ssh login with a tunnel through intermediate server in a single command?



Announcing the arrival of Valued Associate #679: Cesar Manara
Planned maintenance scheduled April 17/18, 2019 at 00:00UTC (8:00pm US/Eastern)
2019 Community Moderator Election Results
Why I closed the “Why is Kali so hard” questionHow to copy remote NAS file behind a routerRemote desktop over SSH reverse tunnel to replace TeamViewerSingle command to login to SSH and run program?Why SSH login works in shell but fails in all third parties via ssh tunnel?Correct ssh config file settings to tunnel to a 3rd machineSSH tunnel via MySQL WorkbenchSSH ProxyCommand one host to reach anotherConnect DMZ database using SSH tunnelPasswordless ssh tunnelJava KVM Console with an SSH Tunnel Through a JumphostCreating a ssh config for a reverse tunnel + local forward



.everyoneloves__top-leaderboard:empty,.everyoneloves__mid-leaderboard:empty,.everyoneloves__bot-mid-leaderboard:empty margin-bottom:0;








4















Is there a way in a single SSH command to login via SSH to a remote server passing through an intermediate server? In essence, I need to create a tunnel to my "bridge server" and via the tunnel to login to the remote server.



For example, I'm trying to compress the following into a single ssh command:



  1. ssh -N -L 2222:remoteserver.com:22 bridge_userid@bridgemachine.com

  2. ssh -p 2222 remote_userid@localhost

This currently works, but I would rather be able to squeeze everything into a single command such that if I exit my ssh shell, my tunnel closes at the same time.



I have tried the following in my config but to no avail:



Host axp
User remote_userid
HostName remoteserver.com
IdentityFile ~/.ssh/id_rsa.eric
ProxyCommand ssh -W %h:%p bridge_userid@bridgemachine.com


As per @jasonwryan comments and the transparent-mulithop link, I'm able to get the following command working:



ssh -A -t bridge_userid@bridgemachine.com ssh -A remote_userid@remoteserver.com


but now I would like to package that up neatly into my .ssh/config file, and not quite sure what I need to use as my ProxyCommand. I've seen a couple of links online as well as @boomshadow's answer that requires nc, but unfortunately the AIX server I'm using as my bridge machine does not have netcat installed on it.










share|improve this question



















  • 1





    ProxyCommand ssh -W %h:%p bridge...

    – jasonwryan
    Jul 14 '15 at 18:34











  • @jasonwryan I think I might have something wrong in my config as it is not working. I've got the following in my .ssh/config for my remoteserver: ProxyCommand ssh -W %h:%p bridge_userid@bridgemachine.com.

    – Eric B.
    Jul 14 '15 at 18:52











  • Edit that into your question: it will get lost in the comments. You need to declare the host, Host Remote... See sshmenu.sourceforge.net/articles/transparent-mulithop.html

    – jasonwryan
    Jul 14 '15 at 19:12












  • Can't you just log into the bridge server and ssh to your target server from there?

    – daniel kullmann
    Jul 14 '15 at 20:18











  • @danielkullmann Sure I can. I'm just trying to avoid doing that, and I would rather keep my ssh key on my local machine instead of having to put it on the bridge server as well.

    – Eric B.
    Jul 14 '15 at 20:44

















4















Is there a way in a single SSH command to login via SSH to a remote server passing through an intermediate server? In essence, I need to create a tunnel to my "bridge server" and via the tunnel to login to the remote server.



For example, I'm trying to compress the following into a single ssh command:



  1. ssh -N -L 2222:remoteserver.com:22 bridge_userid@bridgemachine.com

  2. ssh -p 2222 remote_userid@localhost

This currently works, but I would rather be able to squeeze everything into a single command such that if I exit my ssh shell, my tunnel closes at the same time.



I have tried the following in my config but to no avail:



Host axp
User remote_userid
HostName remoteserver.com
IdentityFile ~/.ssh/id_rsa.eric
ProxyCommand ssh -W %h:%p bridge_userid@bridgemachine.com


As per @jasonwryan comments and the transparent-mulithop link, I'm able to get the following command working:



ssh -A -t bridge_userid@bridgemachine.com ssh -A remote_userid@remoteserver.com


but now I would like to package that up neatly into my .ssh/config file, and not quite sure what I need to use as my ProxyCommand. I've seen a couple of links online as well as @boomshadow's answer that requires nc, but unfortunately the AIX server I'm using as my bridge machine does not have netcat installed on it.










share|improve this question



















  • 1





    ProxyCommand ssh -W %h:%p bridge...

    – jasonwryan
    Jul 14 '15 at 18:34











  • @jasonwryan I think I might have something wrong in my config as it is not working. I've got the following in my .ssh/config for my remoteserver: ProxyCommand ssh -W %h:%p bridge_userid@bridgemachine.com.

    – Eric B.
    Jul 14 '15 at 18:52











  • Edit that into your question: it will get lost in the comments. You need to declare the host, Host Remote... See sshmenu.sourceforge.net/articles/transparent-mulithop.html

    – jasonwryan
    Jul 14 '15 at 19:12












  • Can't you just log into the bridge server and ssh to your target server from there?

    – daniel kullmann
    Jul 14 '15 at 20:18











  • @danielkullmann Sure I can. I'm just trying to avoid doing that, and I would rather keep my ssh key on my local machine instead of having to put it on the bridge server as well.

    – Eric B.
    Jul 14 '15 at 20:44













4












4








4








Is there a way in a single SSH command to login via SSH to a remote server passing through an intermediate server? In essence, I need to create a tunnel to my "bridge server" and via the tunnel to login to the remote server.



For example, I'm trying to compress the following into a single ssh command:



  1. ssh -N -L 2222:remoteserver.com:22 bridge_userid@bridgemachine.com

  2. ssh -p 2222 remote_userid@localhost

This currently works, but I would rather be able to squeeze everything into a single command such that if I exit my ssh shell, my tunnel closes at the same time.



I have tried the following in my config but to no avail:



Host axp
User remote_userid
HostName remoteserver.com
IdentityFile ~/.ssh/id_rsa.eric
ProxyCommand ssh -W %h:%p bridge_userid@bridgemachine.com


As per @jasonwryan comments and the transparent-mulithop link, I'm able to get the following command working:



ssh -A -t bridge_userid@bridgemachine.com ssh -A remote_userid@remoteserver.com


but now I would like to package that up neatly into my .ssh/config file, and not quite sure what I need to use as my ProxyCommand. I've seen a couple of links online as well as @boomshadow's answer that requires nc, but unfortunately the AIX server I'm using as my bridge machine does not have netcat installed on it.










share|improve this question
















Is there a way in a single SSH command to login via SSH to a remote server passing through an intermediate server? In essence, I need to create a tunnel to my "bridge server" and via the tunnel to login to the remote server.



For example, I'm trying to compress the following into a single ssh command:



  1. ssh -N -L 2222:remoteserver.com:22 bridge_userid@bridgemachine.com

  2. ssh -p 2222 remote_userid@localhost

This currently works, but I would rather be able to squeeze everything into a single command such that if I exit my ssh shell, my tunnel closes at the same time.



I have tried the following in my config but to no avail:



Host axp
User remote_userid
HostName remoteserver.com
IdentityFile ~/.ssh/id_rsa.eric
ProxyCommand ssh -W %h:%p bridge_userid@bridgemachine.com


As per @jasonwryan comments and the transparent-mulithop link, I'm able to get the following command working:



ssh -A -t bridge_userid@bridgemachine.com ssh -A remote_userid@remoteserver.com


but now I would like to package that up neatly into my .ssh/config file, and not quite sure what I need to use as my ProxyCommand. I've seen a couple of links online as well as @boomshadow's answer that requires nc, but unfortunately the AIX server I'm using as my bridge machine does not have netcat installed on it.







ssh ssh-tunneling port-forwarding






share|improve this question















share|improve this question













share|improve this question




share|improve this question








edited Jul 15 '15 at 14:47







Eric B.

















asked Jul 14 '15 at 18:26









Eric B.Eric B.

193128




193128







  • 1





    ProxyCommand ssh -W %h:%p bridge...

    – jasonwryan
    Jul 14 '15 at 18:34











  • @jasonwryan I think I might have something wrong in my config as it is not working. I've got the following in my .ssh/config for my remoteserver: ProxyCommand ssh -W %h:%p bridge_userid@bridgemachine.com.

    – Eric B.
    Jul 14 '15 at 18:52











  • Edit that into your question: it will get lost in the comments. You need to declare the host, Host Remote... See sshmenu.sourceforge.net/articles/transparent-mulithop.html

    – jasonwryan
    Jul 14 '15 at 19:12












  • Can't you just log into the bridge server and ssh to your target server from there?

    – daniel kullmann
    Jul 14 '15 at 20:18











  • @danielkullmann Sure I can. I'm just trying to avoid doing that, and I would rather keep my ssh key on my local machine instead of having to put it on the bridge server as well.

    – Eric B.
    Jul 14 '15 at 20:44












  • 1





    ProxyCommand ssh -W %h:%p bridge...

    – jasonwryan
    Jul 14 '15 at 18:34











  • @jasonwryan I think I might have something wrong in my config as it is not working. I've got the following in my .ssh/config for my remoteserver: ProxyCommand ssh -W %h:%p bridge_userid@bridgemachine.com.

    – Eric B.
    Jul 14 '15 at 18:52











  • Edit that into your question: it will get lost in the comments. You need to declare the host, Host Remote... See sshmenu.sourceforge.net/articles/transparent-mulithop.html

    – jasonwryan
    Jul 14 '15 at 19:12












  • Can't you just log into the bridge server and ssh to your target server from there?

    – daniel kullmann
    Jul 14 '15 at 20:18











  • @danielkullmann Sure I can. I'm just trying to avoid doing that, and I would rather keep my ssh key on my local machine instead of having to put it on the bridge server as well.

    – Eric B.
    Jul 14 '15 at 20:44







1




1





ProxyCommand ssh -W %h:%p bridge...

– jasonwryan
Jul 14 '15 at 18:34





ProxyCommand ssh -W %h:%p bridge...

– jasonwryan
Jul 14 '15 at 18:34













@jasonwryan I think I might have something wrong in my config as it is not working. I've got the following in my .ssh/config for my remoteserver: ProxyCommand ssh -W %h:%p bridge_userid@bridgemachine.com.

– Eric B.
Jul 14 '15 at 18:52





@jasonwryan I think I might have something wrong in my config as it is not working. I've got the following in my .ssh/config for my remoteserver: ProxyCommand ssh -W %h:%p bridge_userid@bridgemachine.com.

– Eric B.
Jul 14 '15 at 18:52













Edit that into your question: it will get lost in the comments. You need to declare the host, Host Remote... See sshmenu.sourceforge.net/articles/transparent-mulithop.html

– jasonwryan
Jul 14 '15 at 19:12






Edit that into your question: it will get lost in the comments. You need to declare the host, Host Remote... See sshmenu.sourceforge.net/articles/transparent-mulithop.html

– jasonwryan
Jul 14 '15 at 19:12














Can't you just log into the bridge server and ssh to your target server from there?

– daniel kullmann
Jul 14 '15 at 20:18





Can't you just log into the bridge server and ssh to your target server from there?

– daniel kullmann
Jul 14 '15 at 20:18













@danielkullmann Sure I can. I'm just trying to avoid doing that, and I would rather keep my ssh key on my local machine instead of having to put it on the bridge server as well.

– Eric B.
Jul 14 '15 at 20:44





@danielkullmann Sure I can. I'm just trying to avoid doing that, and I would rather keep my ssh key on my local machine instead of having to put it on the bridge server as well.

– Eric B.
Jul 14 '15 at 20:44










2 Answers
2






active

oldest

votes


















6














The ProxyCommand is what you need. At my company, all the DevOps techs have to use a "jumpstation" in order to access the rest of the VPC's. The jumpstation is VPN access-controlled.



We've got our SSH config setup to automatically go through the jumpstation automatically.



Here is an edited version of my .ssh/config file:



Host *.internal.company.com
User jacob
IdentityFile ~/.ssh/id_rsa
ProxyCommand ssh -q -A jacob@company-internal-jumphost nc -q0 %h %p


Every time I do an 'ssh' to a server on that 'internal' subdomain, it will automatically jump through the jumpstation first.



Edit:
Here is the entire section of the .ssh/config for the 'Internal' VPC for us to log into it:



# Internal VPC
Host company-internal-jumphost
Hostname 10.210.x.x #(edited out IP for security)
IdentityFile ~/.ssh/id_rsa
Host 10.210.*
User ubuntu
IdentityFile ~/.ssh/company-id_rsa
ProxyCommand ssh -q -A jacob@company-internal-jumphost nc -q0 %h %p
Host *.internal.company.com
User jacob
IdentityFile ~/.ssh/id_rsa
ProxyCommand ssh -q -A jacob@company-internal-jumphost nc -q0 %h %p





share|improve this answer

























  • Thanks for the suggestion. Unfortunately, I don't have netcat (ie: nc) available on the server. (It's an AIX server)

    – Eric B.
    Jul 15 '15 at 1:28






  • 2





    There is a more elegant sollution based on ProxyCommand and the -W option which allows you to do things like ssh user@hostA/hostB/hostC to connect to hostC through 2 intermediates, see: dmitry.khlebnikov.net/2015/08/…

    – galaxy
    Sep 4 '15 at 13:39











  • Will this work if you have a different username on the intermediary hosts? Can you use ssh user@hostA/otheruser@hostB/someone@hostC?

    – DopeGhoti
    Jan 17 '17 at 17:50











  • @DopeGhoti, yes you can. In my 2nd code block, I've got user 'ubuntu' specified for the 10.210.* hosts. Also, you can change your user on the intermediary host (jump host) using the ProxyCommand. See how I've got "jacob@company....". You can also specify a different user there as well.

    – BoomShadow
    Jan 17 '17 at 18:56











  • Why not use ssh -W in the ProxyCommand, provided the SSH version isn't too old (5.4)? en.wikibooks.org/wiki/OpenSSH/Cookbook/Proxies_and_Jump_Hosts

    – 0xC0000022L
    Mar 27 '18 at 19:22



















2














If OpenSSH 7.3 or later is used then you can use ProxyJump like this:



$ ssh -o ProxyJump=user1@gateway user2@remote


If either user is omitted then the local user is implied.




A variation on the indirect login theme is indirect file transfer. You can use scp and rsync with indirect ssh to copy files through the intermediate server.



To copy through the gateway using scp:



$ scp -oProxyJump=root@gateway myfile user@remote:path


If user is omitted, the local user is used.



The ProxyJump was introduced in OpenSSH 7.3. An alternative is to use ProxyCommand:



$ scp -oProxyCommand="ssh -W %h:%p root@gateway" myfile user@remote:path


To copy through the gateway using rsync:



$ rsync -av -e 'ssh -o "ProxyJump root@gateway"' myfile user@remote@path


Or



$ rsync -av -e 'ssh -o "ProxyCommand ssh -A root@gateway -W %h:%p"' myfile user@remote@path


I paraphrase other answers (on superuser) that cover indirect scp and indirect rsync in more detail.






share|improve this answer























    Your Answer








    StackExchange.ready(function()
    var channelOptions =
    tags: "".split(" "),
    id: "106"
    ;
    initTagRenderer("".split(" "), "".split(" "), channelOptions);

    StackExchange.using("externalEditor", function()
    // Have to fire editor after snippets, if snippets enabled
    if (StackExchange.settings.snippets.snippetsEnabled)
    StackExchange.using("snippets", function()
    createEditor();
    );

    else
    createEditor();

    );

    function createEditor()
    StackExchange.prepareEditor(
    heartbeatType: 'answer',
    autoActivateHeartbeat: false,
    convertImagesToLinks: false,
    noModals: true,
    showLowRepImageUploadWarning: true,
    reputationToPostImages: null,
    bindNavPrevention: true,
    postfix: "",
    imageUploader:
    brandingHtml: "Powered by u003ca class="icon-imgur-white" href="https://imgur.com/"u003eu003c/au003e",
    contentPolicyHtml: "User contributions licensed under u003ca href="https://creativecommons.org/licenses/by-sa/3.0/"u003ecc by-sa 3.0 with attribution requiredu003c/au003e u003ca href="https://stackoverflow.com/legal/content-policy"u003e(content policy)u003c/au003e",
    allowUrls: true
    ,
    onDemand: true,
    discardSelector: ".discard-answer"
    ,immediatelyShowMarkdownHelp:true
    );



    );













    draft saved

    draft discarded


















    StackExchange.ready(
    function ()
    StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2funix.stackexchange.com%2fquestions%2f215986%2fssh-login-with-a-tunnel-through-intermediate-server-in-a-single-command%23new-answer', 'question_page');

    );

    Post as a guest















    Required, but never shown

























    2 Answers
    2






    active

    oldest

    votes








    2 Answers
    2






    active

    oldest

    votes









    active

    oldest

    votes






    active

    oldest

    votes









    6














    The ProxyCommand is what you need. At my company, all the DevOps techs have to use a "jumpstation" in order to access the rest of the VPC's. The jumpstation is VPN access-controlled.



    We've got our SSH config setup to automatically go through the jumpstation automatically.



    Here is an edited version of my .ssh/config file:



    Host *.internal.company.com
    User jacob
    IdentityFile ~/.ssh/id_rsa
    ProxyCommand ssh -q -A jacob@company-internal-jumphost nc -q0 %h %p


    Every time I do an 'ssh' to a server on that 'internal' subdomain, it will automatically jump through the jumpstation first.



    Edit:
    Here is the entire section of the .ssh/config for the 'Internal' VPC for us to log into it:



    # Internal VPC
    Host company-internal-jumphost
    Hostname 10.210.x.x #(edited out IP for security)
    IdentityFile ~/.ssh/id_rsa
    Host 10.210.*
    User ubuntu
    IdentityFile ~/.ssh/company-id_rsa
    ProxyCommand ssh -q -A jacob@company-internal-jumphost nc -q0 %h %p
    Host *.internal.company.com
    User jacob
    IdentityFile ~/.ssh/id_rsa
    ProxyCommand ssh -q -A jacob@company-internal-jumphost nc -q0 %h %p





    share|improve this answer

























    • Thanks for the suggestion. Unfortunately, I don't have netcat (ie: nc) available on the server. (It's an AIX server)

      – Eric B.
      Jul 15 '15 at 1:28






    • 2





      There is a more elegant sollution based on ProxyCommand and the -W option which allows you to do things like ssh user@hostA/hostB/hostC to connect to hostC through 2 intermediates, see: dmitry.khlebnikov.net/2015/08/…

      – galaxy
      Sep 4 '15 at 13:39











    • Will this work if you have a different username on the intermediary hosts? Can you use ssh user@hostA/otheruser@hostB/someone@hostC?

      – DopeGhoti
      Jan 17 '17 at 17:50











    • @DopeGhoti, yes you can. In my 2nd code block, I've got user 'ubuntu' specified for the 10.210.* hosts. Also, you can change your user on the intermediary host (jump host) using the ProxyCommand. See how I've got "jacob@company....". You can also specify a different user there as well.

      – BoomShadow
      Jan 17 '17 at 18:56











    • Why not use ssh -W in the ProxyCommand, provided the SSH version isn't too old (5.4)? en.wikibooks.org/wiki/OpenSSH/Cookbook/Proxies_and_Jump_Hosts

      – 0xC0000022L
      Mar 27 '18 at 19:22
















    6














    The ProxyCommand is what you need. At my company, all the DevOps techs have to use a "jumpstation" in order to access the rest of the VPC's. The jumpstation is VPN access-controlled.



    We've got our SSH config setup to automatically go through the jumpstation automatically.



    Here is an edited version of my .ssh/config file:



    Host *.internal.company.com
    User jacob
    IdentityFile ~/.ssh/id_rsa
    ProxyCommand ssh -q -A jacob@company-internal-jumphost nc -q0 %h %p


    Every time I do an 'ssh' to a server on that 'internal' subdomain, it will automatically jump through the jumpstation first.



    Edit:
    Here is the entire section of the .ssh/config for the 'Internal' VPC for us to log into it:



    # Internal VPC
    Host company-internal-jumphost
    Hostname 10.210.x.x #(edited out IP for security)
    IdentityFile ~/.ssh/id_rsa
    Host 10.210.*
    User ubuntu
    IdentityFile ~/.ssh/company-id_rsa
    ProxyCommand ssh -q -A jacob@company-internal-jumphost nc -q0 %h %p
    Host *.internal.company.com
    User jacob
    IdentityFile ~/.ssh/id_rsa
    ProxyCommand ssh -q -A jacob@company-internal-jumphost nc -q0 %h %p





    share|improve this answer

























    • Thanks for the suggestion. Unfortunately, I don't have netcat (ie: nc) available on the server. (It's an AIX server)

      – Eric B.
      Jul 15 '15 at 1:28






    • 2





      There is a more elegant sollution based on ProxyCommand and the -W option which allows you to do things like ssh user@hostA/hostB/hostC to connect to hostC through 2 intermediates, see: dmitry.khlebnikov.net/2015/08/…

      – galaxy
      Sep 4 '15 at 13:39











    • Will this work if you have a different username on the intermediary hosts? Can you use ssh user@hostA/otheruser@hostB/someone@hostC?

      – DopeGhoti
      Jan 17 '17 at 17:50











    • @DopeGhoti, yes you can. In my 2nd code block, I've got user 'ubuntu' specified for the 10.210.* hosts. Also, you can change your user on the intermediary host (jump host) using the ProxyCommand. See how I've got "jacob@company....". You can also specify a different user there as well.

      – BoomShadow
      Jan 17 '17 at 18:56











    • Why not use ssh -W in the ProxyCommand, provided the SSH version isn't too old (5.4)? en.wikibooks.org/wiki/OpenSSH/Cookbook/Proxies_and_Jump_Hosts

      – 0xC0000022L
      Mar 27 '18 at 19:22














    6












    6








    6







    The ProxyCommand is what you need. At my company, all the DevOps techs have to use a "jumpstation" in order to access the rest of the VPC's. The jumpstation is VPN access-controlled.



    We've got our SSH config setup to automatically go through the jumpstation automatically.



    Here is an edited version of my .ssh/config file:



    Host *.internal.company.com
    User jacob
    IdentityFile ~/.ssh/id_rsa
    ProxyCommand ssh -q -A jacob@company-internal-jumphost nc -q0 %h %p


    Every time I do an 'ssh' to a server on that 'internal' subdomain, it will automatically jump through the jumpstation first.



    Edit:
    Here is the entire section of the .ssh/config for the 'Internal' VPC for us to log into it:



    # Internal VPC
    Host company-internal-jumphost
    Hostname 10.210.x.x #(edited out IP for security)
    IdentityFile ~/.ssh/id_rsa
    Host 10.210.*
    User ubuntu
    IdentityFile ~/.ssh/company-id_rsa
    ProxyCommand ssh -q -A jacob@company-internal-jumphost nc -q0 %h %p
    Host *.internal.company.com
    User jacob
    IdentityFile ~/.ssh/id_rsa
    ProxyCommand ssh -q -A jacob@company-internal-jumphost nc -q0 %h %p





    share|improve this answer















    The ProxyCommand is what you need. At my company, all the DevOps techs have to use a "jumpstation" in order to access the rest of the VPC's. The jumpstation is VPN access-controlled.



    We've got our SSH config setup to automatically go through the jumpstation automatically.



    Here is an edited version of my .ssh/config file:



    Host *.internal.company.com
    User jacob
    IdentityFile ~/.ssh/id_rsa
    ProxyCommand ssh -q -A jacob@company-internal-jumphost nc -q0 %h %p


    Every time I do an 'ssh' to a server on that 'internal' subdomain, it will automatically jump through the jumpstation first.



    Edit:
    Here is the entire section of the .ssh/config for the 'Internal' VPC for us to log into it:



    # Internal VPC
    Host company-internal-jumphost
    Hostname 10.210.x.x #(edited out IP for security)
    IdentityFile ~/.ssh/id_rsa
    Host 10.210.*
    User ubuntu
    IdentityFile ~/.ssh/company-id_rsa
    ProxyCommand ssh -q -A jacob@company-internal-jumphost nc -q0 %h %p
    Host *.internal.company.com
    User jacob
    IdentityFile ~/.ssh/id_rsa
    ProxyCommand ssh -q -A jacob@company-internal-jumphost nc -q0 %h %p






    share|improve this answer














    share|improve this answer



    share|improve this answer








    edited 9 hours ago









    Rui F Ribeiro

    42.1k1484142




    42.1k1484142










    answered Jul 14 '15 at 21:08









    BoomShadowBoomShadow

    436167




    436167












    • Thanks for the suggestion. Unfortunately, I don't have netcat (ie: nc) available on the server. (It's an AIX server)

      – Eric B.
      Jul 15 '15 at 1:28






    • 2





      There is a more elegant sollution based on ProxyCommand and the -W option which allows you to do things like ssh user@hostA/hostB/hostC to connect to hostC through 2 intermediates, see: dmitry.khlebnikov.net/2015/08/…

      – galaxy
      Sep 4 '15 at 13:39











    • Will this work if you have a different username on the intermediary hosts? Can you use ssh user@hostA/otheruser@hostB/someone@hostC?

      – DopeGhoti
      Jan 17 '17 at 17:50











    • @DopeGhoti, yes you can. In my 2nd code block, I've got user 'ubuntu' specified for the 10.210.* hosts. Also, you can change your user on the intermediary host (jump host) using the ProxyCommand. See how I've got "jacob@company....". You can also specify a different user there as well.

      – BoomShadow
      Jan 17 '17 at 18:56











    • Why not use ssh -W in the ProxyCommand, provided the SSH version isn't too old (5.4)? en.wikibooks.org/wiki/OpenSSH/Cookbook/Proxies_and_Jump_Hosts

      – 0xC0000022L
      Mar 27 '18 at 19:22


















    • Thanks for the suggestion. Unfortunately, I don't have netcat (ie: nc) available on the server. (It's an AIX server)

      – Eric B.
      Jul 15 '15 at 1:28






    • 2





      There is a more elegant sollution based on ProxyCommand and the -W option which allows you to do things like ssh user@hostA/hostB/hostC to connect to hostC through 2 intermediates, see: dmitry.khlebnikov.net/2015/08/…

      – galaxy
      Sep 4 '15 at 13:39











    • Will this work if you have a different username on the intermediary hosts? Can you use ssh user@hostA/otheruser@hostB/someone@hostC?

      – DopeGhoti
      Jan 17 '17 at 17:50











    • @DopeGhoti, yes you can. In my 2nd code block, I've got user 'ubuntu' specified for the 10.210.* hosts. Also, you can change your user on the intermediary host (jump host) using the ProxyCommand. See how I've got "jacob@company....". You can also specify a different user there as well.

      – BoomShadow
      Jan 17 '17 at 18:56











    • Why not use ssh -W in the ProxyCommand, provided the SSH version isn't too old (5.4)? en.wikibooks.org/wiki/OpenSSH/Cookbook/Proxies_and_Jump_Hosts

      – 0xC0000022L
      Mar 27 '18 at 19:22

















    Thanks for the suggestion. Unfortunately, I don't have netcat (ie: nc) available on the server. (It's an AIX server)

    – Eric B.
    Jul 15 '15 at 1:28





    Thanks for the suggestion. Unfortunately, I don't have netcat (ie: nc) available on the server. (It's an AIX server)

    – Eric B.
    Jul 15 '15 at 1:28




    2




    2





    There is a more elegant sollution based on ProxyCommand and the -W option which allows you to do things like ssh user@hostA/hostB/hostC to connect to hostC through 2 intermediates, see: dmitry.khlebnikov.net/2015/08/…

    – galaxy
    Sep 4 '15 at 13:39





    There is a more elegant sollution based on ProxyCommand and the -W option which allows you to do things like ssh user@hostA/hostB/hostC to connect to hostC through 2 intermediates, see: dmitry.khlebnikov.net/2015/08/…

    – galaxy
    Sep 4 '15 at 13:39













    Will this work if you have a different username on the intermediary hosts? Can you use ssh user@hostA/otheruser@hostB/someone@hostC?

    – DopeGhoti
    Jan 17 '17 at 17:50





    Will this work if you have a different username on the intermediary hosts? Can you use ssh user@hostA/otheruser@hostB/someone@hostC?

    – DopeGhoti
    Jan 17 '17 at 17:50













    @DopeGhoti, yes you can. In my 2nd code block, I've got user 'ubuntu' specified for the 10.210.* hosts. Also, you can change your user on the intermediary host (jump host) using the ProxyCommand. See how I've got "jacob@company....". You can also specify a different user there as well.

    – BoomShadow
    Jan 17 '17 at 18:56





    @DopeGhoti, yes you can. In my 2nd code block, I've got user 'ubuntu' specified for the 10.210.* hosts. Also, you can change your user on the intermediary host (jump host) using the ProxyCommand. See how I've got "jacob@company....". You can also specify a different user there as well.

    – BoomShadow
    Jan 17 '17 at 18:56













    Why not use ssh -W in the ProxyCommand, provided the SSH version isn't too old (5.4)? en.wikibooks.org/wiki/OpenSSH/Cookbook/Proxies_and_Jump_Hosts

    – 0xC0000022L
    Mar 27 '18 at 19:22






    Why not use ssh -W in the ProxyCommand, provided the SSH version isn't too old (5.4)? en.wikibooks.org/wiki/OpenSSH/Cookbook/Proxies_and_Jump_Hosts

    – 0xC0000022L
    Mar 27 '18 at 19:22














    2














    If OpenSSH 7.3 or later is used then you can use ProxyJump like this:



    $ ssh -o ProxyJump=user1@gateway user2@remote


    If either user is omitted then the local user is implied.




    A variation on the indirect login theme is indirect file transfer. You can use scp and rsync with indirect ssh to copy files through the intermediate server.



    To copy through the gateway using scp:



    $ scp -oProxyJump=root@gateway myfile user@remote:path


    If user is omitted, the local user is used.



    The ProxyJump was introduced in OpenSSH 7.3. An alternative is to use ProxyCommand:



    $ scp -oProxyCommand="ssh -W %h:%p root@gateway" myfile user@remote:path


    To copy through the gateway using rsync:



    $ rsync -av -e 'ssh -o "ProxyJump root@gateway"' myfile user@remote@path


    Or



    $ rsync -av -e 'ssh -o "ProxyCommand ssh -A root@gateway -W %h:%p"' myfile user@remote@path


    I paraphrase other answers (on superuser) that cover indirect scp and indirect rsync in more detail.






    share|improve this answer



























      2














      If OpenSSH 7.3 or later is used then you can use ProxyJump like this:



      $ ssh -o ProxyJump=user1@gateway user2@remote


      If either user is omitted then the local user is implied.




      A variation on the indirect login theme is indirect file transfer. You can use scp and rsync with indirect ssh to copy files through the intermediate server.



      To copy through the gateway using scp:



      $ scp -oProxyJump=root@gateway myfile user@remote:path


      If user is omitted, the local user is used.



      The ProxyJump was introduced in OpenSSH 7.3. An alternative is to use ProxyCommand:



      $ scp -oProxyCommand="ssh -W %h:%p root@gateway" myfile user@remote:path


      To copy through the gateway using rsync:



      $ rsync -av -e 'ssh -o "ProxyJump root@gateway"' myfile user@remote@path


      Or



      $ rsync -av -e 'ssh -o "ProxyCommand ssh -A root@gateway -W %h:%p"' myfile user@remote@path


      I paraphrase other answers (on superuser) that cover indirect scp and indirect rsync in more detail.






      share|improve this answer

























        2












        2








        2







        If OpenSSH 7.3 or later is used then you can use ProxyJump like this:



        $ ssh -o ProxyJump=user1@gateway user2@remote


        If either user is omitted then the local user is implied.




        A variation on the indirect login theme is indirect file transfer. You can use scp and rsync with indirect ssh to copy files through the intermediate server.



        To copy through the gateway using scp:



        $ scp -oProxyJump=root@gateway myfile user@remote:path


        If user is omitted, the local user is used.



        The ProxyJump was introduced in OpenSSH 7.3. An alternative is to use ProxyCommand:



        $ scp -oProxyCommand="ssh -W %h:%p root@gateway" myfile user@remote:path


        To copy through the gateway using rsync:



        $ rsync -av -e 'ssh -o "ProxyJump root@gateway"' myfile user@remote@path


        Or



        $ rsync -av -e 'ssh -o "ProxyCommand ssh -A root@gateway -W %h:%p"' myfile user@remote@path


        I paraphrase other answers (on superuser) that cover indirect scp and indirect rsync in more detail.






        share|improve this answer













        If OpenSSH 7.3 or later is used then you can use ProxyJump like this:



        $ ssh -o ProxyJump=user1@gateway user2@remote


        If either user is omitted then the local user is implied.




        A variation on the indirect login theme is indirect file transfer. You can use scp and rsync with indirect ssh to copy files through the intermediate server.



        To copy through the gateway using scp:



        $ scp -oProxyJump=root@gateway myfile user@remote:path


        If user is omitted, the local user is used.



        The ProxyJump was introduced in OpenSSH 7.3. An alternative is to use ProxyCommand:



        $ scp -oProxyCommand="ssh -W %h:%p root@gateway" myfile user@remote:path


        To copy through the gateway using rsync:



        $ rsync -av -e 'ssh -o "ProxyJump root@gateway"' myfile user@remote@path


        Or



        $ rsync -av -e 'ssh -o "ProxyCommand ssh -A root@gateway -W %h:%p"' myfile user@remote@path


        I paraphrase other answers (on superuser) that cover indirect scp and indirect rsync in more detail.







        share|improve this answer












        share|improve this answer



        share|improve this answer










        answered Oct 20 '17 at 8:08









        starfrystarfry

        3,31313051




        3,31313051



























            draft saved

            draft discarded
















































            Thanks for contributing an answer to Unix & Linux Stack Exchange!


            • Please be sure to answer the question. Provide details and share your research!

            But avoid


            • Asking for help, clarification, or responding to other answers.

            • Making statements based on opinion; back them up with references or personal experience.

            To learn more, see our tips on writing great answers.




            draft saved


            draft discarded














            StackExchange.ready(
            function ()
            StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2funix.stackexchange.com%2fquestions%2f215986%2fssh-login-with-a-tunnel-through-intermediate-server-in-a-single-command%23new-answer', 'question_page');

            );

            Post as a guest















            Required, but never shown





















































            Required, but never shown














            Required, but never shown












            Required, but never shown







            Required, but never shown

































            Required, but never shown














            Required, but never shown












            Required, but never shown







            Required, but never shown







            -port-forwarding, ssh, ssh-tunneling

            Popular posts from this blog

            Word for a person who has no opinion about whether god existsWord for having a definite opinion while simultaneously withholding judgment?What's the opposite of “newcomer? Is ”veteran" OK?What do you call an “atheist” who might believe in an afterlife?What's a word for someone who wants to voice opinions but not have them challenged?Word for someone who dismisses contrary opinions as irrational?Somone who thinks they are overly special/out of the ordinaryIs there a word, phrase or idiom for “a person who is incapable of thinking about the future”?The belief that a god is human-likeA word for a non-famous person/thing you have heard a lot aboutAdjective for a person who enjoys taking care of their appearance

            What was this official D&D 3.5e Lovecraft-flavored rulebook?What was this set of RPG tools called?As a first-time DM should I let my players play complex character classes and roles?Nymph's Kiss and the RelationshipWhat was the name of this Cleric Prestige Class that shapes metal with its bare hands?Are the 3.5e Dragonlance books third party or official works?What's up with the domain Vile Darkness?What was this 80s book about RPGs?What was the name of this Werewolf band?What book had Rituals to “upgrade” animal companions to keep them viable at higher levels?What was this RPG that had rules for player-owned businesses?

            2017 IndyCar Series Contents Series news Teams and drivers Schedule Season summary Footnotes References External links Navigation menu"INDYCAR: Initial 2018 bodywork concepts unveiled"the original"IndyCar confirms switch to Performance Friction brakes in 2017""AJ Foyt Racing will switch to Chevy"the original"Carlos Munoz, Conor Daly will drive for AJ Foyt Racing""Zach Veach's Indy 500 Debut Confirmed with Foyt""No mass exodus from Honda after Ganassi switch""Ex-F1 driver Sato joins Andretti Autosport for 2017 IndyCar season""IndyCar's Ryan Hunter-Reay, sponsor DHL paired through 2020""hhgregg and Andretti Autosport announce partnership for key races in 2016""INDYCAR: Rossi re-signs with Andretti"the original"McLaren Formula 1 - Fernando Alonso to race at Indy 500 with McLaren, Honda and Andretti Autosport""Shank will finally take part in Indy 500 with Harvey, Andretti | MotorSportsTalk""Andretti adds Jack Harvey to Indy 500 field""Ganassi switches to Honda power for 2017""INDYCAR: Chilton returns to Ganassi"the original"IndyCar silly season: Who's going where in 2017?""INDYCAR: Kanaan, NTT Data return to Ganassi"the original"Kimball to remain at Ganassi for 2017""Coyne confirms Bourdais for 2017 IndyCar season""Davison to sub for Bourdais in Indy 500"the original"Gutierrez confirmed for Detroit IndyCar debut""Gutierrez returns with Coyne for rest of 2017 season""Vautier to drive for Coyne at Texas"the original"INDYCAR: Coyne confirms Jones for 2017"the original"Pippa Mann returns to Coyne for Indy 500""Karam, Dreyer & Reinbold teaming up again for Indianapolis 500""Pigot to return to Ed Carpenter Racing""Hildebrand confirmed as full-time Ed Carpenter driver""Veach to replace injured Hildebrand at Barber"the originalNew Team Harding Racing Enters Chaves for 101st Indianapolis 500"Juncos Racing Announces Entry in 101st Running of the Indianapolis 500 :: Juncos Racing""Juncos confirms Pigot for Indy 500""Saavedra confirmed in Juncos' second 500 entry"the original"Lazier confirms Indy 500 run after son's USF2000 debut"the original"Claman DeMelo to race for RLLR at Sonoma"the original"Rahal signs Servia and ace engineer for 2017""IndyCar: Aleshin returns with Schmidt"the original"Aleshin replaced by Saavedra for Toronto""Jack Harvey will pilot SPM No. 7 car at Watkins Glen, Sonoma""Jay Howard confirmed in Tony Stewart's supported SPM Indy entry""INDYCAR: Newgarden to wave the flag at Penske"the original"Pagenaud opts for No. 1 in 2017"the original"Penske confirms Newgarden for 2017""Montoya to stay with Team Penske in 2017""Target leaving IndyCar after 27 seasons with Chip Ganassi""Cavin: IndyCar could see complete driver/team shakeup in 2017""End of the road for KV Racing?""KV Racing confirms closure, equipment sold to Juncos""Juncos confirms IndyCar Series entry"the original"Juncos readies IndyCar program, aims for '17 500"the original"Harding Racing to add Texas, Pocono to schedule"the original"Sato signs with Andretti Autosport for 2017""INDYCAR: Aleshin in Doubt at SPM"the original"Long Beach notebook: JR Hildebrand breaks hand""Hildebrand cleared to return at Phoenix"the original"Bourdais to undergo surgery on multiple fractures""Aleshin loses Schmidt Peterson IndyCar ride""Saavedra in at SPM for Pocono, Gateway"the original"Bourdais to make return at Gateway"the original"The IndyCar Grand Prix no longer is sponsored by Angie's List""2017 IndyCar Series rulebook""2017 Verizon IndyCar Series Official Rulebook"Official websiteeeeee