SSH æ¥ç¶ã®æ¨©éãéå® (ãã¤ã¤ãã³ããªã³ã°ããã¨ããããã話)
SSH でサーバへの接続をトンネリング - kazuhoのメモ置き場ã®ç¶ãã
ãã»ãã¥ãªãã£ä¸ã®è¦è«ã¨ãã¦ãSSH æ¥ç¶ã®ã¯ã©ã¤ã¢ã³ãå´ãã¯ã©ãã¯ããã¦ãããµã¼ãå´ã«å¯¾ãã¦æ»æãã§ããªãããè¨è¨ããããã¨ãããã¨ãããã
ãå ã®ä¾ã®ããã«åç´ã«å ¬ééµèªè¨¼ããã¦ããã ãã ã¨ãssh ã®ãã°ã¤ã³ã¦ã¼ã¶ã¼æ¨©éã§ãªãã§ãããã¡ããããã§ããããããã©ããããã¨è¨ãã¨ããã°ã¤ã³ã¦ã¼ã¶ã¼ã® .ssh/authorized_keys ã§ããããè¨å®ã§ããã
ãã¨ãã°ã
% cat ~tunnel/.ssh/authorized_keys permitopen="0.0.0.0:9999",command="/home/kazuho/bin/echod",no-pty,no-X11-forwarding,no-agent-forwarding ssh-rsa AAA(ç¥) %
ã¨ãè¨å®ãã¦ããã°ã
- -L ã«ãã£ã¦ ssh ãµã¼ãå´ã®æ
å ±ãæ¼æ´©ãããã¨ã¯ãªã
- permitopen ãªãã·ã§ã³ã§åå¨ããªãã¢ãã¬ã¹ (ãããã¯ã¼ã¯ã¢ãã¬ã¹ç) ãæå®
- no-X11-forwarding,no-agent-forwading ã§ãã®ä»ã®ãã©ã¯ã¼ãã£ã³ã°ãæå¶
- ä»»æã®ã³ãã³ããå®è¡ããããã¨ã¯ãªã
- command ãªãã·ã§ã³ã§å®è¡ã³ãã³ããæå®
ã¨ãªã£ã¦ã-R ããã§ããªããããªã·ã¹ãã ã«ãªããã¨æãã(-L ã -R ãç¦æ¢ãããã¨ããããä¸è¬çãªã±ã¼ã¹ã§ã¯ no-tcp-forwarding ãªãã·ã§ã³ã使ãã°ãã)
åè: man sshd