【问题标题】:Trying to make a SSH Tunel尝试建立 SSH 隧道
【发布时间】:2016-03-27 22:34:46
【问题描述】:

我在公有子网上的 AWS 上配置了堡垒服务器。 我可以使用堡垒主机直接 ssh 到私有子网内的 ec2 实例。

我可以连接堡垒主机,检查私有ec2上的7474端口是否打开。

nc -v -z -w 5 10.0.3.102 7474; echo $?
Connection to 10.0.3.102 7474 port [tcp/*] succeeded!
0

我想通过 ssh 隧道从 localhost(我的家用机器)到专用网络上的 ec2 实例。

ssh -v -C -N -L 9000:PRIVATE_MDM:7474 BASTION

但我得到:

打开失败:管理禁止:打开失败

Authenticated to 52.32.240.40 ([52.32.240.40]:22).
debug1: Local connections to LOCALHOST:9000 forwarded to remote address PRIVATE_MDM:7474
debug1: Local forwarding listening on ::1 port 9000.
debug1: channel 0: new [port listener]
debug1: Local forwarding listening on 127.0.0.1 port 9000.
debug1: channel 1: new [port listener]
debug1: Requesting no-more-sessions@openssh.com
debug1: Entering interactive session.
debug1: Connection to port 9000 forwarding to PRIVATE_MDM port 7474 requested.
debug1: channel 2: new [direct-tcpip]
debug1: Connection to port 9000 forwarding to PRIVATE_MDM port 7474 requested.
debug1: channel 3: new [direct-tcpip]
channel 2: open failed: administratively prohibited: open failed
channel 3: open failed: administratively prohibited: open failed
debug1: channel 2: free: direct-tcpip: listening port 9000 for PRIVATE_MDM port 7474, connect from 127.0.0.1 port 42685 to 127.0.0.1 port 9000, nchannels 4
debug1: channel 3: free: direct-tcpip: listening port 9000 for PRIVATE_MDM port 7474, connect from 127.0.0.1 port 42686 to 127.0.0.1 port 9000, nchannels 3
debug1: Connection to port 9000 forwarding to PRIVATE_MDM port 7474 requested.
debug1: channel 2: new [direct-tcpip]
channel 2: open failed: administratively prohibited: open failed
debug1: channel 2: free: direct-tcpip: listening port 9000 for PRIVATE_MDM port 7474, connect from 127.0.0.1 port 42687 to 127.0.0.1 port 9000, nchannels 3

【问题讨论】:

  • 如果还是不行,请尝试在服务器日志中搜索原因或尝试以调试模式运行服务器。它应该会告诉你更准确的原因。
  • 查看我编辑的答案。

标签: ssh amazon-ec2 tunneling


【解决方案1】:

BASTION 机器已禁止通过选项AllowTcpForwarding 创建端口转发。如果你想让端口转发工作,你需要在这台机器上允许这个选项。

编辑: 现在我看到了那里的缺陷。你能添加描述你想要达到的目标吗?将未使用的本地端口转发到未使用的远程端口是没有意义的。您可以将远程端的现有服务转发到本地端口(然后使用-L -- 本地端口转发),或者反过来,将本地服务转发到远程端口(然后使用-R -- 远程端口转发)。没有这个,您将无法继续进行。

解决方案: 示例中nc 和ssh 命令的区别在于使用直接IP 地址和hostname。 BASTION 无法解决导致问题的PRIVATE_MDM。

【讨论】:

  • 我已经设置了:(在文件 etc/ssh/sshd_config 上) PermitTunnel 是 AllowTCPForwarding 是
  • 在那之后您是否重新启动了sshd? PermitTunel 无关。
  • 是的。服务 ssh 重启
  • 我正在尝试连接到私有子网内 ec2 实例上端口 7474 上的服务。所以我创建了一个堡垒服务器。我想连接堡垒服务器并将流量重定向到私有服务器上的 7474。
  • 我发现了问题!堡垒服务器无法解析 PRIVATE_MDM!谢谢曼!!!
猜你喜欢
  • 1970-01-01
  • 1970-01-01
  • 2015-05-05
  • 2020-09-14
  • 2020-08-25
  • 2020-06-21
  • 2023-04-02
  • 1970-01-01
  • 2018-11-27
相关资源
最近更新 更多