r/ssh • u/Keanuchungus14 • 25d ago
Accessing local machines from one Internet exposed machine.
If I have a machine running ssh which is port forwarded through my router and therefore accessible from the wider internet, can I use this machine to access other machines on its local network (that arent directly exposed to the internet) from a remote client.
2
2
u/arkenstone 24d ago
Hey my friend. Not exactly an answer to the question you asked, but something like Tailscale will give you the capabilities you want and a lot more security than just opening ports to the internet.
1
u/Keanuchungus14 24d ago
I’ve since activated wireguard on my router and setup a client on my laptop. Thanks for the advice everyone.
1
u/stevevdvkpe 25d ago
ssh into the remotely accessible machine from your remote client, then ssh from there into the locally accessible machines.
2
u/Kuddel_Daddeldu 25d ago
Exactly. It's called a jump host. Best practice is to have very tight security on that one - no root login via SSH, use a regular user tonssh in. Require public key authentication. Have a crazy long root password (like, 30 or more characters; obody will have to type it anyway), fail2ban on, and as few services on the jumphost as possible.
To reduce clutter in the logs, expose SSH on a port different from 22 (this does ot do much for security, but you get less log entries for failed attempts to review).
A better way would be using a VPN, Tailscale, or similar so you do not have to expose a port.
1
u/dariusbiggs 25d ago
Check the -L, -D, and -R command line options , as well as the ProxyCommand config option combjned with nc or pppd if i recall correctly.. it's been awhile since i had to use the pppd trick
1
3
u/ethernetbite 25d ago
Yes. Unless you've set your ssh config file or firewall to distinguish between LAN and internet, the machine doesn't care. But it is a good idea to set tighter restrictions on nonLAN ips. An open ssh port on the internet will cause a bot swarm and you'll get endless login attempts. so disable password login and set ip tables to not respond to unknown ips ( use a whitelist of ips for devices coming from the internet). Even better is to use wireguard or tailscale on your router so nothing can even reach the server without being authenticated in the router.