You are not logged in.

#1 2009-03-05 12:20:13

LonelyStar
Member
Registered: 2007-12-09
Posts: 123

permanent ssh tunnel

Hi,
To have a secure connection to an mysql database, I want to keep an permanent ssh tunnel from my laptop to my server open.

I wonder, what the best way to this would be!
Is there a general postup/post-reconnect function for the network in netfg2 config from which I could open the tunnel?
Has somebody else a better Idea?

Thanks!
Nathan

Offline

#2 2009-03-05 18:30:17

cactus
Taco Eater
From: t͈̫̹ͨa͖͕͎̱͈ͨ͆ć̥̖̝o̫̫̼s͈̭̱̞͍̃!̰
Registered: 2004-05-25
Posts: 4,622
Website

Re: permanent ssh tunnel

I have a few boxes where i start an ssh tunnel with daemontools, so it if dies for some reason, it will just come back up.


"Be conservative in what you send; be liberal in what you accept." -- Postel's Law
"tacos" -- Cactus' Law
"t̥͍͎̪̪͗a̴̻̩͈͚ͨc̠o̩̙͈ͫͅs͙͎̙͊ ͔͇̫̜t͎̳̀a̜̞̗ͩc̗͍͚o̲̯̿s̖̣̤̙͌ ̖̜̈ț̰̫͓ạ̪͖̳c̲͎͕̰̯̃̈o͉ͅs̪ͪ ̜̻̖̜͕" -- -̖͚̫̙̓-̺̠͇ͤ̃ ̜̪̜ͯZ͔̗̭̞ͪA̝͈̙͖̩L͉̠̺͓G̙̞̦͖O̳̗͍

Offline

#3 2009-03-05 22:04:33

fukawi2
Ex-Administratorino
From: .vic.au
Registered: 2007-09-28
Posts: 6,224
Website

Re: permanent ssh tunnel

LonelyStar wrote:

Has somebody else a better Idea?

I think they did... They called it 'VPN' wink

Offline

#4 2009-03-05 23:13:15

cactus
Taco Eater
From: t͈̫̹ͨa͖͕͎̱͈ͨ͆ć̥̖̝o̫̫̼s͈̭̱̞͍̃!̰
Registered: 2004-05-25
Posts: 4,622
Website

Re: permanent ssh tunnel

full vpn is a bit overkill if you are just wanting to tunnel one single port.

that said, I do "love me some openvpn". wewt wewt!

Last edited by cactus (2009-03-05 23:13:27)


"Be conservative in what you send; be liberal in what you accept." -- Postel's Law
"tacos" -- Cactus' Law
"t̥͍͎̪̪͗a̴̻̩͈͚ͨc̠o̩̙͈ͫͅs͙͎̙͊ ͔͇̫̜t͎̳̀a̜̞̗ͩc̗͍͚o̲̯̿s̖̣̤̙͌ ̖̜̈ț̰̫͓ạ̪͖̳c̲͎͕̰̯̃̈o͉ͅs̪ͪ ̜̻̖̜͕" -- -̖͚̫̙̓-̺̠͇ͤ̃ ̜̪̜ͯZ͔̗̭̞ͪA̝͈̙͖̩L͉̠̺͓G̙̞̦͖O̳̗͍

Offline

#5 2009-03-06 11:14:24

LonelyStar
Member
Registered: 2007-12-09
Posts: 123

Re: permanent ssh tunnel

Hi,

Thanks, the deamon-tools, ssh tunnel is a good Idea!
I want to use it on a laptop wich does not always have an internet connection.
So I wonder, without a I-net connectin, ssh would permanently die (connect errors).
Do you have a trick for daemontools not to permanently restart ssh in such a case?
It has to somehow check if the i-net connection is up or so ...

Offline

#6 2009-03-06 13:46:50

R00KIE
Forum Fellow
From: Between a computer and a chair
Registered: 2008-09-14
Posts: 4,734

Re: permanent ssh tunnel

You can start the ssh connection normally with ssh.
Then put something working (on the remote side) to keep the connection alive, for me this does the trick

watch -n 120 w

R00KIE
Tm90aGluZyB0byBzZWUgaGVyZSwgbW92ZSBhbG9uZy4K

Offline

#7 2009-03-06 15:33:06

ckristi
Member
From: Bucharest, Romania
Registered: 2006-11-21
Posts: 225

Re: permanent ssh tunnel

Well.. and there's the "-N" option, too:

Excerpt from the ssh manual:

     -N      Do not execute a remote command.  This is useful for just for-
             warding ports (protocol version 2 only).

In love I believe and in Linux I trust

Offline

#8 2009-03-06 15:44:25

kcbanner
Member
From: Toronto, Canada
Registered: 2006-08-28
Posts: 43
Website

Re: permanent ssh tunnel

You can also set SSH to send a tcp keep-alive packet every X seconds. (ie ServerAliveInterval 200  in /etc/ssh/ssh_config )

Offline

#9 2009-03-06 18:32:05

LonelyStar
Member
Registered: 2007-12-09
Posts: 123

Re: permanent ssh tunnel

Hi,

OK, I need my ssh connection to keep alive. That makes sense, I did not even think about that.
But also, I not to start the "ssh daemon" only the network connection is up (or even better, my server is reachable).
How do I do that?

Thanks!
Nathan

Offline

Board footer

Powered by FluxBB