èŠåïŒæçš¿ã¯éåžžã«ããªã¥ãŒã ããããŸããã䜿ããããã®ããã«ãæçã«åå²ããªãããšã«ããŸããã
ç®æ¬¡ïŒ
- ããŒç®¡ç
- sshçµç±ã§ãã¡ã€ã«ãã³ããŒãã
- å ¥å/åºåã¹ããªãŒã ã®è»¢é
- SSHçµç±ã§ãªã¢ãŒãFSãããŠã³ã
- ãªã¢ãŒãã³ãŒãå®è¡
- .ssh / configã®æ¥ç¶ã®ãšã€ãªã¢ã¹ãšãªãã·ã§ã³
- ããã©ã«ãã®ãªãã·ã§ã³
- XãµãŒããŒè»¢é
- socks-proxyãšããŠã®ssh
- ããŒã転é-ãã©ã¯ãŒããšãªããŒã¹
- ãªããŒã¹ãœãã¯ã¹ãããã·
- ãã³ããªã³ã°L2 / L3ãã©ãã£ãã¯
- èªèšŒãšãŒãžã§ã³ãã®è»¢é
- ä¿¡é ŒãããŠããªããµãŒããŒãä»ããŠsshãä»ããŠsshããã³ããªã³ã°ããïŒ ã»ãšãã©ã®å Žåããããç¥ããªã ïŒ
ããŒç®¡ç
ç°¡åã«èšããšãsshã¯ãã¹ã¯ãŒãã§ã¯ãªãããŒã§ãã°ã€ã³ã§ããŸãã ããŒã¯ãéããéšåãšéããéšåã§æ§æãããŸãã éããŠãããã®ã¯ãŠãŒã¶ãŒã®ããŒã ãã£ã¬ã¯ããªã«é 眮ãããããã«ãã£ãŠãµãŒããŒã«ç§»åããŸããéãããããã®ã¯ãŠãŒã¶ãŒã®ããŒã ãã£ã¬ã¯ããªã«é 眮ããããããããªã¢ãŒããµãŒããŒã«ç§»åããŸãã ååãæ¯èŒãïŒèªåŒµããŸãïŒããã¹ãŠãåé¡ãªããã°-圌ãã¯ãããææŸããŸãã éèŠïŒãµãŒããŒäžã®ã¯ã©ã€ã¢ã³ãã ãã§ãªããã¯ã©ã€ã¢ã³ãã«é¢é£ãããµãŒããŒãæ¿èªãããŸãïŒã€ãŸãããµãŒããŒã¯ç¬èªã®ããŒãæã£ãŠããŸãïŒã ãã¹ã¯ãŒããšæ¯èŒããããŒã®äž»ãªç¹åŸŽã¯ããµãŒããŒã«äŸµå ¥ããããšã§ãçããããšãã§ããªãããšã§ããããŒã¯ã¯ã©ã€ã¢ã³ããããµãŒããŒã«éä¿¡ããããèªèšŒäžã«ã¯ã©ã€ã¢ã³ãã¯ãµãŒããŒã«ããŒãææããŠããããšã蚌æããŸãïŒåãæå·ããžãã¯ïŒã
ããŒçæ
ssh-keygenã³ãã³ãã䜿çšããŠããŒãçæã§ããŸãã ãã©ã¡ãŒã¿ãèšå®ããªãå Žåãå¿ èŠãªãã¹ãŠãä¿åãããŸãã
ããŒã¯ãã¹ã¯ãŒãã§ããã¯ã§ããŸãã ãã®ãã¹ã¯ãŒãïŒåŸæ¥ã®ã°ã©ãã£ã«ã«ã€ã³ã¿ãŒãã§ã€ã¹ïŒã¯äžåºŠèŠæ±ããããã°ããä¿åãããŸãã ãã¹ã¯ãŒãã空ã®å Žåã䜿çšæã«ãã¹ã¯ãŒãã¯èŠæ±ãããŸããã å¿ãããã¹ã¯ãŒããå埩ããããšã¯ã§ããŸããã
ssh-keygen -pã³ãã³ãã䜿çšããŠãããŒã®ãã¹ã¯ãŒããå€æŽã§ããŸãã
ããŒæ§é
ïŒããã©ã«ãã§å Žæã«é¢ãã質åã«åçããå ŽåïŒã
ã/ .ssh / id_rsa.pub-å ¬éããŒã ã¢ã¯ã»ã¹ããå¿ èŠããããµãŒããŒã«ã³ããŒãããŸãã
ã/ .ssh / id_rsa-ç§å¯éµã 誰ã«ãèŠããŠã¯ãããŸããã pubã®ä»£ããã«ã³ããŒããŠã¡ãã»ãŒãž/ãã£ããã«è²Œãä»ããå Žåã¯ãæ°ããããŒãçæããå¿ èŠããããŸãã ïŒåè«ã§ã¯ãããŸãããid_rsaãã¹ãã«sshããŒãäžããããã«æ±ãããã人ã ã®çŽ10ïŒ ãããã³ãããã®10ïŒ ã®100ïŒ ã¯ç·æ§ã§ãïŒã
ãµãŒããŒã«ããŒãã³ããŒ
ãã°ã€ã³ãããŠãŒã¶ãŒãã£ã¬ã¯ããªã§ã/ .ssh / authorized_keysãã¡ã€ã«ãäœæããããã«å ¬éããŒãé 眮ãããšããã¹ã¯ãŒããªãã§å ¥åã§ããŸãã ãã¡ã€ã«ã®ã¢ã¯ã»ã¹èš±å¯ã§ã¯ãèš±å¯ãããŠããªããŠãŒã¶ãŒããã®ãã¡ã€ã«ã«æžã蟌ãããšãèš±å¯ããªãã§ãã ãããèš±å¯ããªãå Žåãsshã¯ãããåãå ¥ããŸããã ããŒã®æåŸã®ãã£ãŒã«ãã¯user @ machineã§ãã ããã¯èªèšŒãšã¯é¢ä¿ãªããããŒãã©ãã«ããããå€æããããã ãã«äŸ¿å©ã§ãã ãã®ãã£ãŒã«ãã¯ãããŒæ§é ã«éåããããšãªãå€æŽïŒãŸãã¯åé€ïŒã§ããããšã«æ³šæããŠãã ããã
ãŠãŒã¶ãŒã®ãã¹ã¯ãŒããããã£ãŠããå Žåãããã»ã¹ãç°¡çŽ åã§ããŸãã ssh-copy-id user @ serverã³ãã³ãã䜿çšãããšããã¡ã€ã«ãæåã§ç·šéããã«ããŒãã³ããŒã§ããŸãã
泚ïŒå€ãsshããã¥ã¢ã«ã«ã¯authorized_keys2ãèšèŒãããŠããŸãã çç±ïŒsshã®æåã®ããŒãžã§ã³ãããã次ã«2çªç®ïŒçŸåšïŒã®ããŒãžã§ã³ããããç¬èªã®æ§æã»ãããäœæããããããã¹ãŠã®äººã«ãšã£ãŠéåžžã«ç²ããŠããŸããã2çªç®ã®ããŒãžã§ã³ã¯ã2ãã®ãªãããŒãžã§ã³ã«åãæ¿ãããŸããã ã€ãŸããåžžã«authorized_keysã§ãããç°ãªãããŒãžã§ã³ã«ã€ããŠã¯èããŸããã
éæšæºããŒãã§sshã䜿çšããŠããå Žåãssh-copy-idã䜿çšããå Žåã¯ç¹å¥ãªããªãã¯ãå¿ èŠã§ãïŒ
ssh-copy-id '-p 443 user@server'
ïŒåŒçšç¬Šã«æ³šæïŒã
ãµãŒããŒããŒ
ãµãŒããŒã«åããŠã¢ã¯ã»ã¹ãããšããsshã¯ããŒãä¿¡é Œãããã©ãããå°ããŸãã noãšçãããšãæ¥ç¶ã¯éããããŸãã ãã®å ŽåãããŒã¯ã/ .ssh / known_hostsãã¡ã€ã«ã«ä¿åãããŸã ã ã©ã®ããŒãäžå¯èœã§ãããã調ã¹ãŸãïŒã»ãã¥ãªãã£ã§ã¯ãªãããïŒã
ãµãŒããŒããŒãå€æŽãããå ŽåïŒããšãã°ããµãŒããŒãåã€ã³ã¹ããŒã«ãããå ŽåïŒãsshã¯åœã®ããŒãå«ã¶ã ãµãŒããŒã«è§Šããã«sshãšå«ã¶ãšãééã£ããµãŒããŒã«äŸµå ¥ããŠããããšã«æ³šæããŠãã ããïŒããšãã°ãåãIPãæã€å¥ã®ã³ã³ãã¥ãŒã¿ãŒããããã¯ãŒã¯ã«ç»å ŽããŸãããããã¯ãäžçäžã«æ°çŸäžãã192.168.1.1ã®ãã¹ãŠã®çš®é¡ã®ããŒã«ã«ãããã¯ãŒã¯ã«ç¹ã«åœãŠã¯ãŸããŸãïŒ ã ãæªæã®ããäžéè æ»æãã®ã·ããªãªã¯ãIPã®ãšã©ãŒã ãã§ã¯ãªããããã¹ãŠãæ£åžžãã§ãããããŒãå€æŽãããå Žåãããã¯ãã©ãã€ã¢ã®ã¬ãã«ãæ°ã¬ãã«äžããæ©äŒã§ãïŒãŸããããŒã«ããèªèšŒãšãµãŒããŒãçªç¶ãã¹ã¯ãŒããæ±ããããå ŽåïŒ -ãã®åŸããã©ãã€ã¢ã100ïŒ ãªã³ã«ãããã¹ã¯ãŒããå ¥åããªãã§ãã ããã
æ¢ç¥ã®ãµãŒããŒããŒãåé€ããã«ã¯ã ssh-keygen -R serverã³ãã³ãã䜿çšããŸã ã ãã®å ŽåãIPããŒãåé€ããå¿ èŠããããŸãïŒãããã¯åå¥ã«ä¿åãããŸãïŒïŒ ssh-keygen -R 127.0.0.1
ãµãŒããŒããŒã¯/ etc / ssh / ssh_host_rsa_keyããã³/etc/ssh/ssh_host_rsa_key.pubã«ä¿åãããŸã ã 次ã®ããããã§ãã
aïŒå€ããµãŒããŒããæ°ãããµãŒããŒã«ã³ããŒããŸãã
bïŒssh-keygenã䜿çšããŠçæããŸãã ãã¹ã¯ãŒããèšå®ããå¿ èŠã¯ãããŸããïŒã€ãŸãã空ã§ãïŒã sshãµãŒããŒã¯ãã¹ã¯ãŒãããŒã䜿çšã§ããŸããã
ãµãŒããŒãè€è£œããå ŽåïŒããšãã°ãä»®æ³ãã·ã³å ïŒããµãŒããŒã®sshããŒãåçæããå¿ èŠãããããšã«æ³šæããŠãã ããã
know_hostsããå€ãããŒãåé€ããããšããå§ãããŸããããããªããšãsshã¯éè€ããŒãèªããŸãã
ãã¡ã€ã«ãã³ããŒãã
ãã¡ã€ã«ããµãŒããŒã«è»¢éããã®ã¯é¢åãªå ŽåããããŸãã sftpããã®ä»ã®å¥åŠãªããšã«ç ©ããããããšã«å ããŠãsshã¯sshã»ãã·ã§ã³ãéããŠãã¡ã€ã«ãã³ããŒããscpã³ãã³ããæäŸããŸãã
scp path/myfile user@8.8.8.8:/full/path/to/new/location/
éãå¯èœã§ãã
scp user@8.8.8.8:/full/path/to/file /path/to/put/here
éã®èŠåïŒmcãsshæ¥ç¶ãå®è¡ã§ãããšããäºå®ã«ããããããã倧ããªãã¡ã€ã«ãã³ããŒããã®ã¯éåžžã«èŠçã§ãã fishïŒä»®æ³fsãšåæ§ã«sshãæäœããããã®mcã¢ãžã¥ãŒã«ïŒã¯éåžžã«é ãã§ãã 100-200kb-éçãããããå¿èåã®ãã¹ããå§ãŸããŸãã ïŒç§ã¯ãscpãç¥ããã«ãéããmcã«ã5GBãã³ããŒããFastEthernetã§12æé匷ããã£ããéåžžã«è¥ãé ã®ããšãæãåºããŸããïŒã
ã³ããŒããæ©èœã¯çŽ æŽãããã§ãã ããããç§ã¯ãååãä»ããŠä¿åãããã-ãšããã«ãµãŒããŒã«ã ãããŠãç¹å¥ãªããã°ã©ã ããã§ã¯ãªãã䜿ãæ £ããããã°ã©ã ããã°ã©ãã£ã«ã«ã¢ãŒãã§ã³ããŒããããã
ã§ããããšïŒ
sshfs
çè«ïŒfuseã¢ãžã¥ãŒã«ã䜿çšãããšãã«ãŒãã«ãããã¡ã€ã«ã·ã¹ãã ãžã®èŠæ±ãããšã¯ã¹ããŒããããŠã察å¿ããããã°ã©ã ã®ãŠãŒã¶ãŒç©ºéã«æ»ãããšãã§ããŸãã ããã«ããããç䌌ãã¡ã€ã«ã·ã¹ãã ããç°¡åã«å®è£ ã§ããŸãã ããšãã°ãsshãä»ããŠãªã¢ãŒããã¡ã€ã«ã·ã¹ãã ãžã®ã¢ã¯ã»ã¹ãæäŸããŠããã¹ãŠã®ããŒã«ã«ã¢ããªã±ãŒã·ã§ã³ïŒäŸå€ã¯ã»ãšãã©ãªãïŒãäœãçããªãããã«ããããšãã§ããŸãã
å®éãäŸå€ïŒO_DIRECTã¯æ®å¿µãªãããµããŒããããŠããŸããïŒããã¯sshfsã®åé¡ã§ã¯ãªããäžè¬çãªãã¥ãŒãºã®åé¡ã§ãïŒã
䜿çšæ³ïŒsshfsããã±ãŒãžãã€ã³ã¹ããŒã«ããŸãïŒããèªäœãèåããŸãïŒã
å®éãdesunote.ruïŒèªå® ã®ã³ã³ãã¥ãŒã¿ãŒã«ãããŸã-åçã¯ãã®èšäºã§ç€ºããŠããŸãïŒãã©ãããããã«ããŠã³ãããã¹ã¯ãªããã®äŸã§ãã
ïŒïŒ/ bin / bash sshfs desunote.ru:/var/www/desunote.ru/ /media/desunote.ru -o reconnect
ãã¡ã€ã«+ xãäœæãããããåŒã³åºããä»»æã®ã¢ããªã±ãŒã·ã§ã³ã«ç§»åããŠãä¿åããŠæ¬¡ã®ããã«è¡šç€ºããŸãã
éèŠãªsshfsãªãã·ã§ã³ã¯æ¬¡ã®ãšããã§ãã-o reconnectïŒãšã©ãŒã®ä»£ããã«åæ¥ç¶ãè©Šã¿ãŸãïŒã
ã«ãŒãããã®ããŒã¿ã§å€ãã®äœæ¥ãããå Žåãidmapãè¡ãïŒå¿ èŠãšããïŒããšãã§ããŸãïŒ
-o idmap = user ã pupkin @ serverãŠãŒã¶ãŒãšããŠæ¥ç¶ããvasiliyãŠãŒã¶ãŒãšããŠããŒã«ã«ã§äœæ¥ããå Žåããpupkinãã¡ã€ã«ã¯vasiliyãã¡ã€ã«ã§ãããšä»®å®ããŸãããšèšããŸãã ãŸãããŸãã¯ã«ãŒããšããŠæ¥ç¶ããå Žåã¯ãã«ãŒããã
ç§ã®å ŽåããŠãŒã¶ãŒåïŒããŒã«ã«ãšãªã¢ãŒãïŒãåãã§ãããããidmapã¯å¿ èŠãããŸããã
sshããŒïŒèšäºã®åé ãåç §ïŒãããå Žåã«ã®ã¿åäœããããšã«æ³šæããŠãã ãããããã§ãªãå Žåããã¹ã¯ãŒãèªèšŒã¯2ã3æ¥ç¶ãããã·ã¥ããŸãã
fusermount -u / pathã³ãã³ãã䜿çšããŠæ¥ç¶ãåæã§ããŸãããæ¥ç¶ãã¹ãã£ãããŒãªå ŽåïŒããšãã°ããããã¯ãŒã¯ããªãå ŽåïŒãã«ãŒãã®äžãããããè¡ãããšãã§ããŸã/å¿ èŠããããŸãïŒsudo umount -f / pathã
ãªã¢ãŒãã³ãŒãå®è¡
sshã¯ãªã¢ãŒããµãŒããŒã§ã³ãã³ããå®è¡ããããã§æ¥ç¶ãéããããšãã§ããŸãã æãç°¡åãªäŸïŒ
ssh user@server ls /etc/
ãµãŒããŒäžã®/ etc /ã®å 容ã衚瀺ãããããŒã«ã«ã³ãã³ãã©ã€ã³ãäœæãããŸãã
äžéšã®ã¢ããªã±ãŒã·ã§ã³ã§ã¯ãå¶åŸ¡ç«¯æ«ãå¿ èŠã§ãã ãããã¯ã-tãªãã·ã§ã³ã§å®è¡ããå¿ èŠããããŸãã
ssh user@server -t remove_command
ãšããã§ã次ã®ãããªããšãã§ããŸãã
ssh user@server cat /some/file|awk '{print $2}' |local_app
ããã«ããã次ã®æ©èœã䜿çšã§ããŸãã
ãã©ã¯ãŒãstdin / out
ããã°ã©ã ã«ãªã¢ãŒãã§ãªã¯ãšã¹ããè¡ãããã®åºåãããŒã«ã«ãã¡ã€ã«ã«é 眮ãããšããŸãã
ssh user@8.8.8.8 command> my_file
ããŒã«ã«åºåããªã¢ãŒãã«çœ®ããããšããŸããã
mycommand | scp-user@8.8.8.8ïŒ/ãã¹/ remote_file
äŸãè€éã«ããŸããã-ãµãŒããŒãããµãŒããŒã«ãã¡ã€ã«ãã¢ããããŒãã§ããŸãïŒ10.1.1.2ã«stdinã眮ããã§ãŒã³ãäœæããŸãããå€éšããã¯ã¢ã¯ã»ã¹ã§ããŸããã
mycommand | ssh user@8.8.8.8 "scp-user@10.1.1.2ïŒ/ path / to / file"
pipe'aã®äœ¿çšã«ã¯ããã®ãããªäžå¯è§£ãªããªãã¯ããããŸãïŒlivejournalã®ã³ã¡ã³ãã§èŠªåã«ææ¡ãããŠããŸãïŒã
tar -c * | ssh user@server "cd && tar -x"
tarã¯ãã¡ã€ã«ãããŒã«ã«ã§ãã¹ã¯ããŠããã¯ããstdoutã«æžã蟌ã¿ãŸããsshã¯ããããèªã¿åãããªã¢ãŒããµãŒããŒäžã®stdinã«æž¡ããŸããcdã¯ããããç¡èŠãïŒstdinã¯èªã¿åããªãïŒãtarã¯ããããèªã¿åããã¢ã³ããã¯ããŸãã ã€ãŸããscpã¯è²§ãã人ã ã®ããã®ãã®ã§ãã
ãšã€ãªã¢ã¹
ççŽã«èšã£ãŠãæè¿ãŸã§ç§ã¯ãããç¥ããã䜿çšããŸããã§ããã 圌ãã¯éåžžã«å¿«é©ã§ããããšãå€æããŸããã
å€ããå°ãªãã倧äŒæ¥ã§ã¯ããµãŒããŒåãspb-MX-i3.extrt.int.company.netã®ããã«èŠããããšããããããŸãã ãããŠãããã«ãããŠãŒã¶ãŒã¯ãããŒã«ã«ã®ãã®ãšåçã§ã¯ãããŸããã ã€ãŸãã次ã®ããã«ãã°ã€ã³ããå¿ èŠããããŸãïŒssh ivanov_i@spb-MX-i3.extrt.int.company.netã å ¥åãããã³ã«-ããªãã¯ååãªãã³ãã«çå矀ãååŸããŸããã å°ããªäŒç€Ÿã§ã¯ãåé¡ã¯æ£å察ã§ã-DNSã«ã€ããŠèª°ãèããããµãŒããŒãžã®ã¢ã¯ã»ã¹ã¯æ¬¡ã®ããã«ãªããŸãïŒssh root@192.168.1.4ã èŠããã«ããŸã è¿·æã§ãã éæšæºã®ããŒããšãããšãã°sshã®æåã®ããŒãžã§ã³ïŒhelloããtsiskamãŸã§ïŒãããå Žåã¯ãããã«ãã©ãã«ãªããŸãã 次ã«ããã¹ãŠã次ã®ããã«ãªããŸãïŒssh -1 -p 334 vv_pupkin@spb-MX-i4.extrt.int.company.netã ãã§ãŒã¯ã§ã ç§ã¯ãã©ãã®è©±ãscpã§ããããããããŸããã
IPïŒ/ etc / hostsïŒã®ã·ã¹ãã å šäœã®ãšã€ãªã¢ã¹ãç»é²ããããšã¯å¯èœã§ãããããã¯æ²ãã£ãåºåã§ãïŒãŠãŒã¶ãŒãšãªãã·ã§ã³ã¯ãšãããå°å·ãããŸãïŒã ãã£ãšçãæ¹æ³ããããŸãã
ã/ .ssh / configãã¡ã€ã«ã䜿çšãããšããµãŒããŒåºæã®ãã©ã¡ãŒã¿ãŒãå«ãæ¥ç¶ãã©ã¡ãŒã¿ãŒãèšå®ã§ããŸããããã¯æãéèŠã§ããããµãŒããŒããšã«ç°ãªããã©ã¡ãŒã¿ãŒããããŸãã 以äžã«èšå®äŸã瀺ããŸãã
ãã¹ãric ãã¹ãåooh-horn-and-hoofs.rf ãŠãŒã¶ãŒç®¡çè ForwardX11ã¯ã å§çž®ã¯ã ãã¹ãããŒã ãã¹ãåmyhome.dyndns.org ãŠãŒã¶ãŒvasya ãã¹ã¯ãŒãèªèšŒ
䜿çšå¯èœãªãã¹ãŠã®ãªãã·ã§ã³ã¯ã man ssh_configã§ç¢ºèªã§ããŸãïŒsshd_configãšæ··åããªãã§ãã ããïŒã
ããã©ã«ãã®ãªãã·ã§ã³
UUSERããã³ããã§ïŒHost *æ§æã䜿çšããŠãããã©ã«ãã®æ¥ç¶èšå®ãæå®ã§ããŸããäŸïŒ
ãã¹ã* ãŠãŒã¶ãŒã«ãŒã å§çž®ã¯ã
/ etc / ssh / ssh_configïŒ/ etc / ssh / ssh d _configãšæ··åããªãã§ãã ããïŒã§ãåãããšãã§ããŸãããããã«ã¯ã«ãŒãæš©éãå¿ èŠã§ããããã¹ãŠã®ãŠãŒã¶ãŒã«é©çšãããŸãã
XãµãŒããŒè»¢é
å®éãäžèšã®èšå®äŸã§ãã®éšåãå°ãèšå®ããŸããã ForwardX11ã¯ãŸãã«ããã§ãã
çè«ïŒUnixã°ã©ãã£ãã¯ã¢ããªã±ãŒã·ã§ã³ã¯éåžžXãµãŒããŒã䜿çšããŸãïŒwaylandã¯æºåäžã§ããããŸã æºåãã§ããŠããŸããïŒã ããã¯ãã¢ããªã±ãŒã·ã§ã³ãèµ·åããæç»ã®ããã«XãµãŒããŒã«æ¥ç¶ããããšãæå³ããŸãã ã€ãŸããGUIã®ãªãââãã¢ãµãŒããŒãšããŒã«ã«ã®XãµãŒããŒïŒäœæ¥å ŽæïŒãããå Žåã¯ããµãŒããŒããã®ã¢ããªã±ãŒã·ã§ã³ããã¹ã¯ãããã«æç»ã§ããããã«ããããšãã§ããŸãã éåžžããªã¢ãŒãXãµãŒããŒã«æ¥ç¶ããããšã¯ãæãå®å šã§ç°¡åãªããšã§ã¯ãããŸããã SSHã¯ãã®ããã»ã¹ãç°¡çŽ åããå®å šã«å®å šã«ããŸãã ãŸãããã©ãã£ãã¯ãååŸããæ©èœã«ãããããå°ãªããã©ãã£ãã¯ã§åŠçã§ããŸãïŒã€ãŸãããã£ãã«äœ¿çšçãåæžãã€ãŸãpingïŒæ£ç¢ºã«ã¯ã¬ã€ãã³ã·ãŒïŒãåæžãã€ãŸãé 延ãåæžïŒã
ããŒïŒ-X-XãµãŒããŒã転éããŸãã -Y転éèš±å¯ã
ssh -XYC user @ SERVERã®çµã¿åãããèŠããŠãããŠãã ããã
äžèšã®äŸïŒäŒç€Ÿåã¯æ¶ç©ºã®ãã®ã§ãïŒã§ã¯ããµãŒããŒooh-horn-and-hoofs.rfã«æ¥ç¶ããŸããããã®ãããªãã®ã§ã¯ãªããWindowsãµãŒããŒã«ã¢ã¯ã»ã¹ããããšãç®æšã«ããŠããŸãã ç§ãã¡ã¯ç ããããã¯ãŒã¯ã§ã®äœæ¥äžã«ãã€ã¯ããœããã®ã»ãã¥ãªãã£ãç¥ã£ãŠããã®ã§ã裞ã®RDPãåºãã®ã¯äžå¿«ã§ãã 代ããã«ãsshãä»ããŠãµãŒããŒã«æ¥ç¶ããããã§rdesktopã³ãã³ããå®è¡ããŸãã
ssh ric
rdesktop -k en-us 192.168.1.1 -g 1900x1200
ãããŠå¥è·¡ããã¹ã¯ãããäžã®ãŠã£ã³ããŠã®ãã°ã€ã³ãŠã£ã³ããŠã æ éã«æå·åãããéåžžã®sshãã©ãã£ãã¯ãšåºå¥ã§ããªãããšã«æ³šæããŠãã ããã
ãœãã¯ã¹ãããã·
次ã®ããã«ïŒã«ãã§ãäŒè°å®€ïŒã«ãããšãããŒã«ã«ã®wifiãã²ã©ãããšã«ãªããŸã-éããããŒããã©ã®ã¬ãã«ã®ã»ãã¥ãªãã£ãã¯ããããŸããã ã¯ããä»ã®äººã®ã¢ã¯ã»ã¹ãã€ã³ããžã®ä¿¡é Œã¯ããã»ã©ã§ã¯ãããŸããïŒããã¯åŠæ³ã§ã¯ãããŸãããè¿ãã®ã«ãã§ã®ååãæã€ãã¹ãŠã®äººã«3Gãé åžããïŒãããŠãã®éçšã§èå³æ·±ãããšãæžãïŒæ®éã®ã©ãããããã䜿çšããŠãã¹ã¯ãŒããšCookieãåé€ãããã®ãããèŠãŸããïŒã
ããŒããéããŠãããšãç¹å®ã®åé¡ãçºçããŸãã ãžã£ããŒãã«ããŒããã次ã«IMAPã次ã«äœããã«ããŒãããŸãã
éåžžã®VPNïŒpptpãl2tpãopenvpnïŒã¯ããã®ãããªç¶æ³ã§ã¯æ©èœããŸãã-åã«ééããŸããã 443rdããŒãã¯ãã»ãšãã©ã®å ŽåCONNECTã¢ãŒãã®ãŸãŸã§ããããšãå®éšçã«ç¥ãããŠããŸããã€ãŸããããã®ãŸãŸãæž¡ãããŸãïŒéåžžã®httpã¯squidã§ééçã«ã©ããã§ããŸãïŒã
ãœãªã¥ãŒã·ã§ã³ã¯socks-proxy sshã¢ãŒãã§ãã ãã®ååïŒsshã¯ã©ã€ã¢ã³ãã¯ãµãŒããŒã«æ¥ç¶ããããŒã«ã«ã§ãªãã¹ã³ããŸãã ãªã¯ãšã¹ããåä¿¡ããåŸãïŒãªãŒãã³æ¥ç¶ãä»ããŠïŒãµãŒããŒã«éä¿¡ãããµãŒããŒã¯ãªã¯ãšã¹ãã«åŸã£ãŠæ¥ç¶ã確ç«ãããã¹ãŠã®ããŒã¿ãsshã¯ã©ã€ã¢ã³ãã«è»¢éããŸãã ãããŠã圌ã¯ç³è«è ã«çããŸãã åäœããã«ã¯ãã¢ããªã±ãŒã·ã§ã³ã«ããœãã¯ã¹ãããã·ã䜿çšãããããã«æ瀺ããå¿ èŠããããŸãã ãããŠããããã·ã®IPã¢ãã¬ã¹ãæå®ããŸãã sshã®å Žåãããã¯ã»ãšãã©ã®å Žålocalhostã§ãïŒãããã£ãŠãèŠç¥ãã¬äººã«ãã£ã³ãã«ãæž¡ãããšã¯ãããŸããïŒã
sock-proxyæ¥ç¶ã¯æ¬¡ã®ããã«ãªããŸãã
ssh -D 8080ãŠãŒã¶ãŒ@ãµãŒããŒ
ä»ã®äººã®wifiã¯ãã°ãã°ã€ããžã¯ã ãã§ãªãé ããŠãããšããäºå®ã®ããã«ã-Cãªãã·ã§ã³ïŒãã©ãã£ãã¯ãå§çž®ããïŒãæå¹ã«ãããšè¯ããããããŸããã ããã¯ã»ãšãã©ãªãã©ã¿ãŒãã§ããããšãããããŸãïŒåçã ããæŒãããŸããïŒã HTTPã§ã®å®éã®ãµãŒãã£ã³ã§ã¯ãçŽ2ã3åã¯ãªãã¯ããŸãïŒ64kbitã®çœå®³ãçºçããå Žåã40åã§ã¯ãªã40ç§ã§ã¡ã¬ãã€ãã®ããŒãžãéãããšãã§ããŸããããã¯è¯ãããšã§ããããã¹ãŠãåªããŠããŸãïŒã ããããæãéèŠãªã®ã¯ãçãŸããCookieãååãããã»ãã·ã§ã³ããªãããšã§ãã
éãããã枯ã«ã€ããŠã¯äœãèšããªãã£ãã 22çªç®ã®ããŒãã¯ããžã£ããŒã®ãäžèŠãªãããŒããšãŸã£ããåãããã«éããããŸãã 解決çã¯ãããŒã443ã§ãµãŒããŒããã³ã°ã¢ããããããšã§ãã 22ããåçãæ®ã䟡å€ã¯ãããŸããããDPIïŒãã£ãŒããã±ããã€ã³ã¹ãã¯ã·ã§ã³ïŒãåããã·ã¹ãã ã§ããæ¬äŒŒsslããææŸããªãå ŽåããããŸãã
ããã¯ç§ã®èšå®ã®ããã§ãïŒ
/ etc / ssh / sshd_configïŒ
ïŒãã©ã°ã¡ã³ãïŒ
ããŒã22
ããŒã443
ãããŠãããã¯ã©ãããããããã®vpnã説æããã/ .ssh / configã®äžéšã§ã
ãã¹ãVPN ãã¹ãådesunote.ru ãŠãŒã¶ãŒvasya å§çž®ã¯ã DynamicForward 127.1ïŒ8080 ããŒã443
ïŒlocalhostãæžããæ yãªã圢åŒ-127.1ã«æ³šæããŠãã ãããããã¯127.0.0.1ãæžãããã®éåžžã«æ£åœãªæ¹æ³ã§ãïŒ
ããŒã転é
SSHæ©èœã®ç解ãéåžžã«é£ããéšåã«ç§»ããŸããããã«ãããããµãŒããŒãããããã³ããµãŒããŒãžãã®TCPãã³ããªã³ã°æäœãäžå¯è§£ã«ãªããŸãã
ç¶æ³ãç解ããããã«ã以äžã®ãã¹ãŠã®äŸã§ã¯ãã®å³ãåç §ããŸãã
ã³ã¡ã³ãïŒ2ã€ã®ç°è²ã®ãããã¯ãŒã¯ã æåã®ãããã¯ãŒã¯ã¯å žåçãªãªãã£ã¹ãããã¯ãŒã¯ïŒNATïŒã«äŒŒãŠããã2çªç®ã¯ã²ãŒããŠã§ã€ã§ããã€ãŸããçœãã€ã³ã¿ãŒãã§ã€ã¹ãšç°è²ã®ã€ã³ã¿ãŒãã§ã€ã¹ãåãããµãŒããŒã§ãããç¬èªã®ãã©ã€ããŒããããã¯ãŒã¯ãèŠãŠããŸãã ããã«èæ ®ãããšããç§ãã¡ã®ãã©ãããããã¯Aã§ãããµãŒããŒãã¯Bã§ãããšèããŠããŸãã
ã¿ã¹ã¯ ïŒã¢ããªã±ãŒã·ã§ã³ãããŒã«ã«ã§å®è¡ããŠããã®ã§ãå¥ã®ãŠãŒã¶ãŒã«ïŒãããã¯ãŒã¯ã®å€éšã§ïŒåœŒãèŠãæ©äŒãäžããå¿ èŠããããŸãã
解決çïŒããŒã«ã«ããŒãïŒ127.0.0.1:80ïŒãå ¬çã«ã¢ã¯ã»ã¹å¯èœãªã¢ãã¬ã¹ã«è»¢éããŸãã ãå ¬éãããŠãããBãäœã䟿å©ãªããŒã80ã䜿çšãããšä»®å®ããŠãéæšæºããŒãïŒ8080ïŒã«è»¢éããŸãã
æçµæ§æïŒ8.8.8.8:8080ã®ãªã¯ãšã¹ãã¯ã©ãããããAã®ããŒã«ã«ãã¹ãã«éãããŸãã
ssh -R 127.1:80:8.8.8.8:8080 user@8.8.8.8
-Rãªãã·ã§ã³ã䜿çšãããšããªã¢ãŒãïŒ R emoteïŒãµãŒããŒããïŒããŒã«ã«ïŒããŒãã«ããŒãããªãã€ã¬ã¯ãã§ããŸãã
éèŠïŒã¢ãã¬ã¹8.8.8.8ã䜿çšããå ŽåããµãŒããŒèšå®Bã§GatewayPortsãæå¹ã«ããå¿ èŠããããŸãã
ãã£ã¬ã³ãž ã ãµãŒããŒãBãã§ã¯ãç¹å®ã®ããŒã¢ã³ããªãã¹ã³ããŠããŸãïŒããšãã°ãSQLãµãŒããŒïŒã ç§ãã¡ã®ã¢ããªã±ãŒã·ã§ã³ã¯ãµãŒããŒãšäºææ§ããããŸããïŒä»ã®ããããOSãéªæªãªç®¡çè ãå¶éã®çŠæ¢ãšèª²ããªã©ïŒã ãªã¢ãŒãã®ããŒã«ã«ãã¹ãã«ããŒã«ã«ã«ã¢ã¯ã»ã¹ãããã
æçµæ§æïŒlocalhostïŒ3333 'A'ã®ãªã¯ãšã¹ãã¯ãlocalhostïŒ3128 'B'ã®ããŒã¢ã³ã«ãã£ãŠåŠçãããå¿ èŠããããŸãã
ssh -L 127.1:3333:127.1:3128 user@8.8.8.8
-Lãªãã·ã§ã³ã䜿çšãããšãããŒã«ã«ã³ãŒã«ïŒ L ocalïŒããªã¢ãŒããµãŒããŒã«è»¢éã§ããŸãã
ã¿ã¹ã¯ ïŒãµãŒããŒãBãã®ç°è²ã®ã€ã³ã¿ãŒãã§ã€ã¹ã§ãç¹å®ã®ãµãŒãã¹ããªãã¹ã³ããŠãããååïŒ192.168.0.3ïŒããã®ã¢ããªã±ãŒã·ã§ã³ãèŠãããšãã§ããããã«ããŸãã
æçµæ§æïŒã°ã¬ãŒã®IPã¢ãã¬ã¹ïŒ192.168.0.2ïŒãžã®èŠæ±ã¯ããµãŒããŒBã®ã°ã¬ãŒã®ã€ã³ã¿ãŒãã§ã€ã¹ã«å°éããŸãã
ssh -L 192.168.0.2:8080:10.1.1.1:80 user@8.8.8.8
ãã¹ãããããã³ãã«
ãã¡ããããã³ãã«ã¯ãªãã€ã¬ã¯ãã§ããŸãã
ã¿ã¹ã¯ãè€éã«ããŸããããã¢ãã¬ã¹10.1.1.2ïŒããŒã80ïŒã®ãµãŒããŒäžã®ããŒã«ã«ãã¹ãã§å®è¡ãããŠããã¢ããªã±ãŒã·ã§ã³ãååã«èŠããããšæããŸãã
解決çã¯é£ããã§ãã
ssh -L 192.168.0.2:8080:127.1:9999 user@8.8.8.8 ssh -L 127.1:9999:127.1:80 user2@10.1.1.2
äœãèµ·ãã£ãŠããã®ïŒ ããŒã«ã«ãªã¯ãšã¹ããã¢ãã¬ã¹ãããµãŒããŒBã®ããŒã«ã«ãã¹ãã«ãªãã€ã¬ã¯ãããããã«sshã«æ瀺ããããŒã«ã«ãã¹ãããªãã¹ã³ããŠãµãŒããŒ10.1.1.2ïŒã¯ã©ã€ã¢ã³ããæ¥ç¶ããå¿ èŠãããïŒã«ãªã¯ãšã¹ããéä¿¡ãããªãã·ã§ã³ã䜿çšããŠããµãŒããŒBã§sshïŒã€ãŸããsshã¯ã©ã€ã¢ã³ãïŒãèµ·åããçŽåŸã«æ¥ç¶ããŸãã ããŒã9999ã¯ä»»æã«éžæãããŸããäž»ãªããšã¯ãæåã®åŒã³åºããš2çªç®ã®åŒã³åºãã§äžèŽããããšã§ãã
ãªããŒã¹ãœãã¯ã¹ãããã·
åã®äŸãåçŽã§æçœã«æããå Žåããã®äŸãäœãããããæšæž¬ããŠã¿ãŠãã ããã
ssh -D 8080 -R 127.1:8080:127.1:8080 user@8.8.8.8 ssh -R 127.1:8080:127.1:8080 user@10.1.1.2
ãµãŒããŒ10.1.1.2ã§ã€ã³ã¿ãŒãããã®äœ¿çšãçŠæ¢ããããšãã¿ã¹ã¯ãšããã»ãã¥ãªãã£æ åœè ã®å Žåããã®ã³ãã³ãã¯ã³ã³ãã¥ãŒã¿ãŒãAãã§å®è¡ãããŠãããããã·ãããã·ã䜿çšããŠãµãŒããŒ10.1.1.2ã®ã€ã³ã¿ãŒãããã¢ã¯ã»ã¹ãæŽçãããããæçã®é«ªã®æ¯ãæãããšãã§ããŸãã ãã©ãã£ãã¯ã¯å®å šã«æå·åãããä»ã®SSHãã©ãã£ãã¯ãšåºå¥ã§ããŸããã ãããã¯ãŒã¯ã192.168.0 / 24ãã®èŠ³ç¹ããã®ã³ã³ãã¥ãŒã¿ãŒããã®çºä¿¡ãã©ãã£ãã¯ã¯ãã³ã³ãã¥ãŒã¿ãŒAã®éåžžã®ãã©ãã£ãã¯ãšåºå¥ã§ããŸããã
ãã³ããªã³ã°
ãã®æç¹ã§ã»ãã¥ãªãã£éšéã®åžç¥ãbããŠããªãã®ã«ãsshãã»ãã¥ãªãã£ã®æ倧ã®æµãšããŠãªã¹ããããŠããªãå ŽåãIPãã³ããªã³ã°ãŸãã¯ã€ãŒãµãããã§ããããã¹ãŠã究極ã®æ®ºäººè ã§ãã æãéæ¿ãªã±ãŒã¹ã§ã¯ãããã«ãããdhcpã®ãã³ããªã³ã°ããªã¢ãŒãarpã¹ããŒãã£ã³ã°ãlanããã³ãã®ä»ã®ç¬¬2ã¬ãã«ã®ãã§ã®èµ·åãå¯èœã«ãªããŸãã
詳现ã«ã€ããŠã¯ãã¡ããã芧ãã ããïŒ www.khanh.net/blog/archives/51-using-openSSH-as-a-layer-2-ethernet-bridge-VPN.html
ïŒæ²ããããªãç§èªèº«ã¯ããã䜿çšããŸããã§ããïŒã
ãã®ãããªç¶æ³ã§ã¯ãDPIïŒãã£ãŒããã±ããã€ã³ã¹ãã¯ã·ã§ã³ïŒã§ãã®ãããªãã³ãã«ããã£ããããããšã¯äžå¯èœã§ããããšã容æã«ç解ã§ããŸã-sshã¯èš±å¯ãããŠããŸãïŒèªã¿åã-å¿ èŠãªããšãè¡ããŸãïŒãŸãã¯sshã¯çŠæ¢ãããŠããŸãïŒãããŠãå°ãåŸæããããšãªãå®å šã«ãã«ãæ®ãããšãã§ããŸãïŒã
æ¿èªè»¢é
ããããã¹ãŠã ãšæããªã.......ãããããŸã ãäžãã«æžãããŠããªãèè ãšã¯ç°ãªããèªè ã¯äžã«ããããã®æçŽãé°è¬ãããããšãåãã£ãŠèŠãŠããŸãã
OpenSSHã§ã¯ããããã®ãµãŒããŒãä¿¡é ŒãããŠããããå¿ èŠãªãã®ãæªçšããå¯èœæ§ãããå Žåã§ãããµãŒããŒãããªããžããããšããŠäœ¿çšããŠä»ã®ãµãŒããŒã«æ¥ç¶ã§ããŸãã
åçŽãªæ¿èªè»¢éã§éå§ããŸãã
ç§ã¯çµµãç¹°ãè¿ããŸãïŒ
ããŒãåãå ¥ããæºåãã§ããŠãããµãŒããŒ10.1.1.2ã«æ¥ç¶ãããšããŸãã ããããããã§ã¯8.8.8.8ã«ã³ããŒããããããŸããããšã³ãã©ã³ã¹ã€ãŒããšååã®äººãsudoãæã¡ãä»ã®äººã®ãã£ã¬ã¯ããªãä»ããŠåéãããå¯èœæ§ãããããã§ãã 劥åã®ãªãã·ã§ã³ã¯ãuser @ 8.8.8.8ãã10.1.1.2ãèªèšŒãããç°ãªããsshããŒãæã€ããšã§ããã8.8.8.8ãã10.1.1.2ã®ãŠãŒã¶ãŒãèš±å¯ããããªãå Žåãããã¯ãªãã·ã§ã³ã§ã¯ãããŸããïŒããã«ãããŒã¯poyuzatã§ããã ãã§ãªãããéšã®æ¥ã®ããã«ãèªåèªèº«ãã³ããŒããããšãã§ããŸãïŒã
sshã¯ãsshãšãŒãžã§ã³ãïŒããŒã®ãã¹ã¯ãŒããèŠæ±ãããµãŒãã¹ïŒã転éããæ©èœãæäŸããŸãã ssh -Aãªãã·ã§ã³ã¯ãèªèšŒããªã¢ãŒããµãŒããŒã«è»¢éããŸãã
åŒã³åºãã¯æ¬¡ã®ããã«ãªããŸãã
ssh -A user@8.8.8.8 ssh user2@10.1.1.2
ãªã¢ãŒãsshã¯ã©ã€ã¢ã³ãïŒ8.8.8.8ïŒã¯ããã®ãµãŒããŒã«æ¥ç¶ããsshã¯ã©ã€ã¢ã³ãã«èªèšŒãšãŒãžã§ã³ãïŒãã ããããŒã§ã¯ãªãïŒïŒã«ã¢ã¯ã»ã¹ããå Žåã®ã¿ã10.1.1.2ã§ããããšã蚌æã§ããŸãã
ã»ãšãã©ã®å ŽåãããŒã«ããŸãã
ãã ãããµãŒããŒãå®å šã«äžè¯ãªå Žåãã«ãŒããµãŒããŒã¯æ¥ç¶æã«åœè£ ã®ããã«ãœã±ããã䜿çšã§ããŸãã
ããã«åŒ·åãªæ¹æ³ããããŸã-sshãåçŽãªãã€ãïŒããã€ããã®æå³ïŒã«å€æãããããéããŠãªã¢ãŒããµãŒããŒãæäœããŸãã
ãã®æ¹æ³ã®äž»ãªå©ç¹ã¯ãäžéãµãŒããŒã®ãããã·ããå®å šã«ç¬ç«ããŠããããšã§ãã åœã®sshãµãŒããŒã䜿çšãããã¹ãŠã®ãã€ããšãã¹ãŠã®ã¢ã¯ã·ã§ã³ããã°ã«èšé²ããä»»æã®ããŒã¿ãã€ã³ã¿ãŒã»ããããå¿ èŠã«å¿ããŠåœé ããããšãã§ããŸããããåãã¯ãæçµããµãŒããŒãšã¯ã©ã€ã¢ã³ãã®éã§è¡ãããŸãã ã¿ãŒããã«ãµãŒããŒã®ããŒã¿ãæ¹ãããããŠããå Žåã眲åã¯åæããŸããã ããŒã¿ãæ¹ãããããŠããªãå Žåãã»ãã·ã§ã³ã¯ä¿è·ã¢ãŒãã§èšå®ããããããã€ã³ã¿ãŒã»ãããããã®ã¯ãããŸããã
ç§ã¯ãã®ã¯ãŒã«ãªèšå®ãç¥ããŸããã§ãã ã
ã»ããã¢ããã¯ã2ã€ã®sshæ©èœã«é¢é£ä»ããããŠããŸãïŒ-Wãªãã·ã§ã³ïŒsshãããã€ããã«å€æããïŒãšProxyCommand configãªãã·ã§ã³ïŒã³ãã³ãã©ã€ã³ãªãã·ã§ã³ãããã§ã¯ãªãããã§ãïŒã ãããã®ãªãã·ã§ã³ã¯æè¿ç»å ŽãããããcentosãŠãŒã¶ãŒã¯éèµ°äžã§ãã
次ã®ããã«ãªããŸãïŒäžã®åçã®å³ïŒïŒ
.ssh / configïŒ
ãã¹ãã¬ã€ã HostName 10.1.1.2 ãŠãŒã¶ãŒuser2 ProxyCommand ssh -WïŒ hïŒïŒ p user@8.8.8.8
ããŠãæ¥ç¶ã¯ç°¡åã§ãïŒ
ssh raep
ã
ãµãŒããŒ8.8.8.8ã¯ãã©ãã£ãã¯ãååãŸãã¯åœé ãããããŠãŒã¶ãŒèªèšŒãšãŒãžã§ã³ãã䜿çšãããããã©ãã£ãã¯ãå€æŽãããããããšã¯ã§ããŸãããæåŠ-ã¯ããã§ããŸãããã ããèš±å¯ãããŠããå Žåã埩å·åãŸãã¯å€æŽããã«èªåèªèº«ãééããŸããèšå®ãæ©èœããããã«ã¯ãuser @ 8.8.8.8ãšuser2@10.1.1.2ã®äž¡æ¹ã®authorized_keysã«å ¬ééµãå¿ èŠã§ã
ãã¡ãããããŒããã©ã¯ãŒãã£ã³ã°ããã¡ã€ã«ã³ããŒããœãã¯ã¹ãããã·ãL2ãã³ãã«ããã³ããªã³ã°ãªã©ãä»ã®ãã¹ãŠã®é害ãæ¥ç¶ã«è£ åã§ããŸãXãµãŒããŒãªã©
ãã¡ã€ãã«
ãã¡ããããã³ãã«ã«é¢ããæçš¿ã«ã¯ãã³ãã«ããããæåããèšäºã«ã¯ãã¹ãŠã®äººæ°ãç§ããããŠããŸãã ç¶æããïŒ