{"id":10275,"date":"2020-03-23T17:51:23","date_gmt":"2020-03-23T17:51:23","guid":{"rendered":"https:\/\/merikebi.warrenmyers.com\/?p=10275"},"modified":"2020-03-23T17:51:23","modified_gmt":"2020-03-23T17:51:23","slug":"sshuttle-a-simple-transparent-proxy-vpn-over-ssh","status":"publish","type":"post","link":"https:\/\/merikebi.warrenmyers.com\/?p=10275","title":{"rendered":"sshuttle \u2013 a simple transparent proxy vpn over ssh"},"content":{"rendered":"<p>I found out about <a href=\"https:\/\/github.com\/sshuttle\/sshuttle\">sshuttle<\/a> from a random <a href=\"https:\/\/twitter.com\/techrepublic\/status\/1241430763985346565?s=12\">tweet<\/a> that happened to catch my eye.<\/p>\n<p>Here&#8217;s the skinny (from the <a href=\"https:\/\/github.com\/sshuttle\/sshuttle\/blob\/master\/README.rst\">readme<\/a>):<\/p>\n<ul>\n<li>Your client machine (or router) is Linux, FreeBSD, or MacOS.<\/li>\n<li>You have access to a remote network via ssh.<\/li>\n<li>You don&#8217;t necessarily have admin access on the remote network.<\/li>\n<li>The remote network has no VPN, or only stupid\/complex VPN<br \/>\nprotocols (IPsec, PPTP, etc). Or maybe you <em>are<\/em> the<br \/>\nadmin and you just got frustrated with the awful state of<br \/>\nVPN tools.<\/li>\n<li>You don&#8217;t want to create an ssh port forward for every<br \/>\nsingle host\/port on the remote network.<\/li>\n<li>You hate openssh&#8217;s port forwarding because it&#8217;s randomly<br \/>\nslow and\/or stupid.<\/li>\n<li>You can&#8217;t use openssh&#8217;s PermitTunnel feature because<br \/>\nit&#8217;s disabled by default on openssh servers; plus it does<br \/>\nTCP-over-TCP, which has <a href=\"https:\/\/sshuttle.readthedocs.io\/en\/stable\/how-it-works.html\">terrible performance<\/a>.<\/li>\n<\/ul>\n<h4>Here&#8217;s how I set it up on my Mac<\/h4>\n<p>Install <a href=\"https:\/\/brew.sh\">homebrew<\/a>:<\/p>\n<p><code>\/bin\/bash -c \"$(curl -fsSL https:\/\/raw.githubusercontent.com\/Homebrew\/install\/master\/install.sh)\"<\/code><\/p>\n<p>Install sshuttle (as a regular user):<\/p>\n<p><code>brew install sshuttle<\/code><\/p>\n<p>Test the connection to a server you have:<\/p>\n<p><code>sudo sshuttle -r &lt;user>@host.tld -x host.tld 0\/0 -vv<\/code><\/p>\n<p>I also made sure that my target server could be connected-to via certificate for my local root user &#8211; but you can use a password if you prefer.<\/p>\n<p>Check your IP address:<\/p>\n<p><code>curl https:\/\/ipv4.cf<\/code><\/p>\n<p>Once you make sure the connection <em>works<\/em>, Ctrl-C to end the session.<\/p>\n<p>Then setup an alias in your shell&#8217;s <code>.profile<\/code> (for me, it&#8217;s <code>.bash_profile<\/code>):<\/p>\n<p><code>alias vpn='sudo sshuttle -r &lt;user>@domain.tld -x domain.tld 0\/0'<\/code><\/p>\n<h4>Other things you can do<\/h4>\n<p>According to the full <a href=\"https:\/\/sshuttle.readthedocs.io\/en\/stable\">docs<\/a>, there are a <em>lot<\/em> more things you can do with sshuttle &#8211; including running it on your router, thereby VPN&#8217;ing <em>your whole LAN<\/em> through an endpoint! You can also run it in server mode.<\/p>\n<p>This is a <strong>super<\/strong> useful little utility!<\/p>\n<p>from antipaucity https:\/\/antipaucity.com\/2020\/03\/23\/sshuttle-a-simple-transparent-proxy-vpn-over-ssh\/<br \/>\nvia <a href=\"https:\/\/ifttt.com\/?ref=da&#038;site=wordpress\">IFTTT<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>I found out about sshuttle from a random tweet that happened to catch my eye. Here&#8217;s the skinny (from the readme): Your client machine (or router) is Linux, FreeBSD, or MacOS. You have access to a remote network via ssh. You don&#8217;t necessarily have admin access on the remote network. The remote network has no &hellip;<br \/><a href=\"https:\/\/merikebi.warrenmyers.com\/?p=10275\" class=\"more-link pen_button pen_element_default pen_icon_arrow_double\">Continue reading <span class=\"screen-reader-text\">sshuttle \u2013 a simple transparent proxy vpn over ssh<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_feature_clip_id":0,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_post_was_ever_published":false},"categories":[4],"tags":[95],"keyring_services":[],"class_list":["post-10275","post","type-post","status-publish","format-standard","hentry","category-blih","tag-antipaucity"],"jetpack_sharing_enabled":true,"jetpack_featured_media_url":"","_links":{"self":[{"href":"https:\/\/merikebi.warrenmyers.com\/index.php?rest_route=\/wp\/v2\/posts\/10275","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/merikebi.warrenmyers.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/merikebi.warrenmyers.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/merikebi.warrenmyers.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/merikebi.warrenmyers.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=10275"}],"version-history":[{"count":1,"href":"https:\/\/merikebi.warrenmyers.com\/index.php?rest_route=\/wp\/v2\/posts\/10275\/revisions"}],"predecessor-version":[{"id":10276,"href":"https:\/\/merikebi.warrenmyers.com\/index.php?rest_route=\/wp\/v2\/posts\/10275\/revisions\/10276"}],"wp:attachment":[{"href":"https:\/\/merikebi.warrenmyers.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=10275"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/merikebi.warrenmyers.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=10275"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/merikebi.warrenmyers.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=10275"},{"taxonomy":"keyring_services","embeddable":true,"href":"https:\/\/merikebi.warrenmyers.com\/index.php?rest_route=%2Fwp%2Fv2%2Fkeyring_services&post=10275"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}