Sample code for 30+ languages & platforms
DataFlex

SSH Tunnel Dynamic Port Forwarding (Local SOCKS Proxy)

See more SSH Tunnel Examples

Demonstrates dynamic port forwarding with the DynamicPortForwarding, InboundSocksUsername, and InboundSocksPassword properties. In dynamic mode the listener acts as a local SOCKS proxy, so each client chooses its own destination and one tunnel can reach many hosts on the SSH server's network.

Background: This is the ssh -D scenario: instead of pinning one local port to one destination, the tunnel speaks SOCKS and lets each client name where it wants to go. Any SOCKS-capable application — a browser, a mail client — can then reach the remote network through the single tunnel. Setting an inbound SOCKS username and password restricts who may use the local proxy, which matters because it would otherwise accept unauthenticated connections from any local process.

Chilkat DataFlex Downloads

DataFlex
Use ChilkatAx-win32.pkg

Procedure Test
    Boolean iSuccess
    Handle hoTunnel
    Integer iSshPort
    String sPassword
    Integer iListenPort
    Boolean iWaitForThreadExit
    String sTemp1

    Move False To iSuccess

    //  Demonstrates dynamic port forwarding with the SshTunnel properties DynamicPortForwarding,
    //  InboundSocksUsername, and InboundSocksPassword.
    //  
    //  In dynamic mode the listener behaves as a local SOCKS proxy: each client chooses its own
    //  destination, so one tunnel can reach many hosts on the SSH server's network.

    Get Create (RefClass(cComChilkatSshTunnel)) To hoTunnel
    If (Not(IsComObjectCreated(hoTunnel))) Begin
        Send CreateComObject of hoTunnel
    End

    //  Enable dynamic (SOCKS) forwarding instead of a single fixed destination.  No DestHostname or
    //  DestPort is needed.
    Set ComDynamicPortForwarding Of hoTunnel To True

    //  Optionally require inbound SOCKS5 clients to authenticate with the local proxy.  If left unset,
    //  the local proxy accepts unauthenticated SOCKS4 and SOCKS5 connections.
    Set ComInboundSocksUsername Of hoTunnel To "myLocalSocksLogin"
    Set ComInboundSocksPassword Of hoTunnel To "myLocalSocksPassword"

    Move 22 To iSshPort
    Get ComConnect Of hoTunnel "ssh.example.com" iSshPort To iSuccess
    If (iSuccess = False) Begin
        Get ComLastErrorText Of hoTunnel To sTemp1
        Showln sTemp1
        Procedure_Return
    End

    //  Normally you would not hard-code the password in source.  You should instead obtain it
    //  from an interactive prompt, environment variable, or a secrets vault.
    Move "mySshPassword" To sPassword

    Get ComAuthenticatePw Of hoTunnel "mySshLogin" sPassword To iSuccess
    If (iSuccess = False) Begin
        Get ComLastErrorText Of hoTunnel To sTemp1
        Showln sTemp1
        Procedure_Return
    End

    //  Start the local SOCKS proxy on port 1080.  SOCKS-capable clients point at 127.0.0.1:1080.
    Move 1080 To iListenPort
    Get ComBeginAccepting Of hoTunnel iListenPort To iSuccess
    If (iSuccess = False) Begin
        Get ComLastErrorText Of hoTunnel To sTemp1
        Showln sTemp1
        Procedure_Return
    End

    Showln "Local SOCKS proxy running on port " iListenPort

    Move True To iWaitForThreadExit
    Get ComCloseTunnel Of hoTunnel iWaitForThreadExit To iSuccess
    If (iSuccess = False) Begin
        Get ComLastErrorText Of hoTunnel To sTemp1
        Showln sTemp1
        Procedure_Return
    End



End_Procedure