Sample code for 30+ languages & platforms
CkPython

Connect to an SSH Server Through Another (Jump Host)

See more SSH Examples

Demonstrates the Chilkat Ssh.ConnectThroughSsh method, which connects to a second SSH server through an already connected and authenticated Ssh object. The first argument is the first (jump-host) Ssh object, and the second and third are the destination hostname and port.

Background: This is SSH chaining through a "jump host" (bastion): the application connects to a reachable gateway, then tunnels onward to a target that is only accessible from inside the network. Each hop is authenticated separately with its own credentials. The result is a normal Ssh object for the target that happens to be routed through the first connection.

Chilkat CkPython Downloads

CkPython
import sys
import chilkat

success = False

#  Demonstrates the Ssh.ConnectThroughSsh method, which connects to a second SSH server through
#  an already connected and authenticated Ssh object (a jump host).  The 1st argument is the
#  first Ssh object, and the 2nd and 3rd are the destination hostname and port.

sshJump = chilkat.CkSsh()

#  Connect and authenticate to the first SSH server (the jump host).
sshPort = 22
success = sshJump.Connect("jump.example.com",sshPort)
if (success == False):
    print(sshJump.lastErrorText())
    sys.exit()

#  Normally you would not hard-code the password in source.  You should instead obtain it
#  from an interactive prompt, environment variable, or a secrets vault.
password = "mySshPassword"

success = sshJump.AuthenticatePw("jumpUser",password)
if (success == False):
    print(sshJump.lastErrorText())
    sys.exit()

#  Connect to the target SSH server through the jump host.
sshTarget = chilkat.CkSsh()
success = sshTarget.ConnectThroughSsh(sshJump,"target.example.com",sshPort)
if (success == False):
    print(sshTarget.lastErrorText())
    sys.exit()

#  Authenticate to the target server (separate credentials).
success = sshTarget.AuthenticatePw("targetUser",password)
if (success == False):
    print(sshTarget.lastErrorText())
    sys.exit()

print("Connected to the target through the jump host.")

sshTarget.Disconnect()
sshJump.Disconnect()