Sample code for 30+ languages & platforms
Tcl

Connect to an SSH Server Through Another (Jump Host)

See more SSH Examples

Demonstrates the Chilkat Ssh.ConnectThroughSsh method, which connects to a second SSH server through an already connected and authenticated Ssh object. The first argument is the first (jump-host) Ssh object, and the second and third are the destination hostname and port.

Background: This is SSH chaining through a "jump host" (bastion): the application connects to a reachable gateway, then tunnels onward to a target that is only accessible from inside the network. Each hop is authenticated separately with its own credentials. The result is a normal Ssh object for the target that happens to be routed through the first connection.

Chilkat Tcl Downloads

Tcl

load ./chilkat.dll

set success 0

#  Demonstrates the Ssh.ConnectThroughSsh method, which connects to a second SSH server through
#  an already connected and authenticated Ssh object (a jump host).  The 1st argument is the
#  first Ssh object, and the 2nd and 3rd are the destination hostname and port.

set sshJump [new_CkSsh]

#  Connect and authenticate to the first SSH server (the jump host).
set sshPort 22
set success [CkSsh_Connect $sshJump "jump.example.com" $sshPort]
if {$success == 0} then {
    puts [CkSsh_lastErrorText $sshJump]
    delete_CkSsh $sshJump
    exit
}

#  Normally you would not hard-code the password in source.  You should instead obtain it
#  from an interactive prompt, environment variable, or a secrets vault.
set password "mySshPassword"

set success [CkSsh_AuthenticatePw $sshJump "jumpUser" $password]
if {$success == 0} then {
    puts [CkSsh_lastErrorText $sshJump]
    delete_CkSsh $sshJump
    exit
}

#  Connect to the target SSH server through the jump host.
set sshTarget [new_CkSsh]

set success [CkSsh_ConnectThroughSsh $sshTarget $sshJump "target.example.com" $sshPort]
if {$success == 0} then {
    puts [CkSsh_lastErrorText $sshTarget]
    delete_CkSsh $sshJump
    delete_CkSsh $sshTarget
    exit
}

#  Authenticate to the target server (separate credentials).
set success [CkSsh_AuthenticatePw $sshTarget "targetUser" $password]
if {$success == 0} then {
    puts [CkSsh_lastErrorText $sshTarget]
    delete_CkSsh $sshJump
    delete_CkSsh $sshTarget
    exit
}

puts "Connected to the target through the jump host."

CkSsh_Disconnect $sshTarget
CkSsh_Disconnect $sshJump

delete_CkSsh $sshJump
delete_CkSsh $sshTarget