Xbase++ Requires Chilkat v11.0.0+
Xbase++
SSH Tunnel Inside another SSH Tunnel
See more SSH Tunnel Examples
Demonstrates how to create a TCP/IP socket connection through an SSH tunnel that is dynamic port forwarded through another SSH tunnel.Chilkat Xbase++ Downloads
LOCAL nSuccess
LOCAL oTunnel
LOCAL cSshHostname
LOCAL nSshPort
LOCAL oTunnelB
LOCAL oChannel
LOCAL nMaxWaitMs
LOCAL nUseTls
LOCAL nBigEndian
LOCAL oDt
LOCAL nBLocalTime
LOCAL nWaitForThreadExit
nSuccess := 0
// This example requires the Chilkat API to have been previously unlocked.
// See Global Unlock Sample for sample code.
oTunnel := CreateObject("Chilkat.SshTunnel")
cSshHostname := "www.ssh-serverA.com"
nSshPort := 22
// Connect to an SSH server and establish the SSH tunnel:
nSuccess := oTunnel:Connect(cSshHostname, nSshPort)
IF (nSuccess == 0)
? oTunnel:LastErrorText
oTunnel:destroy()
RETURN
ENDIF
// Authenticate with the SSH server via a login/password
// or with a public key.
// This example demonstrates SSH password authentication.
nSuccess := oTunnel:AuthenticatePw("mySshLogin", "mySshPassword")
IF (nSuccess == 0)
? oTunnel:LastErrorText
oTunnel:destroy()
RETURN
ENDIF
// Indicate that the background SSH tunnel thread will behave as a SOCKS proxy server
// with dynamic port forwarding:
oTunnel:DynamicPortForwarding := 1
// We may optionally require that connecting clients authenticate with our SOCKS proxy server.
// To do this, set an inbound username/password. Any connecting clients would be required to
// use SOCKS5 with the correct username/password.
// If no inbound username/password is set, then our SOCKS proxy server will accept both
// SOCKS4 and SOCKS5 unauthenticated connections.
oTunnel:InboundSocksUsername := "chilkat123"
oTunnel:InboundSocksPassword := "password123"
// Start the listen/accept thread to begin accepting SOCKS proxy client connections.
// Listen on port 1080.
nSuccess := oTunnel:BeginAccepting(1080)
IF (nSuccess == 0)
? oTunnel:LastErrorText
oTunnel:destroy()
RETURN
ENDIF
// Now that a background thread is running a SOCKS proxy server that forwards connections
// through an SSH tunnel, it is possible to use any Chilkat implemented protocol that is SOCKS capable,
// such as HTTP, POP3, SMTP, IMAP, FTP, Socket, etc. The protocol may use SSL/TLS because the SSL/TLS
// will be passed through the SSH tunnel to the end-destination. Also, any number of simultaneous
// connections may be routed through the SSH tunnel.
oTunnelB := CreateObject("Chilkat.Socket")
// Indicate that the socket object is to use our portable SOCKS proxy/SSH tunnel running in our background thread.
oTunnelB:SocksHostname := "localhost"
oTunnelB:SocksPort := 1080
oTunnelB:SocksVersion := 5
oTunnelB:SocksUsername := "chilkat123"
oTunnelB:SocksPassword := "password123"
// Open a new SSH tunnel through the existing tunnel (via what we treat as a SOCKS5 proxy,
// but it is actually a dynamic port-forwarded SSH tunnel).
nSuccess := oTunnelB:SshOpenTunnel("www.ssh-serverB.com", 22)
IF (nSuccess == 0)
? oTunnelB:LastErrorText
oTunnel:destroy()
oTunnelB:destroy()
RETURN
ENDIF
// Authenticate with ssh-serverB.com
nSuccess := oTunnelB:SshAuthenticatePw("uname", "pwd")
IF (nSuccess == 0)
? oTunnelB:LastErrorText
oTunnel:destroy()
oTunnelB:destroy()
RETURN
ENDIF
// OK, the SSH tunnel (within a tunnel) is setup. Now open a channel within the tunnel.
// Once the channel is obtained, the Socket API may
// be used exactly the same as usual, except all communications
// are sent through the channel in the SSH tunnel.
// Any number of channels may be created from the same SSH tunnel.
// Multiple channels may coexist at the same time.
// Connect to an NIST time server and read the current date/time
oChannel := CreateObject("Chilkat.Socket")
nMaxWaitMs := 4000
nUseTls := 0
nSuccess := oTunnelB:SshNewChannel("time-c.nist.gov", 37, nUseTls, nMaxWaitMs, oChannel)
IF (nSuccess == 0)
? oTunnelB:LastErrorText
oTunnel:destroy()
oTunnelB:destroy()
oChannel:destroy()
RETURN
ENDIF
// The time server will send a big-endian 32-bit integer representing
// the number of seconds since since 00:00 (midnight) 1 January 1900 GMT.
// The ReceiveInt32 method will receive a 4-byte integer, but returns
// 1 or 0 to indicate success. If successful, the integer
// is obtained via the ReceivedInt property.
nBigEndian := 1
nSuccess := oChannel:ReceiveInt32(nBigEndian)
IF (nSuccess == 0)
? oChannel:LastErrorText
oTunnel:destroy()
oTunnelB:destroy()
oChannel:destroy()
RETURN
ENDIF
oDt := CreateObject("Chilkat.CkDateTime")
oDt:SetFromNtpTime(oChannel:ReceivedInt)
// Show the current local date/time
nBLocalTime := 1
? "Current local date/time: " + oDt:GetAsRfc822(nBLocalTime)
// Close the SSH channel.
nSuccess := oChannel:Close(nMaxWaitMs)
IF (nSuccess == 0)
? oChannel:LastErrorText
oTunnel:destroy()
oTunnelB:destroy()
oChannel:destroy()
oDt:destroy()
RETURN
ENDIF
// Stop the background listen/accept thread:
nWaitForThreadExit := 1
nSuccess := oTunnel:StopAccepting(nWaitForThreadExit)
IF (nSuccess == 0)
? oTunnel:LastErrorText
oTunnel:destroy()
oTunnelB:destroy()
oChannel:destroy()
oDt:destroy()
RETURN
ENDIF
// Close the SSH tunnel (would also kick any remaining connected clients).
nSuccess := oTunnel:CloseTunnel(nWaitForThreadExit)
IF (nSuccess == 0)
? oTunnel:LastErrorText
oTunnel:destroy()
oTunnelB:destroy()
oChannel:destroy()
oDt:destroy()
RETURN
ENDIF
oTunnel:destroy()
oTunnelB:destroy()
oChannel:destroy()
oDt:destroy()