Zig Requires Chilkat v11.0.0+
Zig
SSH Tunnel Inside another SSH Tunnel
See more SSH Tunnel Examples
Demonstrates how to create a TCP/IP socket connection through an SSH tunnel that is dynamic port forwarded through another SSH tunnel.Chilkat Zig Downloads
const std = @import("std");
const chilkat = @import("chilkat");
pub fn main(init: std.process.Init) !void {
const alloc = init.arena.allocator();
// This example requires the Chilkat API to have been previously unlocked.
// See Global Unlock Sample for sample code.
const tunnel = try chilkat.SshTunnel.init();
defer tunnel.deinit();
const ssh_hostname = "www.ssh-serverA.com";
const ssh_port = 22;
// Connect to an SSH server and establish the SSH tunnel:
tunnel.connect(ssh_hostname, ssh_port) catch {
std.debug.print("{s}\n", .{try tunnel.getLastErrorText(alloc)});
return;
};
// Authenticate with the SSH server via a login/password
// or with a public key.
// This example demonstrates SSH password authentication.
tunnel.authenticatePw("mySshLogin", "mySshPassword") catch {
std.debug.print("{s}\n", .{try tunnel.getLastErrorText(alloc)});
return;
};
// Indicate that the background SSH tunnel thread will behave as a SOCKS proxy server
// with dynamic port forwarding:
tunnel.setDynamicPortForwarding(true);
// We may optionally require that connecting clients authenticate with our SOCKS proxy server.
// To do this, set an inbound username/password. Any connecting clients would be required to
// use SOCKS5 with the correct username/password.
// If no inbound username/password is set, then our SOCKS proxy server will accept both
// SOCKS4 and SOCKS5 unauthenticated connections.
tunnel.setInboundSocksUsername("chilkat123");
tunnel.setInboundSocksPassword("password123");
// Start the listen/accept thread to begin accepting SOCKS proxy client connections.
// Listen on port 1080.
tunnel.beginAccepting(1080) catch {
std.debug.print("{s}\n", .{try tunnel.getLastErrorText(alloc)});
return;
};
// Now that a background thread is running a SOCKS proxy server that forwards connections
// through an SSH tunnel, it is possible to use any Chilkat implemented protocol that is SOCKS capable,
// such as HTTP, POP3, SMTP, IMAP, FTP, Socket, etc. The protocol may use SSL/TLS because the SSL/TLS
// will be passed through the SSH tunnel to the end-destination. Also, any number of simultaneous
// connections may be routed through the SSH tunnel.
const tunnel_b = try chilkat.Socket.init();
defer tunnel_b.deinit();
// Indicate that the socket object is to use our portable SOCKS proxy/SSH tunnel running in our background thread.
tunnel_b.setSocksHostname("localhost");
tunnel_b.setSocksPort(1080);
tunnel_b.setSocksVersion(5);
tunnel_b.setSocksUsername("chilkat123");
tunnel_b.setSocksPassword("password123");
// Open a new SSH tunnel through the existing tunnel (via what we treat as a SOCKS5 proxy,
// but it is actually a dynamic port-forwarded SSH tunnel).
tunnel_b.sshOpenTunnel("www.ssh-serverB.com", 22) catch {
std.debug.print("{s}\n", .{try tunnel_b.getLastErrorText(alloc)});
return;
};
// Authenticate with ssh-serverB.com
tunnel_b.sshAuthenticatePw("uname", "pwd") catch {
std.debug.print("{s}\n", .{try tunnel_b.getLastErrorText(alloc)});
return;
};
// OK, the SSH tunnel (within a tunnel) is setup. Now open a channel within the tunnel.
// Once the channel is obtained, the Socket API may
// be used exactly the same as usual, except all communications
// are sent through the channel in the SSH tunnel.
// Any number of channels may be created from the same SSH tunnel.
// Multiple channels may coexist at the same time.
// Connect to an NIST time server and read the current date/time
const channel = try chilkat.Socket.init();
defer channel.deinit();
const max_wait_ms = 4000;
const use_tls = false;
tunnel_b.sshNewChannel("time-c.nist.gov", 37, use_tls, max_wait_ms, channel) catch {
std.debug.print("{s}\n", .{try tunnel_b.getLastErrorText(alloc)});
return;
};
// The time server will send a big-endian 32-bit integer representing
// the number of seconds since since 00:00 (midnight) 1 January 1900 GMT.
// The ReceiveInt32 method will receive a 4-byte integer, but returns
// true or false to indicate success. If successful, the integer
// is obtained via the ReceivedInt property.
const big_endian = true;
channel.receiveInt32(big_endian) catch {
std.debug.print("{s}\n", .{try channel.getLastErrorText(alloc)});
return;
};
const dt = try chilkat.DateTime.init();
defer dt.deinit();
dt.setFromNtpTime(channel.getReceivedInt()) catch {};
// Show the current local date/time
const b_local_time = true;
std.debug.print("Current local date/time: {s}\n", .{try dt.getAsRfc822(alloc, b_local_time)});
// Close the SSH channel.
channel.close(max_wait_ms) catch {
std.debug.print("{s}\n", .{try channel.getLastErrorText(alloc)});
return;
};
// Stop the background listen/accept thread:
const wait_for_thread_exit = true;
tunnel.stopAccepting(wait_for_thread_exit) catch {
std.debug.print("{s}\n", .{try tunnel.getLastErrorText(alloc)});
return;
};
// Close the SSH tunnel (would also kick any remaining connected clients).
tunnel.closeTunnel(wait_for_thread_exit) catch {
std.debug.print("{s}\n", .{try tunnel.getLastErrorText(alloc)});
return;
};
}