cmd/tailcat: support forwarding to exit-node targets - #75
Merged
Conversation
Allow forward mappings to target IP:port destinations reachable through an exit-node server, with end-to-end coverage and README examples.
Member
|
You already have #74 open. Why'd you open a new one? |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What does this change do?
Extend the
tailcat forwardsubcommand to forward local TCP ports toarbitrary IP:port targets reachable through a Tailcat server running as an
exit node.
This is useful for accessing TCP services on remote network assets through
an exit-node server, including applications that only support regular
host:portconnections and do not provide Tailnet, SOCKS, or stdio proxyintegration.
The mapping syntax for exit-node targets is:
The
<addrblob>argument is the address blob printed bytailcat serve,typically a value beginning with
tc.Related to #14.
Examples
Start a Tailcat server in exit-node mode:
tailcat serve exit-node # Server listening with new address: tcXXXXXXXXXForward local ports to two remote network assets:
tailcat forward tcXXXXXXXXX \ 3001:172.23.52.30:3001 \ 17170:172.23.52.31:17170This forwards:
Regular forwarding to ports served directly by the Tailcat server continues
to work:
tailcat serve 8080,3306 # Server listening with new address: tcXXXXXXXXX tailcat forward tcXXXXXXXXX 18080:8080 3306By default, local listeners bind to
127.0.0.1. Use--bindwhen aspecific local address is required:
tailcat forward --bind=0.0.0.0 tcXXXXXXXXX \ 3001:172.23.52.30:3001 \ 17170:172.23.52.31:17170Use
--bind=0.0.0.0only when intentionally allowing connections fromother network interfaces.
Design
Client.DialTCPAPI for exit-node IP:port targets.Client.DialTCPPortAPI for ports served by Tailcat.ProxyConnshelper.<remote-port>and<local>:<remote-port>mappings.127.0.0.1by default.Testing
port.
Tested with: