Urgent.News

What's breaking now, across thousands of outlets.

Tech

Port Forwarding: Linux has low level networking tools by the way.

Introduction: Explaining why I talk about this in the first place While we encounter day to day with full-blown proxy like Envoy, Nginx, or Caddy, I would like to share very useful Linux low level tools that can be used either for your home lab, debugging, etc. Remember: always man the tool and read there, staying in terminal saves time and keeps u focused. SSH port forwarding is a tunnel, socat…

Port forwarding is a technique that allows a service running on one machine to be accessed from other machines on the network. While proxy applications like Envoy, Nginx, and Caddy are commonly used for this purpose, Linux also offers low-level tools that can be utilized for home labs and debugging purposes.

One such tool is ssh port forwarding, which creates a secure tunnel and requires authentication on the remote end. However, socat is an alternative that functions as a relay, passing data between two addresses without encryption or authentication.

Socat, short for SOcket CAT, stands for a versatile tool that can copy data between various types of addresses, including TCP ports, UDP ports, UNIX sockets, files, and serial devices. To set up port forwarding using socat, install it with the command "apt install socat".

Imagine a scenario where a service is running on a server and listening on port 5000 (127.0.0.1:5000). To make this service accessible from other machines on the network, we can configure socat to listen on port 6000 (tcp-listen:6000,bind=0.0.0.0,fork) and forward incoming TCP connections to the local service (tcp:127.0.0.1:5000).

The "tcp-listen" option allows socat to accept connections on port 6000, while "bind=0.0.0.0" ensures it listens on all the server's network interfaces. The "fork" option creates a new child process for each client, enabling socat to handle multiple connections simultaneously.

From a security standpoint, it is crucial to remember that socat does not provide encryption or authentication. While using socat on a trusted home network may be acceptable, any deployment beyond that environment should incorporate SSH or TLS to secure the connection. Socat supports TLS through its "OPENSSL" addresses, but this requires setting up certificates independently. Importantly, socat does not offer authentication, meaning anyone with access to port 6000 will have direct access to the remote service.

Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at dev.to →

More in Tech

More from Monday 28 September →