Access to the internet from a firewalled server












1















I'm trying to set up a test Docker platform at work. I need pull images, but can't do so because the test server does not have direct internet access (firewalled). There is another server that can connect to the internet, but only through a proxy. Between the test server and internet-accessible server, only a handful of ports are open. I'm thinking I could set up a tunnel between both, but not sure how.



Ports open from Test server to Internet-accessible:



80/tcp
111/tcp
2049/tcp
7001/tcp
7002/tcp


Ports open from Internet-accessible to Test:



22/tcp
1720/tcp


I have http_proxy configured in .bash_profile, on the Internet-accessible server:



export http_proxy=http://username:password@internet-server:8080/









share|improve this question

























  • What use is that http_proxy definition if port 8080 isn't accessible? Or is that the point of the question? Or is that proxy actually a third server that you haven't mentioned?

    – roaima
    Apr 14 '16 at 22:38













  • The internet-accessible server uses an authenticated proxy on port 8080. If I need to get anything from the web (eg wget) on that host, I have to use the proxy.

    – Dave
    Apr 14 '16 at 23:58













  • Just so that I'm clear; I want to be able to use wget/curl to fetch packages on the test server, through the internet-accessible server.

    – Dave
    Apr 15 '16 at 0:01


















1















I'm trying to set up a test Docker platform at work. I need pull images, but can't do so because the test server does not have direct internet access (firewalled). There is another server that can connect to the internet, but only through a proxy. Between the test server and internet-accessible server, only a handful of ports are open. I'm thinking I could set up a tunnel between both, but not sure how.



Ports open from Test server to Internet-accessible:



80/tcp
111/tcp
2049/tcp
7001/tcp
7002/tcp


Ports open from Internet-accessible to Test:



22/tcp
1720/tcp


I have http_proxy configured in .bash_profile, on the Internet-accessible server:



export http_proxy=http://username:password@internet-server:8080/









share|improve this question

























  • What use is that http_proxy definition if port 8080 isn't accessible? Or is that the point of the question? Or is that proxy actually a third server that you haven't mentioned?

    – roaima
    Apr 14 '16 at 22:38













  • The internet-accessible server uses an authenticated proxy on port 8080. If I need to get anything from the web (eg wget) on that host, I have to use the proxy.

    – Dave
    Apr 14 '16 at 23:58













  • Just so that I'm clear; I want to be able to use wget/curl to fetch packages on the test server, through the internet-accessible server.

    – Dave
    Apr 15 '16 at 0:01
















1












1








1








I'm trying to set up a test Docker platform at work. I need pull images, but can't do so because the test server does not have direct internet access (firewalled). There is another server that can connect to the internet, but only through a proxy. Between the test server and internet-accessible server, only a handful of ports are open. I'm thinking I could set up a tunnel between both, but not sure how.



Ports open from Test server to Internet-accessible:



80/tcp
111/tcp
2049/tcp
7001/tcp
7002/tcp


Ports open from Internet-accessible to Test:



22/tcp
1720/tcp


I have http_proxy configured in .bash_profile, on the Internet-accessible server:



export http_proxy=http://username:password@internet-server:8080/









share|improve this question
















I'm trying to set up a test Docker platform at work. I need pull images, but can't do so because the test server does not have direct internet access (firewalled). There is another server that can connect to the internet, but only through a proxy. Between the test server and internet-accessible server, only a handful of ports are open. I'm thinking I could set up a tunnel between both, but not sure how.



Ports open from Test server to Internet-accessible:



80/tcp
111/tcp
2049/tcp
7001/tcp
7002/tcp


Ports open from Internet-accessible to Test:



22/tcp
1720/tcp


I have http_proxy configured in .bash_profile, on the Internet-accessible server:



export http_proxy=http://username:password@internet-server:8080/






linux firewall proxy






share|improve this question















share|improve this question













share|improve this question




share|improve this question








edited 2 hours ago









Rui F Ribeiro

41.3k1481140




41.3k1481140










asked Apr 14 '16 at 21:37









DaveDave

219




219













  • What use is that http_proxy definition if port 8080 isn't accessible? Or is that the point of the question? Or is that proxy actually a third server that you haven't mentioned?

    – roaima
    Apr 14 '16 at 22:38













  • The internet-accessible server uses an authenticated proxy on port 8080. If I need to get anything from the web (eg wget) on that host, I have to use the proxy.

    – Dave
    Apr 14 '16 at 23:58













  • Just so that I'm clear; I want to be able to use wget/curl to fetch packages on the test server, through the internet-accessible server.

    – Dave
    Apr 15 '16 at 0:01





















  • What use is that http_proxy definition if port 8080 isn't accessible? Or is that the point of the question? Or is that proxy actually a third server that you haven't mentioned?

    – roaima
    Apr 14 '16 at 22:38













  • The internet-accessible server uses an authenticated proxy on port 8080. If I need to get anything from the web (eg wget) on that host, I have to use the proxy.

    – Dave
    Apr 14 '16 at 23:58













  • Just so that I'm clear; I want to be able to use wget/curl to fetch packages on the test server, through the internet-accessible server.

    – Dave
    Apr 15 '16 at 0:01



















What use is that http_proxy definition if port 8080 isn't accessible? Or is that the point of the question? Or is that proxy actually a third server that you haven't mentioned?

– roaima
Apr 14 '16 at 22:38







What use is that http_proxy definition if port 8080 isn't accessible? Or is that the point of the question? Or is that proxy actually a third server that you haven't mentioned?

– roaima
Apr 14 '16 at 22:38















The internet-accessible server uses an authenticated proxy on port 8080. If I need to get anything from the web (eg wget) on that host, I have to use the proxy.

– Dave
Apr 14 '16 at 23:58







The internet-accessible server uses an authenticated proxy on port 8080. If I need to get anything from the web (eg wget) on that host, I have to use the proxy.

– Dave
Apr 14 '16 at 23:58















Just so that I'm clear; I want to be able to use wget/curl to fetch packages on the test server, through the internet-accessible server.

– Dave
Apr 15 '16 at 0:01







Just so that I'm clear; I want to be able to use wget/curl to fetch packages on the test server, through the internet-accessible server.

– Dave
Apr 15 '16 at 0:01












2 Answers
2






active

oldest

votes


















1














You could set up a ssh-based virtual private network using the tun network pseudo-device; man ssh gives an example. If you don't have admin access on the internet-accessible server you might consider sshuttle to accomplish the same thing.






share|improve this answer































    1














    I got this working.



    From the server which has internet-access:



    ssh -R any-port:proxy-ip:proxy-port user@testserver


    Then, once I'm on the test server:



    export http_prox=http://username:password@localhost:any-port/


    eg:



    ssh -R 2001:proxy-ip:8080 root@testserver

    [root@testserver]# export http_proxy=http://proxyuser:proxyuser-password@localhost:2001/
    [root@testserver]# export https_proxy=https://proxyuser:proxyuser-password@localhost:2001/





    share|improve this answer























      Your Answer








      StackExchange.ready(function() {
      var channelOptions = {
      tags: "".split(" "),
      id: "106"
      };
      initTagRenderer("".split(" "), "".split(" "), channelOptions);

      StackExchange.using("externalEditor", function() {
      // Have to fire editor after snippets, if snippets enabled
      if (StackExchange.settings.snippets.snippetsEnabled) {
      StackExchange.using("snippets", function() {
      createEditor();
      });
      }
      else {
      createEditor();
      }
      });

      function createEditor() {
      StackExchange.prepareEditor({
      heartbeatType: 'answer',
      autoActivateHeartbeat: false,
      convertImagesToLinks: false,
      noModals: true,
      showLowRepImageUploadWarning: true,
      reputationToPostImages: null,
      bindNavPrevention: true,
      postfix: "",
      imageUploader: {
      brandingHtml: "Powered by u003ca class="icon-imgur-white" href="https://imgur.com/"u003eu003c/au003e",
      contentPolicyHtml: "User contributions licensed under u003ca href="https://creativecommons.org/licenses/by-sa/3.0/"u003ecc by-sa 3.0 with attribution requiredu003c/au003e u003ca href="https://stackoverflow.com/legal/content-policy"u003e(content policy)u003c/au003e",
      allowUrls: true
      },
      onDemand: true,
      discardSelector: ".discard-answer"
      ,immediatelyShowMarkdownHelp:true
      });


      }
      });














      draft saved

      draft discarded


















      StackExchange.ready(
      function () {
      StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2funix.stackexchange.com%2fquestions%2f276567%2faccess-to-the-internet-from-a-firewalled-server%23new-answer', 'question_page');
      }
      );

      Post as a guest















      Required, but never shown

























      2 Answers
      2






      active

      oldest

      votes








      2 Answers
      2






      active

      oldest

      votes









      active

      oldest

      votes






      active

      oldest

      votes









      1














      You could set up a ssh-based virtual private network using the tun network pseudo-device; man ssh gives an example. If you don't have admin access on the internet-accessible server you might consider sshuttle to accomplish the same thing.






      share|improve this answer




























        1














        You could set up a ssh-based virtual private network using the tun network pseudo-device; man ssh gives an example. If you don't have admin access on the internet-accessible server you might consider sshuttle to accomplish the same thing.






        share|improve this answer


























          1












          1








          1







          You could set up a ssh-based virtual private network using the tun network pseudo-device; man ssh gives an example. If you don't have admin access on the internet-accessible server you might consider sshuttle to accomplish the same thing.






          share|improve this answer













          You could set up a ssh-based virtual private network using the tun network pseudo-device; man ssh gives an example. If you don't have admin access on the internet-accessible server you might consider sshuttle to accomplish the same thing.







          share|improve this answer












          share|improve this answer



          share|improve this answer










          answered Apr 15 '16 at 0:29









          neofugneofug

          1413




          1413

























              1














              I got this working.



              From the server which has internet-access:



              ssh -R any-port:proxy-ip:proxy-port user@testserver


              Then, once I'm on the test server:



              export http_prox=http://username:password@localhost:any-port/


              eg:



              ssh -R 2001:proxy-ip:8080 root@testserver

              [root@testserver]# export http_proxy=http://proxyuser:proxyuser-password@localhost:2001/
              [root@testserver]# export https_proxy=https://proxyuser:proxyuser-password@localhost:2001/





              share|improve this answer




























                1














                I got this working.



                From the server which has internet-access:



                ssh -R any-port:proxy-ip:proxy-port user@testserver


                Then, once I'm on the test server:



                export http_prox=http://username:password@localhost:any-port/


                eg:



                ssh -R 2001:proxy-ip:8080 root@testserver

                [root@testserver]# export http_proxy=http://proxyuser:proxyuser-password@localhost:2001/
                [root@testserver]# export https_proxy=https://proxyuser:proxyuser-password@localhost:2001/





                share|improve this answer


























                  1












                  1








                  1







                  I got this working.



                  From the server which has internet-access:



                  ssh -R any-port:proxy-ip:proxy-port user@testserver


                  Then, once I'm on the test server:



                  export http_prox=http://username:password@localhost:any-port/


                  eg:



                  ssh -R 2001:proxy-ip:8080 root@testserver

                  [root@testserver]# export http_proxy=http://proxyuser:proxyuser-password@localhost:2001/
                  [root@testserver]# export https_proxy=https://proxyuser:proxyuser-password@localhost:2001/





                  share|improve this answer













                  I got this working.



                  From the server which has internet-access:



                  ssh -R any-port:proxy-ip:proxy-port user@testserver


                  Then, once I'm on the test server:



                  export http_prox=http://username:password@localhost:any-port/


                  eg:



                  ssh -R 2001:proxy-ip:8080 root@testserver

                  [root@testserver]# export http_proxy=http://proxyuser:proxyuser-password@localhost:2001/
                  [root@testserver]# export https_proxy=https://proxyuser:proxyuser-password@localhost:2001/






                  share|improve this answer












                  share|improve this answer



                  share|improve this answer










                  answered Apr 19 '16 at 2:40









                  DaveDave

                  219




                  219






























                      draft saved

                      draft discarded




















































                      Thanks for contributing an answer to Unix & Linux Stack Exchange!


                      • Please be sure to answer the question. Provide details and share your research!

                      But avoid



                      • Asking for help, clarification, or responding to other answers.

                      • Making statements based on opinion; back them up with references or personal experience.


                      To learn more, see our tips on writing great answers.




                      draft saved


                      draft discarded














                      StackExchange.ready(
                      function () {
                      StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2funix.stackexchange.com%2fquestions%2f276567%2faccess-to-the-internet-from-a-firewalled-server%23new-answer', 'question_page');
                      }
                      );

                      Post as a guest















                      Required, but never shown





















































                      Required, but never shown














                      Required, but never shown












                      Required, but never shown







                      Required, but never shown

































                      Required, but never shown














                      Required, but never shown












                      Required, but never shown







                      Required, but never shown







                      Popular posts from this blog

                      サソリ

                      広島県道265号伴広島線

                      Setup Asymptote in Texstudio