Jump hosts
A jump host, or bastion, is a server you go through to reach one you cannot
reach directly. etrans does what ssh -J does: it connects and logs in to the
jump host, asks it for a tunnel to the next server, and connects through that.
Nothing is run on the jump host.
Setting one up
In the server's form, fill in Jump host with either:
- the name of a saved server, which logs in the way that server is set up to,
- or an address,
user@hostoruser@host:port, which logs in automatically.
Several jump hosts are separated by commas, nearest first:
bastion, ops@inner-gateway:2200
When the field is empty, a ProxyJump for the host in ~/.ssh/config is used.
ProxyJump none there means no jump host.
What you see
- Each hop has its own host key check and login, so a first connection may ask about two fingerprints, and two passwords if neither has a key that works.
- The title bar says where you are and how:
web-1 via bastion. - Transfers, the terminal and port forwarding all go through the same tunnel.
When it does not work
- bastion could not reach web-1:22: it does not allow forwarding. Its sshd_config needs AllowTcpForwarding yes. The jump host refuses to open tunnels. Whoever runs it has to allow it.
- bastion could not reach web-1:22: nothing answered there. The jump host could not connect onward: the name, the port, or a firewall between them.
- Could not go through the jump host bastion: … Logging in to the jump host itself failed; the rest of the message says why.
A server cannot be its own jump host, and more than eight hops is refused as a loop.