Transparent proxy server that works as a poor man's VPN. Forwards over ssh. Doesn't require admin. Works with Linux and MacOS. Supports DNS tunneling.
Go to file
2021-05-10 20:53:51 +10:00
.github Create Dependabot config file 2021-04-08 01:40:51 +00:00
bin Auto sudoers file (#269) 2019-12-13 08:15:31 +11:00
docs Allow comments in configuration file 2021-02-16 07:51:32 +11:00
sshuttle Warn about adding sshuttle to sudoers. 2021-05-07 14:13:56 -04:00
tests firewall: Allow overriding the TTL 2021-03-05 08:53:53 +11:00
.gitignore Add .gitignore .vscode/ path. Resolve the issue #374 adding tproxy mark option to allow different network mapping. 2020-12-28 10:20:46 +11:00
.prospector.yml Fixes some style issues and minor bugs 2017-11-13 11:58:43 +11:00
bandit.yml updated bandit config 2018-10-17 20:52:04 +11:00
CHANGES.rst Release version 1.0.5 2020-12-29 10:34:58 +11:00
LICENSE Change license text to LGPL-2.1 2020-08-26 12:25:36 -04:00
MANIFEST.in Fix error in requirements.rst 2017-07-09 09:08:48 +10:00
README.rst README.rst: fix Gentoo entry syntax 2021-04-26 16:22:42 +01:00
requirements-tests.txt Bump flake8 from 3.9.1 to 3.9.2 2021-05-10 10:00:12 +00:00
requirements.txt Bump setuptools-scm from 5.0.2 to 6.0.1 2021-03-18 06:10:30 +00:00
run Updated supported Python versions 2020-05-29 07:44:51 +10:00
setup.cfg Fix/pep8 (#277) 2019-02-11 09:59:13 +11:00
setup.py feat: remove mock from test dependencies. 2021-01-17 15:42:55 +11:00
tox.ini remove py35 from tox.ini 2021-01-17 15:42:24 +11:00

sshuttle: where transparent proxy meets VPN meets ssh
=====================================================

As far as I know, sshuttle is the only program that solves the following
common case:

- Your client machine (or router) is Linux, FreeBSD, or MacOS.

- You have access to a remote network via ssh.

- You don't necessarily have admin access on the remote network.

- The remote network has no VPN, or only stupid/complex VPN
  protocols (IPsec, PPTP, etc). Or maybe you *are* the
  admin and you just got frustrated with the awful state of
  VPN tools.

- You don't want to create an ssh port forward for every
  single host/port on the remote network.

- You hate openssh's port forwarding because it's randomly
  slow and/or stupid.

- You can't use openssh's PermitTunnel feature because
  it's disabled by default on openssh servers; plus it does
  TCP-over-TCP, which has `terrible performance`_.
  
.. _terrible performance: https://sshuttle.readthedocs.io/en/stable/how-it-works.html

Obtaining sshuttle
------------------

- Ubuntu 16.04 or later::

      apt-get install sshuttle

- Debian stretch or later::

      apt-get install sshuttle
      
- Arch Linux::

      pacman -S sshuttle

- Fedora::

      dnf install sshuttle
      
 - Gentoo::
 
      emerge -av net-proxy/sshuttle

- NixOS::

      nix-env -iA nixos.sshuttle

- From PyPI::

      sudo pip install sshuttle

- Clone::

      git clone https://github.com/sshuttle/sshuttle.git
      cd sshuttle
      sudo ./setup.py install

- FreeBSD::

      # ports
      cd /usr/ports/net/py-sshuttle && make install clean
      # pkg
      pkg install py36-sshuttle

- macOS, via MacPorts::

      sudo port selfupdate
      sudo port install sshuttle

It is also possible to install into a virtualenv as a non-root user.

- From PyPI::

      virtualenv -p python3 /tmp/sshuttle
      . /tmp/sshuttle/bin/activate
      pip install sshuttle

- Clone::

      virtualenv -p python3 /tmp/sshuttle
      . /tmp/sshuttle/bin/activate
      git clone https://github.com/sshuttle/sshuttle.git
      cd sshuttle
      ./setup.py install

- Homebrew::

      brew install sshuttle

- Nix::

      nix-env -iA nixpkgs.sshuttle


Documentation
-------------
The documentation for the stable version is available at:
https://sshuttle.readthedocs.org/

The documentation for the latest development version is available at:
https://sshuttle.readthedocs.org/en/latest/


Running as a service
--------------------
Sshuttle can also be run as a service and configured using a config management system: 
https://medium.com/@mike.reider/using-sshuttle-as-a-service-bec2684a65fe