<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Tunnel :: Tag :: Ay Docs</title>
    <link>https://ops.docs.72602.space/tags/tunnel/index.html</link>
    <description></description>
    <generator>Hugo</generator>
    <language>en</language>
    <atom:link href="https://ops.docs.72602.space/tags/tunnel/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>72602-minipc → ecs-99</title>
      <link>https://ops.docs.72602.space/csp/72602/tunnel/minipc-ecs/index.html</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>https://ops.docs.72602.space/csp/72602/tunnel/minipc-ecs/index.html</guid>
      <description>SSH 反向隧道：72602-minipc → ecs-99（双入口） 本文档是 72602-minipc 的当前参考方案；执行前应核对 live unit、ECS 安全组、 SSH banner 和监控状态，目标是避免单端口掉线导致完全失联。&#xA;主入口：10021 备入口：10022 两个端口由两个独立 service 维护 一、架构 已登记且获安全组授权的来源客户端 ecs-99 (47.110.67.161) 72602-minipc (192.168.0.25) ssh -p 10021 aaron@47.110.67.161 -&gt; 0.0.0.0:10021 (sshd) --SSH reverse--&gt; localhost:22 ssh -p 10022 aaron@47.110.67.161 -&gt; 0.0.0.0:10022 (sshd) --SSH reverse--&gt; localhost:22 ECS HAProxy :25/:465/:587/:993 -&gt; 127.0.0.1:10225/:10465/:10587/:10993 (sshd) --SSH reverse--&gt; minipc hostPort :25/:465/:587/:993 说明：反向隧道必须由 72602-minipc 主动发起。0.0.0.0 是 ECS 上 sshd 的 reverse-bind，并不等于对任意公网来源开放；安全组来源限制、SSH key 认证、已建立的 SSH child/session、banner 和监控恢复都必须分别验证。</description>
    </item>
  </channel>
</rss>