Example: SSH into a homelab
A server at home (nas) behind NAT, and a laptop. Both join the tunnel’s
private network, and the laptop SSHes into the server by name from
anywhere, with no port opened on the router.
1. Add the server
Section titled “1. Add the server”In the console, open the tunnel’s Private network tab, click
Add a server, pick A server and click Create key, keeping the
server tag. Copy the command it shows; the key isn’t shown again. Run it
on the server with a name:
sudo towonel mesh up --hub-url https://hub.example.eu --auth-key tmk_… --name nasmesh up stays in the foreground; run it under systemd so it survives
reboots (see keep it running). sshd needs no
change.
2. Add the laptop
Section titled “2. Add the laptop”sudo towonel mesh up --hub-url https://hub.example.euIt opens the console on Add a device with the code filled in (or open
the printed link on another device). Pick the network, type the last 4
letters of the code and click Add to your tunnel.
towonel mesh status on the laptop now lists nas.
3. SSH in
Section titled “3. SSH in”ssh user@nas.towonel.internalThat works while mesh up runs with root on the laptop. Without root, the
laptop gets no towonel0 interface; tunnel SSH through mesh nc instead,
in ~/.ssh/config:
Host nas User user ProxyCommand towonel mesh nc %h %pThen ssh nas. Keep Host equal to the device name and don’t set
HostName: %h is passed to mesh nc as the device to reach.
Only allow SSH
Section titled “Only allow SSH”By default your devices reach every port on a tagged server. To limit the laptop to SSH, open Access policy, click Customize and use:
{ "rules": [ { "from": ["*"], "to": ["self"] }, { "from": ["*"], "to": ["tag:server"], "ports": ["22"], "proto": "tcp" } ], "tests": [ { "from": "laptop", "to": "nas", "port": 22, "allow": true }, { "from": "laptop", "to": "nas", "port": 445, "allow": false } ]}Replace laptop with your laptop’s device name; the tests must pass
before the policy is saved.
Without the console
Section titled “Without the console”A self-hosted hub doesn’t need the web console. With the operator key
(TOWONEL_OPERATOR_KEY, or operator.key on the hub host), create a key
for each device:
towonel mesh auth-key --tenant-id <id> --tag tag:server # for nastowonel mesh auth-key --tenant-id <id> --tag tag:laptop # for the laptopBrowser sign-in needs the console, so the laptop joins with its key like
the server: sudo towonel mesh up --hub-url … --auth-key tmk_…. Tag it:
untagged keys expire after 180 days, and renewing one needs the console.
Tagged devices can’t start connections under the default policy, so allow the laptop to reach SSH:
echo '{"rules": [{"from": ["tag:laptop"], "to": ["tag:server"], "ports": ["22"], "proto": "tcp"}]}' \ | towonel mesh policy set - --tenant-id <id>towonel mesh devices lists the devices, and towonel mesh remove laptop
takes a lost laptop off the network.