Skip to content

Example: SSH into a homelab

A server at home (nas) behind NAT, and a laptop. Both join the tunnel’s private network, and the laptop SSHes into the server by name from anywhere, with no port opened on the router.

In the console, open the tunnel’s Private network tab, click Add a server, pick A server and click Create key, keeping the server tag. Copy the command it shows; the key isn’t shown again. Run it on the server with a name:

Terminal window
sudo towonel mesh up --hub-url https://hub.example.eu --auth-key tmk_… --name nas

mesh up stays in the foreground; run it under systemd so it survives reboots (see keep it running). sshd needs no change.

Terminal window
sudo towonel mesh up --hub-url https://hub.example.eu

It opens the console on Add a device with the code filled in (or open the printed link on another device). Pick the network, type the last 4 letters of the code and click Add to your tunnel. towonel mesh status on the laptop now lists nas.

Terminal window
ssh user@nas.towonel.internal

That works while mesh up runs with root on the laptop. Without root, the laptop gets no towonel0 interface; tunnel SSH through mesh nc instead, in ~/.ssh/config:

Host nas
User user
ProxyCommand towonel mesh nc %h %p

Then ssh nas. Keep Host equal to the device name and don’t set HostName: %h is passed to mesh nc as the device to reach.

By default your devices reach every port on a tagged server. To limit the laptop to SSH, open Access policy, click Customize and use:

{
"rules": [
{ "from": ["*"], "to": ["self"] },
{ "from": ["*"], "to": ["tag:server"], "ports": ["22"], "proto": "tcp" }
],
"tests": [
{ "from": "laptop", "to": "nas", "port": 22, "allow": true },
{ "from": "laptop", "to": "nas", "port": 445, "allow": false }
]
}

Replace laptop with your laptop’s device name; the tests must pass before the policy is saved.

A self-hosted hub doesn’t need the web console. With the operator key (TOWONEL_OPERATOR_KEY, or operator.key on the hub host), create a key for each device:

Terminal window
towonel mesh auth-key --tenant-id <id> --tag tag:server # for nas
towonel mesh auth-key --tenant-id <id> --tag tag:laptop # for the laptop

Browser sign-in needs the console, so the laptop joins with its key like the server: sudo towonel mesh up --hub-url … --auth-key tmk_…. Tag it: untagged keys expire after 180 days, and renewing one needs the console.

Tagged devices can’t start connections under the default policy, so allow the laptop to reach SSH:

Terminal window
echo '{"rules": [{"from": ["tag:laptop"], "to": ["tag:server"], "ports": ["22"], "proto": "tcp"}]}' \
| towonel mesh policy set - --tenant-id <id>

towonel mesh devices lists the devices, and towonel mesh remove laptop takes a lost laptop off the network.