使用Paramiko从Windows跳板机(RDP)连接Unix主机的报错问题及参数dest_addr/local_addr获取方法咨询
Troubleshooting Paramiko Connection Issues with Windows Jump Host & Direct-TCPIP Parameters
Let's break down your problems one by one, with practical fixes and explanations:
1. Fixing the WinError 10060 Connection Timeout
The WinError 10060 timeout error has a straightforward root cause: your Windows jump host doesn’t have an SSH server enabled by default. Unlike Unix-like systems, Windows doesn’t ship with an SSH daemon (sshd) pre-installed, so Paramiko can’t establish an SSH connection to it on port 22.
Here’s how to resolve this:
- Enable OpenSSH Server on Windows:
- Go to Settings > Apps > Optional features > Add a feature
- Search for "OpenSSH Server", select it, and install the feature
- Open the Services app (run
services.msc), find "OpenSSH SSH Server", set its startup type to Automatic, and start the service
- Check Firewall Rules: Ensure Windows Firewall allows incoming TCP connections on port 22. Create an inbound rule for port 22 if it doesn’t exist.
- Verify Username Format: For domain accounts, use the format
DOMAIN\UsernameorUsername@domain.cominstead of just the username. Local accounts usually work with the plain username, but double-check your environment’s requirements.
2. Understanding dest_addr and local_addr in Direct-TCPIP Channels
Let’s clarify what these parameters do when creating the tunnel:
dest_addr: This is the SSH endpoint of the target Unix host you want to reach through the jump machine. It’s exactly the same IP and port (usually 22) you used when connecting via PuTTY from the jump host. Your example value('10.103.53.26', 22)is correct if that’s your Unix host’s address.local_addr: This is the local IP and port on the jump host that initiates the connection to the target Unix host. You don’t need to specify a fixed value like('192.168.115.103', 22)—instead, use('0.0.0.0', 0)to let the jump host’s OS automatically assign an available local port. This is the standard approach unless your network has strict port-binding rules.
Corrected Nested SSH Example Code
Here’s a full working script that connects to the Windows jump host first, then tunnels to your target Unix machine:
import paramiko # Step 1: Connect to the Windows jump host (ensure SSH server is enabled!) jump_client = paramiko.SSHClient() jump_client.set_missing_host_key_policy(paramiko.AutoAddPolicy()) try: # Adjust username format if using a domain account jump_client.connect( hostname='10.x.x.172', username='******SA', password='Jul@2021', port=22 ) print("Successfully connected to Windows jump host") except Exception as e: print(f"Failed to connect to jump host: {str(e)}") exit() # Get the transport object from the jump host connection jump_transport = jump_client.get_transport() # Step 2: Define target and local addresses dest_addr = ('10.103.53.26', 22) # Target Unix host's SSH endpoint local_addr = ('0.0.0.0', 0) # Let jump host auto-assign local port # Establish the direct TCP/IP tunnel through the jump host try: tunnel_channel = jump_transport.open_channel( "direct-tcpip", dest_addr=dest_addr, src_addr=local_addr ) print("Successfully established tunnel to target Unix host") except Exception as e: print(f"Failed to create tunnel: {str(e)}") jump_client.close() exit() # Step 3: Connect to the target Unix host using the tunnel target_client = paramiko.SSHClient() target_client.set_missing_host_key_policy(paramiko.AutoAddPolicy()) try: # Use the tunnel channel as the sock parameter target_client.connect( hostname='10.103.53.26', username='your_unix_username', password='your_unix_password', sock=tunnel_channel ) print("Successfully connected to target Unix host") # Example: Run a command on the Unix host stdin, stdout, stderr = target_client.exec_command('uname -a') print("\nUnix host info:") print(stdout.read().decode().strip()) except Exception as e: print(f"Failed to connect to target host: {str(e)}") finally: # Clean up connections target_client.close() jump_client.close()
内容的提问来源于stack exchange,提问作者krishnakumar
相关产品推荐
相关产品推荐

