如何通过多跳SSH从本地主机连接到目标服务器的TTY终端?
If you need to get a direct interactive TTY on target-server from your localhost without opening any ports on your local machine, SSH's built-in proxy capabilities are the perfect solution. Here are two reliable, straightforward methods:
Method 1: Use ProxyJump (Modern SSH, v7.3+)
This is the cleanest approach if your local SSH client is version 7.3 or newer. The -J (ProxyJump) flag tells SSH to chain connections: first to the middle server, then directly through it to the target server—no local port forwarding needed at all.
Run this command directly:
ssh -J your-middle-user@middle-server your-target-user@target-server
After authenticating (first to middle-server, then to target-server), you’ll get a full interactive TTY on the target server just like you were connecting directly.
Method 2: ProxyCommand (Compatible with Older SSH Versions)
If your SSH client doesn’t support ProxyJump, use ProxyCommand with the -W flag (which forwards your local stdin/stdout to the target host:port via the middle server). This achieves the same result without opening any local ports.
Use this command:
ssh -o ProxyCommand="ssh -W %h:%p your-middle-user@middle-server" your-target-user@target-server
The %h and %p are placeholders that SSH automatically replaces with target-server’s hostname and SSH port (default 22), so you don’t have to hardcode these values.
Make It Permanent (Optional)
To avoid typing the full command every time, add a configuration block to your ~/.ssh/config file:
For ProxyJump:
Host target-server User your-target-user ProxyJump your-middle-user@middle-server
For ProxyCommand:
Host target-server User your-target-user ProxyCommand ssh your-middle-user@middle-server -W %h:%p
Now you can just run ssh target-server to connect directly through the middle server.
Key Notes
- Ensure your localhost has SSH access to
middle-server, andmiddle-serverhas SSH access totarget-server(port 22 must be open between them). - Neither method requires opening any ports on localhost—all traffic is tunneled through the middle server’s existing SSH connection.
- Add the
-Aflag to your command (e.g.,ssh -A -J ...) if you want to use your local SSH keys to authenticate totarget-serverviamiddle-server(avoids needing to copy keys to the middle server).
内容的提问来源于stack exchange,提问作者fkrahe

