在运行Windows 10 IoT Core的树莓派3上创建反向SSH隧道求助
I’ve worked through this exact setup before, so I’ll walk you through the steps clearly—since Windows 10 IoT Core has some quirks compared to regular Linux or full Windows.
Prerequisites
- A Raspberry Pi 3 running Windows 10 IoT Core (make sure it’s updated to a recent build)
- A remote server/VPS with a public IP address (this will act as your tunnel gateway; it needs SSH enabled)
- Basic familiarity with SSH commands and PowerShell (for managing the Pi)
Step 1: Enable and Verify SSH on Windows 10 IoT Core
By default, SSH might not be enabled on your Pi. Here’s how to check and turn it on:
- Connect to your Pi via the Windows Device Portal (open a browser to
http://[your-pi-local-ip]:8080) - Navigate to Settings > SSH
- Toggle the SSH service to On, note the default port (usually 22)
- Alternatively, enable it via PowerShell:
Set-Service sshd -StartupType Automatic Start-Service sshd
Step 2: Test Basic SSH Connectivity to Your Gateway Server
First, confirm your Pi can reach the remote server. Open a PowerShell session on the Pi (either via Device Portal’s PowerShell tab or local terminal):
ssh [gateway-username]@[gateway-public-ip]
If you can log in successfully, exit the session to proceed.
Step 3: Create the Reverse SSH Tunnel
Run this command on your Pi to establish the reverse tunnel. This forwards traffic from your gateway server’s port 2222 to your Pi’s local SSH port (22):
ssh -fN -R 2222:localhost:22 [gateway-username]@[gateway-public-ip]
Let’s break down the flags:
-f: Runs SSH in the background after authentication-N: Tells SSH not to execute any remote commands (just keep the tunnel open)-R: Specifies the reverse tunnel mapping:[gateway-port]:localhost:[pi-ssh-port]
Critical Gateway Server Config
To let other devices connect through the gateway to your Pi, edit the SSH config on your gateway server:
- Log into your gateway server and open
sshd_configwith a text editor:sudo nano /etc/ssh/sshd_config - Find the
GatewayPortsline and set it to:GatewayPorts yes - Restart the SSH service:
sudo systemctl restart sshd
This allows the gateway to listen on public interfaces for the tunnel port, not just localhost.
Step 4: Test the Tunnel
From any device with SSH access to your gateway server, connect to your Pi using:
ssh -p 2222 [pi-username]@[gateway-public-ip]
You should be dropped into your Pi’s PowerShell session—success!
Step 5: Make the Tunnel Persistent (Survive Reboots)
The above command will die if your Pi reboots. To fix this, create a scheduled task on Windows 10 IoT Core:
- On your Pi’s PowerShell, run:
$action = New-ScheduledTaskAction -Execute "ssh.exe" -Argument "-fN -R 2222:localhost:22 [gateway-username]@[gateway-public-ip]" $trigger = New-ScheduledTaskTrigger -AtStartup $principal = New-ScheduledTaskPrincipal -UserId "SYSTEM" -LogonType ServiceAccount Register-ScheduledTask -TaskName "ReverseSSHTunnel" -Action $action -Trigger $trigger -Principal $principal - To avoid entering a password every time, set up SSH key authentication between your Pi and gateway server:
- On your Pi, generate an SSH key pair:
ssh-keygen -t ed25519 - Copy the public key to your gateway server:
ssh-copy-id [gateway-username]@[gateway-public-ip]
- On your Pi, generate an SSH key pair:
Now the tunnel will automatically start when your Pi boots up, no password required.
Troubleshooting Tips
- If the tunnel won’t stay up, check your gateway server’s firewall to ensure port 2222 is open (for incoming traffic)
- Make sure your Pi has a stable internet connection—unreliable Wi-Fi can drop the tunnel
- If you can’t connect to the Pi via the gateway, double-check the
GatewayPortssetting on the gateway server
内容的提问来源于stack exchange,提问作者Lucas Niewohner

