You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

请求实现基于现有Apache服务器(80/443端口)的本地SSH网页会话方案

请求实现基于现有Apache服务器(80/443端口)的本地SSH网页会话方案

Hey there, let's work through this problem step by step. Your work firewall's smart enough to detect and block SSH traffic even on a non-standard port, so serving an SSH terminal through your existing Apache (using port 80/443, which the firewall won't flag as SSH) is exactly the right approach. Here are two reliable methods to set this up without needing any new open ports:

Method 1: Use WebSSH with Apache Reverse Proxy

This is the most straightforward and polished option. WebSSH is a lightweight web-based SSH client that you can run locally, then proxy through Apache so it's accessible via your existing web server's port.

  1. Install WebSSH on your server
    First, install the package (assuming you're on a Debian/Ubuntu system):

    sudo apt update && sudo apt install webssh
    

    For RHEL/CentOS, you can use pip:

    pip install webssh
    
  2. Configure WebSSH to listen only locally
    You don't want WebSSH accessible directly from the internet—we'll let Apache handle that. Start it with:

    wssh --address=127.0.0.1 --port=8080
    

    This makes it listen only on localhost port 8080. To make it run on startup, you can create a systemd service file for it.

  3. Set up Apache reverse proxy for WebSSH
    Edit your Apache site configuration (usually in /etc/apache2/sites-available/your-site.conf) and add this block inside the <VirtualHost> section:

    ProxyPass /ssh http://127.0.0.1:8080/
    ProxyPassReverse /ssh http://127.0.0.1:8080/
    

    This tells Apache to forward any requests to https://your-domain.com/ssh to the local WebSSH instance.

  4. Enable required Apache modules and restart
    Enable the proxy modules if you haven't already:

    sudo a2enmod proxy proxy_http
    sudo systemctl restart apache2
    

    Now you can visit https://your-domain.com/ssh in your work browser, enter your localhost SSH credentials, and you'll have a working terminal—all over port 443, which the firewall won't block as SSH traffic.

Method 2: Use ShellInABox with Apache Alias (No Reverse Proxy Needed)

If you prefer a tool that can integrate directly with Apache via CGI or an alias, ShellInABox is a great choice. It can generate static HTML/CSS/JS files that you can host directly through Apache.

  1. Install ShellInABox
    On Debian/Ubuntu:

    sudo apt install shellinabox
    
  2. Configure ShellInABox to generate static content
    Run this command to generate the web files for a localhost SSH session:

    shellinaboxd --static-file=/var/www/html/ssh --service=/:SSH:127.0.0.1:22
    

    This creates a directory /var/www/html/ssh with all the necessary files to host the SSH terminal.

  3. Set permissions and test
    Make sure Apache can read the files:

    sudo chown -R www-data:www-data /var/www/html/ssh
    

    Now visit https://your-domain.com/ssh—you'll see the SSH login prompt right there, served directly from Apache without any extra ports.

Key Notes for Both Methods

  • Always use HTTPS: Never serve this over plain HTTP, since your SSH credentials would be sent in clear text. Ensure your Apache has a valid SSL certificate (Let's Encrypt works great for this).
  • Restrict access if needed: You can add Apache authentication (like Basic Auth) to the /ssh path to make sure only you can access the terminal. Add this to your Apache config:
    <Location /ssh>
        AuthType Basic
        AuthName "Restricted SSH Access"
        AuthUserFile /etc/apache2/.htpasswd
        Require valid-user
    </Location>
    
    Then create the .htpasswd file with sudo htpasswd -c /etc/apache2/.htpasswd your-username.

Either of these methods will let you access your server's SSH terminal through your existing Apache port, bypassing the work firewall's SSH traffic detection.

备注:内容来源于stack exchange,提问作者JWright

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.04.21 13:44:38