请求实现基于现有Apache服务器(80/443端口)的本地SSH网页会话方案
Hey there, let's work through this problem step by step. Your work firewall's smart enough to detect and block SSH traffic even on a non-standard port, so serving an SSH terminal through your existing Apache (using port 80/443, which the firewall won't flag as SSH) is exactly the right approach. Here are two reliable methods to set this up without needing any new open ports:
Method 1: Use WebSSH with Apache Reverse Proxy
This is the most straightforward and polished option. WebSSH is a lightweight web-based SSH client that you can run locally, then proxy through Apache so it's accessible via your existing web server's port.
Install WebSSH on your server
First, install the package (assuming you're on a Debian/Ubuntu system):sudo apt update && sudo apt install websshFor RHEL/CentOS, you can use pip:
pip install websshConfigure WebSSH to listen only locally
You don't want WebSSH accessible directly from the internet—we'll let Apache handle that. Start it with:wssh --address=127.0.0.1 --port=8080This makes it listen only on localhost port 8080. To make it run on startup, you can create a systemd service file for it.
Set up Apache reverse proxy for WebSSH
Edit your Apache site configuration (usually in/etc/apache2/sites-available/your-site.conf) and add this block inside the<VirtualHost>section:ProxyPass /ssh http://127.0.0.1:8080/ ProxyPassReverse /ssh http://127.0.0.1:8080/This tells Apache to forward any requests to
https://your-domain.com/sshto the local WebSSH instance.Enable required Apache modules and restart
Enable the proxy modules if you haven't already:sudo a2enmod proxy proxy_http sudo systemctl restart apache2Now you can visit
https://your-domain.com/sshin your work browser, enter your localhost SSH credentials, and you'll have a working terminal—all over port 443, which the firewall won't block as SSH traffic.
Method 2: Use ShellInABox with Apache Alias (No Reverse Proxy Needed)
If you prefer a tool that can integrate directly with Apache via CGI or an alias, ShellInABox is a great choice. It can generate static HTML/CSS/JS files that you can host directly through Apache.
Install ShellInABox
On Debian/Ubuntu:sudo apt install shellinaboxConfigure ShellInABox to generate static content
Run this command to generate the web files for a localhost SSH session:shellinaboxd --static-file=/var/www/html/ssh --service=/:SSH:127.0.0.1:22This creates a directory
/var/www/html/sshwith all the necessary files to host the SSH terminal.Set permissions and test
Make sure Apache can read the files:sudo chown -R www-data:www-data /var/www/html/sshNow visit
https://your-domain.com/ssh—you'll see the SSH login prompt right there, served directly from Apache without any extra ports.
Key Notes for Both Methods
- Always use HTTPS: Never serve this over plain HTTP, since your SSH credentials would be sent in clear text. Ensure your Apache has a valid SSL certificate (Let's Encrypt works great for this).
- Restrict access if needed: You can add Apache authentication (like Basic Auth) to the
/sshpath to make sure only you can access the terminal. Add this to your Apache config:
Then create the<Location /ssh> AuthType Basic AuthName "Restricted SSH Access" AuthUserFile /etc/apache2/.htpasswd Require valid-user </Location>.htpasswdfile withsudo htpasswd -c /etc/apache2/.htpasswd your-username.
Either of these methods will let you access your server's SSH terminal through your existing Apache port, bypassing the work firewall's SSH traffic detection.
备注:内容来源于stack exchange,提问作者JWright

