Using SSH_config Match to connect to a host using multiple IP or Hostnames
fmartingr.com
fmartingr.com
$ cat ~/.ssh/config
# Define external nodes here
…SNIP…
# If connecting to a *.xn0.org host and router.xn0.org = 10.0.0.1, must be home/vpn.
Match host *.xn0.org exec "getent ahosts router.xn0.org | grep -q ^10.0.0.1"
ProxyJump none
# If connecting to a *.xn0.org host and the macaddr of 10.0.0.1 is NOT f0:9f:XX:XX:XX:XX, then use jump.xn0.org:
Match host *.xn0.org exec "! arp -ne 10.0.0.1 | grep -Fq f0:9f:XX:XX:XX:XX"
ProxyJump jump.xn0.org
# Define internal nodes here
…SNIP…(As someone that's a long-term SSH user most of the good stuff was in the thread)
I also believe the day before yesterday someone showed an incredible rsync/dotfile/ssh trick in the comments but I have no idea what article it was on.
I'm not sure if Big SSH is astroturfing HN lately or not but I'm here for it.
I bookmarked that for reference last night.
Each setting file has a full comment page on how to use its keyword, a commented-out default setting, and a CISecurity-recommended setting.
Each setting files are named (via numeric prefix) to be in execution order, which enables for easier thinking of “how deep” it goes into the SSH protocol.
As a default, the config files are written into a local build/etc/ssh subdirectories for perusal before being implemented manually into /etc
Plus, I code-review OpenSSH regularly.
A few months ago I switched to WezTerm, which has a built-in first class terminal multiplexer and remote protocol, including typeahead. The benefits are that I'm using the same terminal I (now) use on my Linux box, so I have the same keyboard shortcuts on Mac and Linux, and various things like cut/paste aren't weirded out by tmux.
The one downside I've had so far is that often when I've suspended too long my wezterm client disconnects and I have to reconnect to the session (just up-arrow+enter in my terminal), where mosh+tmux would just stay always there.
Match is extremely useful though. It's in use on a few systems I control to allow password authentication from certain subnets.
https://docs.google.com/document/d/1u9mGu7bv5JYL_Fvv0L7OX4_1...
Worth noting that I actually just use split-horizon DNS for my personal VPN though. Telling Unbound this is a lot easier (and still works with stuff that isn't SSH):
local-zone: "mydomain.com." transparent
local-data: "foo.mydomain.com. A 10.0.0.4"However, I also have a similar setup but for my SDN I use Twingate which lets me re-route DNS when its connected so all I need to do is the equivalent of defining
*.lan
as a resource in the UI and then I can reach it no matter when I'm connected via SDN or not.`Match exec "test ${REGION}.${ENVIRONMENT} = us-east-1.staging"
ProxyJump yourRegionEnvSpecificBastion`Edit: autocorrect
Based on my own personal experience I'd also say that no (modern) clients do so although that could be wrong.