Changes for page Remote Access Gateway
Last modified by Kilight Cao on 2022/07/25 10:47
Summary
-
Page properties (1 modified, 0 added, 0 removed)
Details
- Page properties
-
- Content
-
... ... @@ -70,10 +70,14 @@ 70 70 1. Give a free port to the user and ask them to configure RSSH page in the gateway. 71 71 1. In your server or other machine, you will able to access to the end user device by below command: 72 72 73 -{{{ $ ssh -p <End User Host Port> root@<Host Address> 74 -}}} 73 +(% class="box" %) 74 +((( 75 + $ ssh -p <End User Host Port> root@<Host Address> 76 +))) 75 75 78 +((( 76 76 (% class="mark" %)**Remote RSSH Access allow the gateway to connect to SSH server as well. This will create risk to the RSSH server. Please make sure the account use for Gateway Access has the lowest access right.** 80 +))) 77 77 78 78 79 79 ==== 2.1.2.1 Note for set up RSSH server ==== ... ... @@ -94,13 +94,15 @@ 94 94 95 95 Below gateway support reverse SSH access: 96 96 97 -{{{ Firmware Version >lgw--build-v5.4.1618196981-20210412-1111 Firmware Download 101 +(% class="box" %) 102 +((( 103 + Firmware Version >lgw~-~-build-v5.4.1618196981-20210412-1111 Firmware Download 98 98 LG01N, OLG01N (Note: LG01-P LG01-S doesn't support) 99 99 LG02, OLG02 100 100 LG308, DLOS8 101 101 LPS8 102 102 LIG16 103 - }}}109 +))) 104 104 105 105 === 2.2.1 End User Guide to use SSH access === 106 106 ... ... @@ -114,6 +114,7 @@ 114 114 115 115 git clone rssh-server 116 116 123 + 117 117 2).cd rssh-server; sudo make ~-~--> to Generate the execute file:rssh_serv 118 118 119 119 [[image:https://wiki.dragino.com/images/thumb/e/e3/Generate_the_execute_file.png/500px-Generate_the_execute_file.png||height="103" width="500"]] ... ... @@ -122,21 +122,27 @@ 122 122 123 123 **Debug** : 124 124 125 -{{{ if you git fail. --> sudo: git: command not found. 126 - please install git. --> yum install git -y or apt-get install git -y. 127 -}}} 132 +(% class="box" %) 133 +((( 134 + if you git fail. ~-~-> (% class="mark" %)**sudo: git: command not found.**(%%) 135 +please install git. ~-~-> (% class="mark" %)**yum install git -y or apt-get install git -y. ** 136 +))) 128 128 129 -{{{ if you make error 127,it lack of gcc. 130 - please install gcc. -->yum install gcc. 131 -}}} 138 +(% class="box" %) 139 +((( 140 + if you make error 127,it** (% class="mark" %)lack of gcc.(%%)** 141 +please install gcc. ~-~->(% class="mark" %)**yum install gcc.** 142 +))) 132 132 133 133 [[image:https://wiki.dragino.com/images/d/d7/Lack_of_gcc.png||height="174" width="434"]] 134 134 135 135 lack of gcc 136 136 137 -{{{ if you make a fatal error : sqlite3.h,it lack of sqlite3. 138 - please insatell sqlite3. 139 -}}} 148 +(% class="box" %) 149 +((( 150 + if you make a fatal error : sqlite3.h,it (% class="mark" %)**lack of sqlite3.**(%%) 151 +please insatell **sqlite3**. 152 +))) 140 140 141 141 [[image:https://wiki.dragino.com/images/thumb/9/93/Lack_of_sqlite3.png/500px-Lack_of_sqlite3.png||height="137" width="500"]] 142 142 ... ... @@ -144,25 +144,28 @@ 144 144 145 145 How to install Sqlit3 146 146 147 -{{{ Step1:Download the SQLit3 installation package 148 - sudo wget 149 - Step2:tar the SQLit3 installation package 160 +(% class="box" %) 161 +((( 162 +Step1:Download the SQLit3 installation package 163 + sudo wget [[https:~~/~~/www.sqlite.org/2021/sqlite-autoconf-3350400.tar.gz>>url:https://www.sqlite.org/2021/sqlite-autoconf-3350400.tar.gz]] 164 +Step2:tar the SQLit3 installation package 150 150 sudo tar -zxvf sqlite-autoconf-3350300.tar.gz 151 - 166 +Step3:Generate the makefile 152 152 cd sqlite-autoconf-3350300/;./configure 153 - 168 +Step4:Compile makefile 154 154 sudo make 155 - 170 +Step5:Install makefile 156 156 sudo make install 157 - 158 - cd /usr/local/bin;ls -al 159 - cd sqlite-autoconf-3350300/;./sqlite3 test.db 160 - 172 +Check: 173 + cd /usr/local/bin;ls -al ~-~-> Check to see if there is a file for sqlite3 174 + cd sqlite-autoconf-3350300/;./sqlite3 test.db ~-~-> Test whether the sqlite3 was installed successfully 175 +debug: 161 161 If you get the imformation that is SQLite header and source version mismatch, when you execute./sqlite3 test.db. 162 162 Please execute the command /sbin/ldconfig. 163 163 After that execute the command ./sqlite3 test.db again. 164 - }}}179 +))) 165 165 181 + 166 166 ===== 2.2.1.1.2 Step 2 :Install and run the RSS service ===== 167 167 168 168 1):intall database for /var/rsshdb.sqlite3 and Server development port for 3721(The default is 3721) ... ... @@ -169,10 +169,12 @@ 169 169 170 170 user must enter the root account and run the following commands 171 171 172 -{{{ $ ./create_sqlite3_db.sh 173 - $ ./rssh_serv -p 3721 2>&1 & 174 - $ ps -ef | grep rssh_serv check 3721 port 175 -}}} 188 +(% class="box" %) 189 +((( 190 +$ ./create_sqlite3_db.sh 191 +$ ./rssh_serv -p 3721 2>&1 & 192 +$ ps -ef | grep rssh_serv check 3721 port 193 +))) 176 176 177 177 [[image:https://wiki.dragino.com/images/thumb/c/cb/Intall_database_and_server_development_port.png/500px-Intall_database_and_server_development_port.png||height="70" width="500"]] 178 178 ... ... @@ -180,40 +180,47 @@ 180 180 181 181 **Debug:** 182 182 183 -{{{ Check /var/rsshdb.sqlite3 --> ls /var/rsshdb.sqlite3 184 - Check ls /var/rsshdb.sqlite3 --> sudo chmod 777 rssh_serv 185 -}}} 201 +(% class="box" %) 202 +((( 203 +Check /var/rsshdb.sqlite3 ~-~->(% class="mark" %)** ls /var/rsshdb.sqlite3**(%%) 204 +Check ls /var/rsshdb.sqlite3 ~-~-> (% class="mark" %)**sudo chmod 777 rssh_serv** 205 +))) 186 186 187 -{{{ if fail to open dpvlry or to bind to it 188 - please kill rssh_serv,and run ./rssh_serv -p 3721 2>&1 & again 189 -}}} 207 +(% class="box" %) 208 +((( 209 +if** fail to open dpvlry or to bind to it** 210 +please kill rssh_serv,and run (% class="mark" %)** ./rssh_serv -p 3721 2>&1 &** (%%) again 211 +))) 190 190 213 + 191 191 ===== 2.2.1.1.3 Step 3 :Create a minimal SSH user (reverse SSH proxy for the gateway) ===== 192 192 193 -1):sudo useradd XXXXX (custom user name) 216 +1):(% class="mark" %)**sudo useradd XXXXX**(%%) (custom user name) 194 194 195 -2):sudo passwd xxxxxx 218 +2):(% class="mark" %)**sudo passwd xxxxxx** 196 196 197 -3):cp /bin/bash /bin/rbash 220 +3):(% class="mark" %)**cp /bin/bash /bin/rbash** 198 198 199 -4):sudo nano /etc/passwd ~-~-> Change /bin/bash to /bin/rbash 222 +4):(% class="mark" %)**sudo nano /etc/passwd**(%%) ~-~-> Change /bin/bash to /bin/rbash 200 200 201 -5):sudo nano /home/xxxxx/.bashrc **empty it,and input export PATH=$HOME/bin** 224 +5):(% class="mark" %)**sudo nano /home/xxxxx/.bashrc**(%%) **empty it,and input export PATH=$HOME/bin** 202 202 203 -6):sudo nano /home/xxxxx/.bash_profile **empty it,and input export PATH=$HOME/bin** 226 +6):(% class="mark" %)**sudo nano /home/xxxxx/.bash_profile**(%%) **empty it,and input export PATH=$HOME/bin** 204 204 205 205 **Now user "XXXXX" is the user with limited permissions of the current system** 206 206 230 + 207 207 === 2.2.2 How does user get the gateway to connect to a user's private server === 208 208 209 209 ===== 2.2.2.1 Step1: Come bace the gateway web UI for get the gateway Public key ===== 210 210 211 -1)in the system ~-~-> Remote Mgmt/span> 235 +1)in the system ~-~-> (% class="mark" %)**Remote Mgmt/span>** 212 212 213 213 [[image:https://wiki.dragino.com/images/thumb/8/8f/Remote_Mgmt.png/500px-Remote_Mgmt.png||height="367" width="500"]] 214 214 215 215 Remote Mgmt 216 216 241 + 217 217 ===== 2.2.2.2 Step2: Authorization server ===== 218 218 219 219 copy the Gateway Publickey into user's private server "/home/XXXXX/.ssh/authorized_keys" file. ... ... @@ -222,6 +222,7 @@ 222 222 223 223 Publickey 224 224 250 + 225 225 ===== 2.2.2.3 Step3: connecte private server ===== 226 226 227 227 in the gateway web UI ... ... @@ -230,14 +230,17 @@ 230 230 231 231 gateway web UI 232 232 233 -{{{Connection Type : If user's least privileged user with private server uses a password, select Public Key 234 -Note:if user's least privileged user no uses a password,choose from both is fine 235 -Login ID : Input user name "eg : "XXXXX" 236 -Host Address : Input user's private server address 237 -Connect at Startupt: : Choose to enable connect once device is powered. 259 +(% class="box" %) 260 +((( 261 +(% class="mark" %)**Connection Type **(%%) : If user's least privileged user with private server uses a password, select (% class="mark" %)**Public Key**(%%) 262 +**Note:if user's least privileged user no uses a password,choose from both is fine** 263 +(% class="mark" %)**Login ID**(%%) : Input user name "eg : "XXXXX" 264 +(% class="mark" %)**Host Address**(%%) : Input user's private server address 265 +(% class="mark" %)**Connect at Startupt**(%%): Choose to enable connect once device is powered. 238 238 Click Save and then Connect 239 - }}}267 +))) 240 240 269 + 241 241 ===== 2.2.2.4 Step 4 :Cheak is fine ===== 242 242 243 243 Rssh Host connection Ok ... ... @@ -246,9 +246,10 @@ 246 246 247 247 Rssh Host connection Ok 248 248 278 + 249 249 user can use common ps | grep ssh to check it in the gateway. 250 250 251 -[[image:https://wiki.dragino.com/images/thumb/a/ad/Check_the_gateway.png/500px-Check_the_gateway.png ||height="47" width="500"]]281 +[[image:https://wiki.dragino.com/images/thumb/a/ad/Check_the_gateway.png/500px-Check_the_gateway.png]] 252 252 253 253 Check the gateway 254 254 ... ... @@ -259,8 +259,10 @@ 259 259 260 260 **Debug:** 261 261 262 -{{{ check: sudo ls /home/xxxxx/.ssh/authorizedkey 263 -}}} 292 +(% class="box" %) 293 +((( 294 + check: sudo ls /home/xxxxx/.ssh/authorizedkey 295 +))) 264 264 265 265 === 2.2.3 How to Ser up a Reverse SSH access === 266 266 ... ... @@ -270,11 +270,11 @@ 270 270 271 271 Loging server 272 272 305 + 273 273 ==== 2.2.3.2 Step2:access the gateway ==== 274 274 275 275 $ cd rssh-server/ 276 276 277 - 278 278 Check the gateway linking to the server $ ./connect-gw.sh -l 279 279 280 280 [[image:https://wiki.dragino.com/images/thumb/e/ee/Check_gateway_link_server.png/500px-Check_gateway_link_server.png||height="157" width="500"]]