Introduction: Explaining why I talk about this in the first place
While we encounter day to day with full-blown proxy like Envoy, Nginx, or Caddy, I would like to share very useful Linux low level tools that can be used either for your home lab, debugging, etc.
Remember: always man the tool and read there, staying in terminal saves time and keeps u focused.
SSH port forwarding is a tunnel, socat is a relay. SSH wraps the traffic in encryption and needs a login on the far end. socat just passes bytes along as they are and needs nothing on the other side.
apt install socat
socat stands for SOcket CAT. Like cat copies data from a file to your screen, socat copies data between two addresses, in both directions. An address can be a TCP port, a UDP port, a UNIX socket, a file, a serial device, and more.
The scenario
A service runs on the server and listens at port 5000: 127.0.0.1:5000. It works, but only locally. We want other machines on the network to reach it on port 6000.
"A service is already running on port 5000, and this makes it also available on port 6000 from any IP."
Socat tcp-listen:6000,bind=0.0.0.0,reuseaddr,fork tcp:127.0.0.1:5000
tcp-listen:6000 wait for incoming TCP connections on port 6000.
bind=0.0.0.0 makes socat listen on all of the server's network interfaces.
fork creates a new child process for each client. Without it, socat handles one connection and exits.
tcp:127.0.0.1:5000 is the destination. For each client, socat connects to the local service and relays data back and forth.
Security Perspective:
use range= to choose who may connect, and remember that it neither encrypts nor authenticates anything. On a trusted home network that's often fine. For anything beyond that, put SSH or TLS in front of it.
Wrap Up:
socat is a relay, not a secure tunnel. Keep these points in mind.
No encryption. With tcp: addresses, traffic crosses the network in plain text. socat supports TLS through its OPENSSL addresses, but that requires setting up certificates yourself.
No authentication. Anyone who can reach port 6000 gets straight through to the service.


Top comments (1)
Some comments may only be visible to logged-in visitors. Sign in to view all comments.