Files
obsidian-vault/personal/docs/truenas-remote-access-reverse-proxy.md
T
2026-05-29 21:02:08 +00:00

5.1 KiB
Executable File

⚠️ Важно: разные сети TrueNAS и Kraken находится в разных сетях. Доступ через доменное имя. Прямой доступ по IP с них невозможен. Всегда используйте truenas_admin@mallexxx.duckdns.org для SSH из 192.168.1.x. Для Eagle/Kraken/Taiga — только mallexxx.duckdns.org.

TrueNAS Remote Access Cheat Sheet

Network Layout

Internet (90.189.160.148 / mallexxx.duckdns.org)
    └── GPON Router (192.168.0.1) — Novisibirsk, Rostelecom, Realtek-based
    │       ├── OpenWrt (192.168.0.11) — WAN, acts as main router
    │       │       └── TrueNAS (192.168.2.197)
    │       └── ZONT heating controller (192.168.0.10)
	└── Asus Router - Bishkek (192.168.1.1)
	│       ├── Kraken
	│       ├── HTPC

VPS

  • IP: 91.207.28.205
  • Tunnel user: tun (shell /bin/false, key auth only)

Method 1 — Reverse SSH Tunnel via VPS (primary)

How it works

TrueNAS dials out to VPS, VPS exposes port 2222 → TrueNAS SSH.

TrueNAS script

/mnt/RED_2TB/system/tunnel.sh — runs on boot via Init/Shutdown Scripts.

Connect to TrueNAS

ssh -p 2222 truenas_admin@91.207.28.205

Enable/disable access on VPS

passwd -u tun   # enable
passwd -l tun   # disable

Start tunnel manually (if not running)

# On TrueNAS shell (as root)
sudo bash /mnt/RED_2TB/system/tunnel.sh &

Check tunnel is active on VPS

ss -tlnp | grep 2222

Check tunnel connection from TrueNAS

ss -tnp | grep 91.207.28.205

Kill all VPS SSH sessions after delay

(sleep 600 && pkill -f "ssh.*91.207.28.205") &

Method 2 — Access GPON Router UI remotely

How it works

OpenWrt → reverse tunnel to VPS → forward to GPON UI (192.168.0.1:80)

Step 1 — On OpenWrt, open reverse tunnel to VPS

ssh -i ~/.ssh/id_ed25519 -N -R 8081:192.168.0.1:80 root@91.207.28.205

Step 2 — On your machine, forward locally

ssh -L 9091:localhost:8081 root@91.207.28.205

Step 3 — Open in browser

http://localhost:9091

Method 3 — Access TrueNAS Web UI remotely

TrueNAS blocks TCP forwarding (administratively prohibited), so direct port forward through TrueNAS SSH doesn't work.

Workaround via OpenWrt

# On OpenWrt
ssh -i ~/.ssh/id_ed25519 -N -R 8082:192.168.2.197:80 root@91.207.28.205

# On your machine
ssh -L 9092:localhost:8082 root@91.207.28.205

Then open http://localhost:9092


OpenWrt SSH access

# Direct (local network)
ssh root@192.168.2.2

# Via TrueNAS tunnel
ssh -p 2222 truenas_admin@91.207.28.205
# then: ssh root@192.168.2.2

OpenWrt uses dropbear SSH client — no -v flag, use -i for key:

ssh -i ~/.ssh/id_ed25519 user@host

TrueNAS Notes

Init/Shutdown Scripts

# List all scripts
midclt call initshutdownscript.query

# Add new script
midclt call initshutdownscript.create '{"command":"bash /path/to/script.sh &","type":"COMMAND","when":"POSTINIT","enabled":true,"timeout":10}'

SSH authorized keys

# View
midclt call user.query | python3 -c "import sys,json; users=json.load(sys.stdin); [print(u['sshpubkey']) for u in users if u['username']=='truenas_admin']"

# Update (replace all keys)
midclt call user.update 70 '{"sshpubkey":"key1\nkey2\nkey3"}'

# truenas_admin user ID: 70
# authorized_keys file: /home/truenas_admin/.ssh/authorized_keys

TrueNAS shells

  • Shell 6 — TrueNAS CLI (own interface, limited commands)
  • Shell 7 — Linux bash (full commands, use this for SSH/scripts)

DuckDNS / External Access (mallexxx.duckdns.org)

Verify DNS matches public IP

curl ifconfig.me
nslookup mallexxx.duckdns.org

Test port reachability from outside

nc -zv 90.189.160.148 80
nc -zv 90.189.160.148 443
nc -zv 90.189.160.148 22

Port forwarding on OpenWrt

uci show firewall | grep redirect

Key services:

Service External port Internal
TrueNAS SSH 22 192.168.2.197:22
Caddy HTTP 80 192.168.2.197:8088
Caddy HTTPS 443 192.168.2.197:8443
MQTT 1883 192.168.2.197:1883
Transmission 51413 192.168.2.197:51413

VPS sshd_config (relevant settings)

GatewayPorts yes
AllowTcpForwarding yes
PermitRootLogin yes

Reload after changes: systemctl reload sshd


Troubleshooting

Tunnel not connecting after reboot

  1. Check script exists: cat /mnt/RED_2TB/system/tunnel.sh
  2. Check Init/Shutdown script: midclt call initshutdownscript.query
  3. Start manually: sudo bash /mnt/RED_2TB/system/tunnel.sh &
  4. Check tun user is unlocked on VPS: passwd -u tun

Port 2222 already in use on VPS

Another tunnel instance is running. Kill old one:

# On VPS
fuser -k 2222/tcp

SSH auth failing from OpenWrt to TrueNAS

Dropbear requires explicit key flag:

ssh -i ~/.ssh/id_ed25519 truenas_admin@192.168.2.197

GPON DMZ target

GPON DMZ should point to OpenWrt WAN IP: 192.168.0.10 (fixed via MAC reservation)