Skip to main content

Linux tuntap using openssh

Project description


Linux TUN/TAP using the openssh and Python3

This package comes with two command line interfaces:

  • ssh-tuntap-server
  • ssh-tuntap-client

this tutorial show's how to use this project:


Currently only point-to-point (tun) layer-3 tunneling is supported.


You have to install this package on both client and server.

sudo -H pip3 install sshtuntap


sudo -H pip3 install git+

Bash auto completion

ssh-tuntap-server completion install   # On server
ssh-tuntap-client completion install   # On client

Open new bash instance to perform changes.


ssh-tuntap-server --help
ssh-tuntap-client --help

Server setup

The server cli stands for setup network, add, delete and list users. this is just a utility to perform user and tuntap interface management and ip address assignment.

OpenSSH Server

Enable ssh tunneling on the server by editing the /etc/ssh/sshd_config and ensure the line:

PermitTunnel yes


PermitTunnel point-to-point

see man 5 sshd_config for more info.

Restart the ssh server to perform the changes.

service ssh restart

Create Network and systemd service

sudo ssh-tuntap-server install


sudo ssh-tuntap-server install

you may use uninstall sub-command to remove systemd service.

sudo ssh-tuntap-server uninstall

Add foo host

You have to create the server user mannualy (depends on your distro).

Here I'm using ubuntu server 18.04. and assume the server's hostname is

Run these commands on the server:

sudo adduser foo

Then use this command to create /home/foo/.ssh/tuntap.yml:

sudo ssh-tuntap-server add foo


Client command line stands for fetch host configuration from the server and perform connection using the ssh -w.

ssh-tuntap-client setup

Use this to connect:

sudo ssh-tuntap-client connect


Edit /etc/sysctl.conf on the server to enable ip forwarding.

net.ipv4.ip_forward = 1

Run sysctl -p to refresh with the new configuration

sudo sysctl -p

Configure NAT

sudo iptables -tnat -APOSTROUTING -s192.168.22.0/24 -jMASQUERADE

iptables persistency

sudo apt install iptables-persistent netfilter-persistent

Project details

Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

sshtuntap-2.0.7.tar.gz (8.9 kB view hashes)

Uploaded source

Built Distribution

sshtuntap-2.0.7-py3-none-any.whl (9.6 kB view hashes)

Uploaded py3

Supported by

AWS AWS Cloud computing Datadog Datadog Monitoring Facebook / Instagram Facebook / Instagram PSF Sponsor Fastly Fastly CDN Google Google Object Storage and Download Analytics Huawei Huawei PSF Sponsor Microsoft Microsoft PSF Sponsor NVIDIA NVIDIA PSF Sponsor Pingdom Pingdom Monitoring Salesforce Salesforce PSF Sponsor Sentry Sentry Error logging StatusPage StatusPage Status page