# Setting up thinlinc over a reverse tunnel

**URL:** <https://community.thinlinc.com/t/setting-up-thinlinc-over-a-reverse-tunnel/399>\
**Category:** Community Support\
**Tags:** jumphost, tlclient, tlserver\
**Created:** [4 July 2022 15:22 UTC](https://community.thinlinc.com/t/setting-up-thinlinc-over-a-reverse-tunnel/399 "2022-07-04T15:22:46Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![jayd](https://avatars.discourse-cdn.com/v4/letter/j/e36b37/32.png) [@jayd](https://community.thinlinc.com/u/jayd)\
**Post date:** [4 July 2022 15:22 UTC](https://community.thinlinc.com/t/setting-up-thinlinc-over-a-reverse-tunnel/399/1 "2022-07-04T15:22:46Z")

</div>

Hi all,

I am trying to run thinlinc over a reverse tunnel but I am stuck on how to properly set up the connection on windows.

The tunnel on the host is set up as:  
ssh -R 192.168.2.153:10022:localhost:22 USERNAME@RELAY\_SERVER\_PUBLIC\_IP

RELAY\_SERVER\_PUBLIC\_IP:22 is routed to 192.168.2.153:22  
RELAY\_SERVER\_PUBLIC\_IP:21 is routed to 192.168.2.153:10022  
(I had to use a commonly used port due to client side restrictions.)

Authentication is set up using RSA keys on the host (not the relay server).

Up until here, I am able to log in to the host using ssh on the client side.

> ssh USER\_NAME@RELAY\_SERVER\_PUBLIC\_IP -p 21

However, I was unbale to use thinlinc. After some searching, I read that I have to use HOST\_ALIASES for tunnels. To do this on the client side (windows), I created a conf file and start thinlinc in cmd as

> tlclient.exe -C tlclient.conf

I tried several options in the conf file, such as  
HOST\_ALIASES=192.168.2.153:10022:localhost:22

But it does not seem to work. The client does seem to read the conf file correctly, because I get different responses based on how I define HOST\_ALIASES.

Is there anyone who knows how I should get thinlinc up and running?

Kind regards,

-J

client version: 4.12.1

---

<div class="post-metadata">

**Author:** ![aaron](https://dub1.discourse-cdn.com/flex005/user_avatar/community.thinlinc.com/aaron/32/13_2.png) [@aaron](https://community.thinlinc.com/u/aaron)\
**Post date:** [5 July 2022 06:48 UTC](https://community.thinlinc.com/t/setting-up-thinlinc-over-a-reverse-tunnel/399/2 "2022-07-05T06:48:30Z")

</div>

Hello,

I’m not sure if this will completely solve your problem, but the syntax you’re using for the `HOST_ALIASES` variable is incorrect. See “[Configuration Parameters Used by the ThinLinc Client — The ThinLinc Administrator's Guide 4.14.0 build 2408 documentation](https://www.cendio.com/resources/docs/tag/client_config_params.html?highlight=host_aliases#client-config-HOST_ALIASES)”.

What you probably want is something like:

`HOST_ALIASES=192.168.2.153=RELAY_SERVER_PUBLIC_IP:22`

---

<div class="post-metadata">

**Author:** ![jayd](https://avatars.discourse-cdn.com/v4/letter/j/e36b37/32.png) [@jayd](https://community.thinlinc.com/u/jayd)\
**Post date:** [6 July 2022 07:57 UTC](https://community.thinlinc.com/t/setting-up-thinlinc-over-a-reverse-tunnel/399/3 "2022-07-06T07:57:14Z")

</div>

Ah, that makes sense! Thank you!
