Stop Double SSH-ing to Internal Hosts
SSH & Remote Administration
Stop Double SSH-ing to Internal Hosts
🧩 The Challenge
Ever needed to get to that one internal server, but it’s only accessible through a jump host or bastion? You SSH into the jumpbox, wait for the prompt, then SSH *again* from there to the actual target machine. It’s slow, a real pain for automation scripts, and frankly, it just grinds my gears.
💡 The Fix
Your `~/.ssh/config` file has a super neat trick for this. You can tell your SSH client to handle that multi-hop dance for you automatically. Configure it once, then `ssh target_host` just works, no manual intermediate connection required.
Host jumpbox
Hostname 192.168.1.100
User sysadmin
Host internal-server
Hostname 10.0.0.5
User devops
ProxyJump jumpbox
⚙️ Why It Works
The SSH client reads your `ProxyJump` entry for `internal-server`. It first makes a connection to the `jumpbox`, establishes a secure tunnel, and then forwards your connection for `internal-server` *through* that initial connection. It’s all seamless.
🚀 Pro-Tip: Pair this with `ForwardAgent yes` for your jumpbox host, and you won’t even need your private keys on the jump host itself.
Linux Tips & Tricks | © ngelinux.com | 10/7/2026
