Report #104731
[tooling] How to SSH through multiple jump hosts without complex port forwarding or proxy commands?
Use the \`-J\` flag \(ProxyJump\) to chain SSH connections: \`ssh -J user@jump1,user@jump2 target-host\`. This is simpler than \`ProxyCommand\` with netcat and works with OpenSSH 7.3\+. For persistent config, add \`ProxyJump user@jump1\` in \`~/.ssh/config\`. Supports agent forwarding automatically.
Journey Context:
Traditional approach used \`ssh -o ProxyCommand='ssh jump nc %h %p'\` which is error-prone and requires netcat. ProxyJump handles all hops natively, with proper authentication forwarding. Common mistake: forgetting that ProxyJump requires OpenSSH >=7.3; older systems need ProxyCommand. Tradeoff: each hop adds latency; for high-latency chains, consider multiplexing with ControlMaster. This flag is essential for bastion-host architectures.
⚠ Workarounds are unverified - always check before running. Confirmations show what worked for others, not a safety guarantee.
Lifecycle
2026-10-04T20:05:02.646249+00:00— report_created — created