mirror of
https://github.com/fosrl/pangolin.git
synced 2026-05-09 06:09:26 -05:00
Closed
opened 2026-04-30 03:52:09 -05:00 by GiteaMirror
·
12 comments
No Branch/Tag Specified
main
dependabot/npm_and_yarn/fast-uri-3.1.2
crowdin_dev
dev
s3
dependabot/npm_and_yarn/fast-xml-builder-1.2.0
dependabot/npm_and_yarn/axios-1.15.2
dependabot/npm_and_yarn/next-intl-4.9.2
dependabot/npm_and_yarn/prod-patch-updates-64dd675a88
dependabot/npm_and_yarn/dev-minor-updates-10ef4f0f15
dependabot/docker/node-26-alpine
dependabot/docker/docker/library/node-26-slim
dependabot/npm_and_yarn/multi-7bdfbe8666
resource-policies
redis
newt-install-commands
dependabot/npm_and_yarn/multi-d2fd79378c
dependabot/npm_and_yarn/uuid-14.0.0
dependabot/npm_and_yarn/postcss-8.5.10
miloschwartz-patch-2
dependabot/github_actions/actions/setup-node-6.4.0
dependabot/npm_and_yarn/next-16.2.1
dependabot/npm_and_yarn/recharts-3.8.1
cross-org-idp
update-readme
miloschwartz-patch-1
breakout-sites-tables
revert-2766-feature/systemd-install-instructions
ssh
delete-account
msg-delivery
org-only-idp
cicd
patch
site-targets-auto-login
1.18.3-s.3
1.18.3-s.2
1.18.3
1.18.3-s.1
1.18.3-s.0
1.18.2-s.5
1.18.2-s.4
1.18.2-s.3
1.18.2-s.2
1.18.2-s.1
1.18.2
1.18.2-s.0
1.18.1-s.7
1.18.1-s.6
1.18.1-s.5
1.18.1-s.4
1.18.1-s.3
1.18.1-s.2
1.18.1
1.18.1-s.1
1.18.1-s.0
1.18.0-s.2
1.18.0-s.1
1.18.0
1.18.0-s.0
1.17.1-s.7
1.17.1-s.6
1.18.0-rc.0
1.17.1-s.5
1.17.1-s.4
1.17.1-s.3
1.17.1
1.17.1-s.2
1.17.1-s.1
1.17.1-s.0
1.17.0-s.4
1.17.0
1.17.0-s.3
1.17.0-s.2
1.17.0-s.1
1.17.0-s.0
1.17.0-rc.0
1.16.2-s.22
1.16.2-s.21
1.16.2-s.20
1.16.2-s.19
1.16.2-s.18
1.16.2-s.17
1.16.2-s.16
1.16.2-s.15
1.16.2-s.14
1.16.2-s.13
1.16.2-s.12
1.16.2-s.11
1.16.2-s.10
1.16.2-s.9
1.16.2-s.8
1.16.2-s.7
1.16.2-s.6
1.16.2-s.5
1.16.2-s.4
1.16.2-s.3
1.16.2-s.2
1.16.2-s.1
1.16.2
1.16.2-s.0
1.16.1-s.1
1.16.1
1.16.1-s.0
1.16.0
1.16.0-s.1
1.16.0-s.0
1.16.0-rc.0
1.15.4-s.10
1.15.4-s.9
1.15.4-s.8
1.15.4-s.7
1.15.4-s.6
1.15.4-s.5
1.15.4-s.4
1.15.4-s.3
1.15.4-s.2
1.15.4-s.1
1.15.4
1.15.4-s.0
1.15.3
1.15.3-s.1
1.15.3-s.0
1.15.2
1.15.1-s.1
1.15.1-s.0
1.15.1
1.15.0-s.5
1.15.0
1.15.0-s.4
1.15.0-s.3
1.15.0-s.2
1.15.0-s.1
1.15.0-s.0
1.15.0-rc.0
1.14.1-s.3
1.14.1-s.2
1.14.1-s.1
1.14.1-s.0
1.14.1
1.14.0-s.2
1.14.0
1.14.0-rc.0
1.13.1
1.13.1-s.0
1.13.0
1.13.0.s.0
1.13.0-rc.0
1.12.2-s.5
1.12.3
1.12.2-s.4
1.12.2-s.3
1.12.2-s.2
1.12.2-s.1
1.12.2
1.12.2-s.0
1.12.1
1.12.0
1.12.0-s.0
1.12.0-rc.0
1.11.1
1.11.1-s.0
1.11.0-s.5
1.11.0
1.11.0-s.4
1.11.0-s.3
1.11.0-s.2
1.11.0-s.1
1.11.0-s.0
1.10.3
1.10.2
1.10.1
1.10.0
1.9.4
1.9.3
1.9.2
1.9.1
1.9.0
1.8.0
1.7.3
1.7.2
1.7.1
1.7.0
1.6.2
1.6.1
1.6.0
1.5.1
1.5.0
1.4.0
1.3.2
1.3.1
1.3.0
1.2.0
1.1.0
1.0.1
1.0.0
1.0.0-beta.15
1.0.0-beta.14
1.0.0-beta.13
1.0.0-beta.12
1.0.0-beta.11
1.0.0-beta.10
1.0.0-beta.9
1.0.0-beta.8
1.0.0-beta.7
1.0.0-beta.6
1.0.0-beta.5
1.0.0-beta.4
1.0.0-beta.3
1.0.0-beta.2
1.0.0-beta.1
Labels
Clear labels
api
authentication
bug
config
dependencies
docker
documentation
enhancement
good first issue
help wanted
Improvement
Look Into
needs investigating
networking
new feature
non-critical bug
potential bug
pull-request
question
reverse proxy
Security
stale
ui
wontfix
Mirrored from GitHub Pull Request
No Label
stale
Milestone
No items
No Milestone
Projects
Clear projects
No project
No Assignees
Notifications
Due Date
No due date set.
Dependencies
No dependencies set.
Reference: github-starred/pangolin#8287
Reference in New Issue
Block a user
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Delete Branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Originally created by @roadkingvrod on GitHub (Apr 24, 2025).
Original GitHub issue: https://github.com/fosrl/pangolin/issues/593
I may be misunderstanding how this should work. I have successfully set up https proxies and they work great, and as expected.
However, I'm trying to figure out how to set up an RDP type resource. Here's my scenario:"
I have newt installed in a separate subnet and connected (site shows connected in Pangolin). I am now trying to set up an rdp connection to a server in that network via the tcp resources. I have set up a resource to the best of my understanding, and in the newt logs, I see thsi:
nelIP:100.89.128.4]}
INFO: 2025/04/24 11:21:41 WireGuard device created. Lets ping the server now...
INFO: 2025/04/24 11:21:41 Ping attempt 1
INFO: 2025/04/24 11:21:41 Pinging 100.89.128.1
INFO: 2025/04/24 11:21:41 Ping latency: 9.9418ms
INFO: 2025/04/24 11:21:41 Starting ping check
INFO: 2025/04/24 11:21:41 Started tcp proxy from 100.89.128.4:43996 to 192.168.52.10:3389
INFO: 2025/04/24 11:22:11 Pinging 100.89.128.1
INFO: 2025/04/24 11:22:11 Ping latency: 4.6659ms
INFO: 2025/04/24 11:22:41 Pinging 100.89.128.1
INFO: 2025/04/24 11:22:41 Ping latency: 2.6014ms
192.168.52.10:3389 is the server I want to remote desktop to once I'm authenicated into Pangolin.
How do I actually connect to it?
Thanks for helping with my basic knowledge!
@roadkingvrod commented on GitHub (Apr 24, 2025):
Important to note that Newt is running directly on Windows so there are no container issues (and windows fiirewall is turned off)
@miloschwartz commented on GitHub (Apr 24, 2025):
Assuming the proxy is working, to connect you'd use the VPS IP as the hostname, and use the port you set when you defined the resource as the port.
@roadkingvrod commented on GitHub (Apr 24, 2025):
That's how I thought it should work but no luck. Knowing that, I'll keep tinkering and report back anything I find. Thanks!
@miloschwartz commented on GitHub (Apr 24, 2025):
Just doing my due diligence by asking, have you triple checked the following:
@roadkingvrod commented on GitHub (Apr 24, 2025):
OS firewall is off. But I have a question on the outside firewall/router. I was hoping that you'd have to authenticate to gain access to the TCP port (as RDP open to the web can be quite dangerous). Does Pangolin just enrypt the data without authentication?
@TuncTaylan commented on GitHub (Apr 25, 2025):
Just for this I just tested on my setup, here is a quick summary and points you might be missing:
config/traefik/traefik_config.ymldocker-compose-ymlallow_raw_resourcesflag in yourconfig/config.ymlis set to true.docker compose up -d --force-recreateThat's it, it works as described.
To your question about encryption, pingolin sends the raw TCP, everything else is handled by the RDP, and RDP is encapsulated and encrypted within TCP.
@roadkingvrod commented on GitHub (Apr 25, 2025):
Thank you @TuncTaylan and @miloschwartz . I appreciate the help.
@akehir commented on GitHub (Apr 26, 2025):
Small question to @TuncTaylan , I haven't found this in the docs explicitly; but it's a question asked by @roadkingvrod .
He asked:
However to my understanding, raw ports are always forwarded directly without authentication. Therefore, this is basically the same as exposing the RDP port directly to the internet; or am I missing something?
@TuncTaylan commented on GitHub (Apr 26, 2025):
Grüezi!
Yes, that’s correct — Pangolin does not provide authentication or encryption for raw TCP/UDP resources. I was referring to the RDP protocol, which should be encrypted within the TCP communication.
That said, exposing RDP directly to the internet is risky. I personally wouldn’t do it, as Microsoft hasn’t historically been known for strong inherent security.
@github-actions[bot] commented on GitHub (May 11, 2025):
This issue has been automatically marked as stale due to 14 days of inactivity. It will be closed in 14 days if no further activity occurs.
@github-actions[bot] commented on GitHub (May 25, 2025):
This issue has been automatically closed due to inactivity. If you believe this is still relevant, please open a new issue with up-to-date information.
@krevelen commented on GitHub (Oct 27, 2025):
you could use an SSH tunnel instead, and then initiate rdp on your (extended) localhost