Secure TCP/UDP port tunneling over HTTPS — no VPN needed.
Zeltunnel is a lightweight, single-binary tunneling tool that wraps TCP and UDP traffic inside an encrypted HTTPS connection. Firewalls and deep-packet inspection only see ordinary HTTPS traffic on port 443 — exactly like regular web browsing. No VPN configuration, no router port-forwarding, no cloud account required.
Zeltunnel is application-protocol blind: it does not understand or inspect what you are forwarding. RDP, SSH, VNC, databases, DNS, game servers, and custom protocols all work identically. You only need to specify whether to forward TCP or UDP, a local listen address, and a remote target.
[Your Machine] ──── HTTPS/WSS (:443) ────▶ [Zeltunnel Server] ────▶ [Target Host]
127.0.0.1:3390 encrypted tunnel.example.com 2.3.3.3:3389
Local forward mode — your app connects to a local port; Zeltunnel sends traffic through the encrypted tunnel; the server connects to the remote target on your behalf.
Reverse mode — the server exposes a public port; internet users connect to it; traffic flows back through the tunnel to a service running on your machine.
# Creates server.yml, client.yml, certs/server.crt, certs/server.key
# in the current directory — a random 256-bit token is generated automatically
docker run --rm -v $(pwd):/config rocheston/zeltunnel config init --out /config
server:
public_url: "https://tunnel.example.com"
bind_https: "0.0.0.0:443"
tls_cert: "/config/certs/server.crt"
tls_key: "/config/certs/server.key"
docker run -d \
-p 443:443 \
-v $(pwd):/config \
rocheston/zeltunnel server --config /config/server.yml
docker run -d \
-p 3389:3389 \
-v $(pwd):/config \
rocheston/zeltunnel client --config /config/client.yml
docker run --rm rocheston/zeltunnel test
# RDP — connect your RDP client to localhost:3389
docker run --rm -p 3389:3389 rocheston/zeltunnel connect \
--server https://tunnel.example.com \
--token MY_SECRET_TOKEN \
--listen 0.0.0.0:3389 \
--target REMOTE_HOST:3389 \
--protocol any
# SSH
docker run --rm -p 2222:2222 rocheston/zeltunnel connect \
--server https://tunnel.example.com \
--token MY_SECRET_TOKEN \
--listen 0.0.0.0:2222 \
--target 10.0.0.5:22 \
--protocol tcp
# DNS (UDP)
docker run --rm -p 5353:5353/udp rocheston/zeltunnel connect \
--server https://tunnel.example.com \
--token MY_SECRET_TOKEN \
--listen 0.0.0.0:5353 \
--target 10.0.0.53:53 \
--protocol udp
docker run --rm rocheston/zeltunnel reverse \
--server https://tunnel.example.com \
--token MY_SECRET_TOKEN \
--remote-listen 0.0.0.0:8080 \
--target 127.0.0.1:8080 \
--protocol tcp
# Hash a token for use in server.yml
docker run --rm rocheston/zeltunnel token hash MY_SECRET_TOKEN
# Generate a self-signed TLS certificate
docker run --rm -v $(pwd)/certs:/config/certs rocheston/zeltunnel cert generate \
--out /config/certs --server-name tunnel.example.com
# Validate a config file
docker run --rm -v $(pwd):/config rocheston/zeltunnel config check --config /config/server.yml
# Run the built-in self-test (no config needed)
docker run --rm rocheston/zeltunnel test
| Option | Values | Description |
|---|---|---|
--protocol | tcp | udp | any | What to forward. any creates both TCP and UDP listeners. |
--transport | wss | quic | auto | Tunnel transport. auto tries QUIC first, falls back to WSS. |
server:
public_url: "https://tunnel.example.com"
bind_https: "0.0.0.0:443"
tls_cert: "/config/certs/server.crt"
tls_key: "/config/certs/server.key"
security:
allow_open_proxy: false
default_bind_host: "127.0.0.1"
max_tcp_connections_per_client: 256
auth:
tokens:
- id: "alice"
token_sha256: "<output of: zeltunnel token hash MY_SECRET>"
allowed_targets:
- "*:*" # allow any target (restrict per-user in production)
allowed_reverse_listens:
- "0.0.0.0:30000-30100"
transports:
wss:
enabled: true
path: "/zt/v1/connect"
quic:
enabled: false
bind: "0.0.0.0:443"
allowed_targets list; the server rejects all other connections2.3.3.3:3389), CIDR (10.0.0.0/8:22), wildcard hostname (*.corp.example.com:443), or open (*:*)Built with 💛 by Haja Mo
Content type
Image
Digest
sha256:4fc3eb867…
Size
34.3 MB
Last updated
5 months ago
docker pull rocheston/zeltunnel