{% extends "base.html" %} {% block title %}Help{% endblock %} {% block content %}
PatchBay forwards ports between Linux machines over SSH. One machine is the target: it runs this web UI and is reachable from the internet. Every other machine is a client: it keeps an SSH connection open to the target, so it needs no open ports and can sit behind NAT.
You decide what goes where by wiring nodes on the Patch page, like cables on a patch panel. A source is a service you want to reach (for example a web server on a client), a sink is where it shows up (for example a public port on the target). All traffic passes through the target, which counts it for the Stats page.
./install.sh --role client and set TargetHost (and TargetPort) in /etc/patchbay/patchbay.conf.patchbayd --pubkey and paste the output under Settings → Clients.patchbayd on the client. It shows as online on the Patch and Services pages within a few seconds.| Client Source | A service on a client, e.g. 127.0.0.1:80 for a local web server. The address is as seen from that client, so it can also be another machine in the client's network. |
| Public Sink | A port opened on the target. Bind 0.0.0.0 makes it reachable from everywhere, 127.0.0.1 only from the target itself. |
| Client Sink | A port opened on a client. Use it to reach a service on one client from another client, without exposing it publicly. |
| Splitter | Sends one source to several sinks, e.g. the same service on a public port and on a client. A source has only one output, so use a splitter to fan out. |
| Tunnel Source | A host behind a VPN interface (tun0 etc.), on the target or on a client. Enter the interface and the peer's address inside the VPN. |
| Tunnel Sink | A port that only accepts connections arriving through a VPN interface, so VPN peers can reach a service that is not open anywhere else. |
Label is a free-text name shown in Stats. Interface suggestions come from the tun interfaces each host reports.
Normally a service behind PatchBay sees every visitor as coming from PatchBay itself (for example 127.0.0.1). Every sink has two optional checkboxes to pass the real address on. Only one can be on at a time.
mod_remoteip and RemoteIPProxyProtocol On, nginx with listen ... proxy_protocol, HAProxy, Postfix, Dovecot. For UDP the header is in front of every datagram.127.0.0.1. PatchBay sets up the routing this needs on the client by itself (setting TransparentTable, default 470). If the visitor uses IPv6 and the service only IPv4, that connection falls back to the normal address.Services lists the listening ports on every host with the program behind them, which helps to fill in source addresses. Use Refresh now to ask all hosts for a fresh list.
Stats shows traffic per sink: current rates, open connections and history from the last hour up to all time. "In" is traffic towards the service, "out" is traffic back to the visitor. How long history is kept is set under Settings.
patchbay.conf) also manages users, the mail server and statistics retention.| not connected | The sink has no wire into its input. |
| source offline | The client with the source is not connected right now. Check that patchbayd runs there and its key is listed under Settings. |
| protocol mismatch | Source and sink use different protocols (TCP vs UDP). |
| bind ... failed | The port is already used by another program, or the bind address does not exist on that host. |
| interface not present | The tun interface does not exist (yet). PatchBay retries every few seconds, so this clears once the VPN is up. |
| transparent spoofing needs a source on a client | Spoofing only works when the service is reached from a client. Use PROXY v2 instead, or move the source. |
| daemon not reachable | The web UI cannot talk to patchbayd on the target. Changes are saved and applied once it runs again. |