Back to articles
Technology Insight

Bypass Strict Corporate Firewalls: A Comprehensive Guide to Managing VPS via SSH over WebSockets using Chisel

June 6, 2026

The Challenge of Strict Corporate Network Environments

In the modern enterprise landscape, security is paramount. Network administrators routinely implement stringent firewall policies to safeguard internal assets, often restricting outbound traffic to essential web browsing ports, specifically port 80 (HTTP) and port 443 (HTTPS). While this drastically reduces the attack surface, it poses a significant hurdle for systems engineers, DevOps professionals, and system administrators who require remote access to cloud infrastructure via the standard SSH port (22).

When deep packet inspection (DPI) and strict egress filtering are enforced, traditional methods like altering the default SSH port fail. The firewall identifies the non-HTTP traffic and abruptly terminates the connection. To overcome this infrastructure bottleneck without violating the integrity of corporate security layers, a sophisticated technique is required: encapsulating SSH traffic inside standard WebSockets. This is where Chisel becomes an indispensable tool in your administrative toolkit.

Understanding Chisel and the Mechanics of WebSocket Tunneling

Chisel is a fast, secure, and lightweight TCP/UDP tunnel written in Go. It operates by creating a client-server architecture where all transported data is encapsulated within standard HTTP requests and upgraded to WebSockets. Because WebSockets run natively over ports 80 and 443, firewall rules and reverse proxies perceive the connection as standard web traffic, allowing it to pass through unhindered.

Here is how the architecture functions in practice:

  • The Chisel Server: Deployed on your remote Virtual Private Server (VPS). It listens for incoming WebSocket connections on an open web port (e.g., 443) and forwards authenticated internal traffic to the local SSH daemon (port 22).
  • The Chisel Client: Run on your local corporate workstation. It establishes an outbound connection to the Chisel server, masquerading as a standard browser making an HTTPS upgrade request.
  • The SSH Client: Initiates a connection to a local port defined by the Chisel client, which is then tunneled securely to the remote VPS.
By utilizing this encapsulation method, data is double-encrypted: first by Chisel's internal SSH-based transport mechanism (or TLS via a reverse proxy), and second by the native SSH protocol itself, ensuring robust end-to-end security.

Prerequisites and Environment Setup

Before initiating the implementation, ensure you have administrative access to both your local environment and the target cloud infrastructure. You will need:

  1. A remote VPS running a modern Linux distribution (e.g., Ubuntu, Debian, or CentOS) with an active SSH daemon.
  2. A registered domain name pointed to your VPS IP address (highly recommended for implementing TLS encryption).
  3. Chisel binaries compiled for your specific server and client operating systems.

Installing Chisel on the Remote VPS and Local Client

Since Chisel is a single binary executable, installation is straightforward. You can download the pre-compiled binaries directly from the official GitHub repository or install them using terminal commands. On a Linux-based VPS, execute the following commands:

curl [https://i.jpillora.com/chisel](https://i.jpillora.com/chisel)! | bash

For your local corporate workstation, download the corresponding version (Windows, macOS, or Linux). Ensure that the binary is added to your system's environment PATH for ease of execution.

Step-by-Step Implementation Guide

Step 1: Configuring the Chisel Server on the VPS

To ensure the connection bypasses deep packet inspection, we will configure the Chisel server to run on a web-friendly port. For testing purposes, we can launch the server directly via the command line:

chisel server --port 8080 --reverse

In this configuration, the --reverse flag is critical. It allows the client to dictate the port forwarding rules, granting the local machine the ability to map its local ports to the server's internal services.

Step 2: Deploying a Reverse Proxy (Nginx) with Let's Encrypt TLS

Running Chisel over raw HTTP (port 8080) may still trigger alerts on advanced corporate firewalls utilizing Deep Packet Inspection (DPI), as the underlying traffic lack valid SSL certificates. To make the traffic completely indistinguishable from legitimate enterprise web traffic, we place Chisel behind an Nginx reverse proxy secured with an SSL/TLS certificate from Let's Encrypt.

Create an Nginx configuration block for your domain (e.g., vps.yourdomain.com):

server {
    listen 443 ssl;
    server_name vps.yourdomain.com;

    ssl_certificate /etc/letsencrypt/live/[vps.yourdomain.com/fullchain.pem](https://vps.yourdomain.com/fullchain.pem);
    ssl_certificate_key /etc/letsencrypt/live/[vps.yourdomain.com/privkey.pem](https://vps.yourdomain.com/privkey.pem);

    location / {
        proxy_pass [http://127.0.0.1:8080](http://127.0.0.1:8080);
        proxy_http_version 1.1;
        proxy_set_header Upgrade $http_upgrade;
        proxy_set_header Connection "upgrade";
        proxy_set_header Host $host;
        proxy_cache_bypass $http_upgrade;
    }
}

This configuration seamlessly upgrades standard HTTP requests to WebSockets and routes them internally to the Chisel server listening on port 8080. Restart Nginx to apply changes.

Step 3: Establishing the Tunnel from the Local Client

With the server secured behind HTTPS, execute the Chisel client on your local machine to open the encrypted tunnel. Run the following command in your terminal:

chisel client [https://vps.yourdomain.com](https://vps.yourdomain.com) 2222:127.0.0.1:22

This command instructs the Chisel client to connect to the secure remote URL and forward any traffic hitting local port 2222 across the WebSocket tunnel directly to port 22 (the standard SSH port) on the remote VPS.

Step 4: Connecting via SSH Over the WebSocket Tunnel

Now that the tunnel is active, your corporate firewall sees nothing more than an open, persistent HTTPS connection to a secure website. To access your VPS command line, open a new terminal window on your local machine and target the mapped local port:

ssh [email protected] -p 2222

Authentication occurs exactly as it would during a standard SSH session. You can utilize your existing SSH keys or password credentials securely, as the traffic flows flawlessly through the established WebSocket conduit.

Optimizing for Production: Persistent Services and Security Hardening

To ensure this solution is robust enough for enterprise-grade reliance, you must guarantee high availability and protect the endpoint from unauthorized scanning.

Creating a Systemd Service for Chisel

To prevent the Chisel server process from terminating when your terminal closes, configure it as a background service using systemd. Create a service file at /etc/systemd/system/chisel.service:

[Unit]
Description=Chisel Tunnel Server
After=network.target

[Service]
Type=simple
ExecStart=/usr/local/bin/chisel server --port 8080 --reverse --auth "admin:StrongSecretToken"
Restart=on-failure
User=nobody

[Unit]
WantedBy=multi-user.target

Note the addition of the --auth flag. This ensures that only clients possessing the correct credentials can establish a tunnel, preventing unauthorized entities from exploiting your endpoint.

Enable and start the service with the following administrative commands:

sudo systemctl daemon-reload
sudo systemctl enable chisel
sudo systemctl start chisel

Conclusion

Bypassing restrictive corporate firewalls does not require compromising security or resorting to illicit software. By leveraging Chisel to encapsulate SSH connections inside standard, TLS-encrypted WebSockets, engineering teams can maintain optimal productivity and seamless VPS administration from anywhere. By routing traffic through standard web ports like 443, this approach ensures your administrative operations remain completely hidden from aggressive egress filters while maintaining strict end-to-end cryptographic integrity.