FastTunnel is a cross-platform intranet penetration framework written in C# that lets developers and operators expose services running on machines behind NAT to the public internet.
What it is
FastTunnel is an open-source intranet penetration tool and framework built in C# and distributed under the Apache License 2.0. Rather than being a fixed application, it is described as an easy-to-extensible and easy-to-maintain framework: you can reference the NuGet package FastTunnel.Core and build your own penetration application around it, targeting whatever business extensions you need. The project lives in the Infrastructure & Operations ecosystem under Networking & Connectivity, with published topics spanning tunnel, reverse-proxy, tcp-proxy, http-proxy, nat, proxy, ssh and rdp.
The concrete problem it solves is reachability: services hosted on a local or intranet machine have no public address, so they cannot be reached by other people or by external services such as callback endpoints. FastTunnel punches a tunnel out through that network boundary so intranet services can be exposed to the public network for yourself or anyone to access, whether the origin machine is a Windows, Linux or Mac host. It replaces the need to run separate ad-hoc port-mapping, reverse-proxy and HTTP proxy setups for each internal service by providing one framework that handles tunneling, domain-based routing, port forwarding and proxying together.
Key capabilities
- Remote access to intranet computers running Windows, Linux or Mac from outside the network.
- Access intranet web services through a custom domain name, a configuration the README notes is usually used for WeChat development.
- Port forwarding and port mapping to reach services on any intranet port, with MySQL, Redis and FTP named as examples.
- Binding multiple domain names to access different intranet services through the same tunnel.
- Restriction of access through a domain name whitelist.
- Client identity verification before a connection is accepted.
- Building your own penetration application by referencing the
FastTunnel.Core NuGet package.
Who uses it and how
- Developers working on WeChat development who need a public domain endpoint pointing at an intranet web service running on a local machine.
- Operators who need to reach database and file services such as MySQL, Redis and FTP that only listen on an internal host, reached through port forwarding.
- Teams running mixed Windows, Linux and Mac machines that need remote reachability into any of them.
- Framework users who consume
FastTunnel.Core from NuGet and extend it with their own business logic to build a penetration platform for others to register against.
- Administrators restricting exposure by combining domain name whitelisting with client identity verification.
Getting started
Install the FastTunnel.Core package from NuGet to build against the framework, and follow the getting-started guide in the opentask-doc repository; the project also points to mirror repositories on GitHub and Gitee.
How it compares
FastTunnel stands alone in this registry.
When to use it — and when not to
The README explicitly warns not to use the service for important items, so critical or production workloads should look elsewhere. Note also that p2p penetration is listed as unimplemented, and the project carries 18 open issues, so features you may assume are complete may not be. Its identity as a framework rather than a turnkey product means adopting it means taking on building, operating and maintaining your own penetration application rather than simply deploying one.