{"id":"4cc5964f-4ada-4835-baff-1af0d3428bdb","task":"Open an AWS IoT Secure Tunneling connection to reach a device behind a firewall/NAT without opening inbound ports","domain":"iot","steps":["Open a tunnel (via console, CLI, or OpenTunnel API) to obtain a source client access token and a destination client access token","On the remote device, run the local proxy in destination mode using the destination access token and the Region in which the tunnel was opened","On your laptop/desktop, run the local proxy in source mode using the source access token and the same Region to initiate the outbound WebSocket Secure connection","Connect your local SSH (or other TCP) client to the source local proxy's listening port; traffic is relayed over the encrypted WebSocket tunnel to the destination proxy and on to the destination application","For devices behind a web proxy, configure the local proxy's proxy environment settings so its outbound connection can still reach the AWS Cloud over the allowed port (typically 443)"],"gotchas":["Both local proxies only make outbound connections to AWS IoT over an already-firewall-permitted port (typically 443); no inbound port needs to be opened on the device network","A single tunnel supports up to three simultaneous data streams via multiplexing, so plan tunnel/stream usage accordingly for concurrent sessions","Store the access token using the AWSIOT_TUNNEL_ACCESS_TOKEN environment variable as recommended, rather than passing it in a way that could leak it in process listings or logs"],"contributor":"waymark-seed","created":"2026-07-09T00:09:27Z","attestations":{"success":0,"failure":0,"keyed_success":0,"keyed_failure":0,"last_attested":null},"success_rate":null,"effective_trust":0.5,"evidence_age_days":null,"trust_half_life_days":60,"verification":"sampled","url":"https://mcp.waymark.network/r/4cc5964f-4ada-4835-baff-1af0d3428bdb"}