Port Forward Through Gateway to Workstation


I have whonix gateway and work station running on a proxmox host. I would like to be able to forward a port from the gateway to the work station so that I can VNC into the work station.

I tried the following, but it did not seem to work…

iptables -A PREROUTING -t nat -i eth0 -p tcp --dport 5900 -j DNAT --to-destination
iptables -A FORWARD -p tcp -d --dport 5900 -j ACCEPT
iptables -A POSTROUTING -t nat -s -o eth0 -j MASQUERADE

So my question is, what iptables commands do I need to run on the gateway and what commands do I need to run on the work station?

Thank you so much for any help you can give, I really appreciate it, Ive been banging my head against the desk for a couple of days now trying to get this done.


Possible. Tested with VirtualBox and Qubes. (KVM should work in principle too but untested by me.) Working with ssh, sshfs and VNC. Virtualizer specific. But undocumented.

Which virtualizer?

Hopefully these pointers can help.

You need to open a port in Whonix-Gateway firewall.


You need to open a port in Whonix-Workstation firewall.


Do SSH into Whonix-Gateway as exercise preparing for…


SSH into Whonix-Workstation


SSH first as exercise. Then you get the idea, you’d just change the port numbers and can use VNC.

I would also exercise this locally first before doing this on remote.


No need.

To get from Whonix-Gateway to Whonix-Workstation I’d use:

  • SSH port forwarding,
  • socat, OR
  • systemd-socket-proxyd
1 Like

Proxmox is KVM.

1 Like

Thank you so much, SSH port forwarding worked like a charm!

1 Like
[Imprint] [Privacy Policy] [Cookie Policy] [Terms of Use] [E-Sign Consent] [DMCA] [Contributors] [Investors] [Priority Support] [Professional Support]