Remote access to beaglebone blue

Viewed 270

I'm working on a personal project that involves a Beaglebone blue. I want to access it remotely from anywhere. I'm not sure what the best way to do this is. I know I could just forward a corresponding port (unsafe) or something along those lines but I want to avoid too many security flaws. The board controls a camera which I plan on displaying in a UI that also allows me to move the camera around. There are so many companies that have devices that can be controlled from anywhere...so how do I?

3 Answers

There are a lot of solutions for this question. I will mention a few.

In general your device should either:

Have a public ip (if your infra allows it and your ISP provides this service), and then you can access it directly.

Connect to an online server using some service:

  1. Using VPN. Connecting your device to an openVPN server (I think this is the most popular solution). Wiregurd is also quite popular
  2. Using consul or etcd or similar service for its service discovery feature
  3. Using a cloud provider (AWS, Azure, GCP etc.) IoT service products

So let me post my comments as a coherent answer. Assuming you have a dynamic IP but otherwise unrestricted access to it from public Internet:

  1. Make sure your router always gives the BB the same address in LAN
  2. Install your Web UI and other stuff on BB
  3. Configure SSH server on BB to accept only key-based authentication, no passwords (PasswordAuthentication no in /etc/ssh/sshd_config).
  4. Generate a keypair in your PC and give your public key to the BB (in /home/<youruser>/.ssh/authorized_keys). Ensure key-based SSH logins works in local network before proceeding.
  5. Subscribe to a dynamic DNS service with a Linux client that runs on ARM. Install the client on BB.
    I use No-IP, where the client comes as source code and probably compiles on BB (haven't tested). It's a bit annoying as you have to re-activate your free subscription once a month, maybe there are better services.
  6. In your router forward a random external port (8822, 62222, pick a mnemonic) to the BB-s IP and port 22.
  7. Remotely SSH into the BB using your dynamic DNS and external port (e.g. myhome.no-ip.org:62222). While testing in your LAN, note some routers support a "hairpin" connection to the public IP from inside the LAN, some don't.
    Don't forget to configure your SSH client to activate local port 80 forwarding in the client (-L 80:localhost:80 in command line, similar in Putty GUI)
  8. While the SSH link is up, you can access the Web UI running in BB from your local PC on address http://localhost:80 (securely tunneled through the SSH connection).
Related