# Instruction for Tunneler usage

**URL:** <https://openziti.discourse.group/t/instruction-for-tunneler-usage/1012>\
**Category:** Ziti Overlay\
**Created:** [January 27, 2023, 7:24pm UTC](https://openziti.discourse.group/t/instruction-for-tunneler-usage/1012 "2023-01-27T19:24:33Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Joe](https://avatars.discourse-cdn.com/v4/letter/j/b9e5f3/32.png) [@Joe](https://openziti.discourse.group/u/Joe)\
**Post date:** [January 27, 2023, 7:24pm UTC](https://openziti.discourse.group/t/instruction-for-tunneler-usage/1012/1 "2023-01-27T19:24:33Z")

</div>

Hi, this link tells me how to install a `Tunneler` ([Tunnelers | OpenZiti](https://docs.openziti.io/docs/reference/tunnelers/)). But I cannot find relevant instruction of how to use it after the installation.

1. How does a tunneler register and enroll to Ziti network?
2. How does an application/client made aware of the tunneler and use it?

Thanks.

---

<div class="post-metadata">

**Author:** ![TheLumberjack](https://yyz2.discourse-cdn.com/free1/user_avatar/openziti.discourse.group/thelumberjack/32/113_2.png) [@TheLumberjack](https://openziti.discourse.group/u/TheLumberjack)\
**Post date:** [January 27, 2023, 8:16pm UTC](https://openziti.discourse.group/t/instruction-for-tunneler-usage/1012/2 "2023-01-27T20:16:41Z")

</div>

Hi @Joe,

> [@Joe](#):
>
> How does a tunneler register and enroll to Ziti network?

Each of the tunnelers is different. `ziti-edge-tunnel` will show you usage info if you execute it, but basically you just supply an identity file, or a directory where you'll put identities and then start it up. For example:

```auto
ziti-edge-tunnel run: run Ziti tunnel (required superuser access)
usage: ziti-edge-tunnel run -i <id.file> [-r N] [-v N] [-d|--dns-ip-range N.N.N.N/n]

        -i|--identity <identity> run with provided identity file (required)
        -I|--identity-dir <dir> load identities from provided directory
        -v|--verbose N set log level, higher level -- more verbose (default 3)
        -r|--refresh N set service polling interval in seconds (default 10)
        -d|--dns-ip-range <ip range> specify CIDR block in which service DNS names are assigned in N.N.N.N/n format (default 100.64.0.1/10)

```

You'd run it with something like: `sudo ./ziti-edge-tunnel run -i ./zsshSvcServer.json`

If you are using a Mac or Windows client, there are "add identity" buttons for both of those:

 ![image](https://global.discourse-cdn.com/free1/uploads/netfoundry/original/1X/942641fa2e2957e4f75b8b23109da1a4845d1f65.jpeg)

> [@Joe](#):
>
> How does an application/client made aware of the tunneler and use it?

The client is instructed by the overlay network itself (via the controller) that it has a service, it's configured for intercepting etc.

I could make a short video showing all that together if you want, and if these screen caps aren't enough for you. You're right, we don't really have a 'how to' guide for this yet, but I can see it being valuable.

If you want a quick video giving a demonstration let me know and I'll make one (I might just make it anyway, if I don't hear back, and I end up making one, I'll post back)

---

<div class="post-metadata">

**Author:** ![scareything](https://yyz2.discourse-cdn.com/free1/user_avatar/openziti.discourse.group/scareything/32/106_2.png) [@scareything](https://openziti.discourse.group/u/scareything)\
**Post date:** [February 1, 2023, 6:16pm UTC](https://openziti.discourse.group/t/instruction-for-tunneler-usage/1012/3 "2023-02-01T18:16:41Z")

</div>

Hi @Joe. When I read your second question I took “application/client” to mean the tcp/ip application that is ultimately initiating the connection and being proxied over the Ziti network. If that take is correct, then I’d say your question gets right to the magic of what the tunnelers do. The short answer is that the tcp/ip application is unaware that its outbound connections are being intercepted by the tunneler and then proxied over a Ziti overlay.

Basically the tunneler creates routes and DNS mappings for the IPs and hostnames that are specified in your Ziti service configurations. Depending on the operating system, the tunneler either creates a virtual network interface (called a `tun` interface) or a special listening socket that can have specific destination addresses diverted to it (via iptables `tproxy` rules).

The `tun` and `tproxy` intercept methods are explained in _slightly_ more detail at [ziti/ziti-tunnel at release-next · openziti/ziti · GitHub](https://github.com/openziti/ziti/tree/release-next/ziti-tunnel). Note that this document specifically relates to the older golang-based `ziti-tunnel` tunneler (which is currently deprecated), but the `tun` and `tproxy` overviews are still mostly worthwhile their own.

So connections to IPs are intercepted _transparently_ (that is, without the knowledge of the initiating application) via `tun` or `tproxy`. To intercept connections to hostnames, tunnelers run an internal DNS server that maps hostnames in the ziti service configurations to IP addresses that are routed to the `tun` interface or `tproxy` listener.

If my mentions of “service configurations” are a little vague, my colleague Geoff wrote a few “how-to” style bogs that show how the service configurations are made (among other things).

- [Free Secure Access to NAS From Anywhere](https://blog.openziti.io/free-secure-access-to-nas-from-anywhere)
- [Set Up a Secure Multiplayer Minecraft Server](https://blog.openziti.io/set-up-a-secure-multiplayer-minecraft-server)

Thanks for the question, and please let me know if this answer doesn’t give you what you’re looking for!
