One Pivot Runs Out
You built a tunnel. You routed the internal network. You can breathe.
Then you scan it, and the real target isn’t there.
It’s one more network deeper, behind a machine you just found. A subnet only that machine can see.
Your first pivot got you into network B. The goal is in network C, and only pivot 2 can reach it.
You need to pivot through your pivot. That’s a double pivot.
The Catch
Here’s what makes it tricky.
Your second machine, pivot 2, is buried inside network B.
It can talk to its neighbours in B. It cannot talk to your Kali box out on the internet.
It has no route home.
So if you just run a second agent on pivot 2 and point it at Kali, the connection dies at the perimeter. Same wall, same lesson as before:
Pivot 2 can’t dial you directly. But it can reach pivot 1, which already has a tunnel home.
The trick is to make pivot 1 pass the connection along.
Watch the chain build in the animation:
- Pivot 2 falls, but its bid to reach Kali slams into the first firewall.
- Pivot 1 opens a relay, a door inside network B that quietly forwards back to your proxy.
- Agent 2 dials pivot 1, rides tunnel 1 home, and tunnel 2 forms.
- A second interface routes network C, and your traffic bores two layers deep to the target.
Same recipe as one pivot, just stacked.
Step 1: Relay the Proxy Port
On pivot 1’s session, open a listener that forwards ligolo’s own port straight back to your proxy:
[Agent : pivot1@target] » listener_add --addr 0.0.0.0:11601 --to 127.0.0.1:11601 --tcp Now anything that hits pivot 1 on 11601 gets carried back through tunnel 1 to your Kali proxy.
You’ve placed a door to your proxy inside network B.
Step 2: Point Agent 2 at Pivot 1
From your foothold on pivot 2, run a second agent. Aim it at pivot 1’s internal IP, not at Kali:
The connection reaches pivot 1, rides tunnel 1 home, and lands on your proxy.
A second session appears in your console. Pivot 2 just phoned home, without ever being able to see you.
Step 3: A Second Interface and Route
Each pivot needs its own virtual card. Build a second one:
Select the new session, start its tunnel on that interface, and route network C down it:
[Agent : pivot2@target] » start --tun ligolo2 That’s it. Network C is now routable from your Kali box, three networks away, and your tools still have no idea any of this is happening.
The Pattern Generalizes
Look at what each layer needed:
| Ingredient | Why |
|---|---|
| a relay listener on the previous pivot | gives the next agent a door home |
| a fresh agent pointed at that pivot | rides the existing tunnels back |
a fresh interface (ligolo2, ligolo3, …) | keeps each hop’s traffic separate |
| a fresh route | tells Kali which subnet lives on which card |
Triple pivot? Quadruple? It’s the same four steps, over and over. Chain as deep as the network goes.
Don’t Forget the Extra Cleanup
A double pivot leaves two of everything behind.
When you’re done, tear down both interfaces and both routes, and close the relay listener you opened on pivot 1:
Every card you raise and every door you open is one more thing to close. Leave the network the way you found it.