Choose the right direction
Local forwarding opens a listener on your device and carries its traffic toward an approved remote destination. Remote forwarding opens a listener on the SSH server. In a native SSH session its destination is reached from your device; in a browser Gateway session its destination is reached from the Gateway, not your browser. A SOCKS5 proxy lets a compatible application request destinations through a native listener.
Local and SOCKS5 listeners require a supported native app: a browser cannot bind a TCP port on your device. Forwarding also depends on the server and route allowing the requested operation.
Start a tunnel
- Open Port Forwarding for the intended connected host.
- Choose local, remote or SOCKS5 mode and read the explanation shown for it.
- Enter the listener and destination details. The app only permits loopback for local and SOCKS5 listeners.
- Review the displayed exposure and start the tunnel.
- Confirm it appears under Active tunnels, then test it from the intended application.
- Choose Stop tunnel when finished and verify it is no longer active.
Remote forwarding requests a loopback listener on the SSH server, but the server's GatewayPorts policy can override the requested bind address. Verify that policy before exposing a sensitive service. Other processes on the listening device can still reach a loopback listener. Tunnels stop when their owning SSH connection closes.
A saved preset is configuration, not a running listener. Review Auto-start on connect before saving a preset so future connections do not unexpectedly start it.
Forwarding is not destination authentication
The service reached through a tunnel still needs its own appropriate authentication and encryption. Do not expose a database or administrative service more broadly than intended, and do not treat a loopback listener as permission for arbitrary remote destinations.
SSH agent forwarding is a separate advanced capability. It can let a remote environment request authentication operations using your agent. Enable it only for trusted hosts and a specific need, not as a general fix for connection errors.
See connection routes and privacy boundaries before using an unfamiliar Gateway.