Remote tools

Port forwarding and SOCKS5

Reach an approved service through a connection while keeping listener scope and exposure explicit.

2 min read User guide

Choose the right direction

Local forwarding opens a listener on your device and carries its traffic toward an approved remote destination. Remote forwarding opens a listener on the SSH server. In a native SSH session its destination is reached from your device; in a browser Gateway session its destination is reached from the Gateway, not your browser. A SOCKS5 proxy lets a compatible application request destinations through a native listener.

Local and SOCKS5 listeners require a supported native app: a browser cannot bind a TCP port on your device. Forwarding also depends on the server and route allowing the requested operation.

Start a tunnel

  1. Open Port Forwarding for the intended connected host.
  2. Choose local, remote or SOCKS5 mode and read the explanation shown for it.
  3. Enter the listener and destination details. The app only permits loopback for local and SOCKS5 listeners.
  4. Review the displayed exposure and start the tunnel.
  5. Confirm it appears under Active tunnels, then test it from the intended application.
  6. Choose Stop tunnel when finished and verify it is no longer active.

Remote forwarding requests a loopback listener on the SSH server, but the server's GatewayPorts policy can override the requested bind address. Verify that policy before exposing a sensitive service. Other processes on the listening device can still reach a loopback listener. Tunnels stop when their owning SSH connection closes.

A saved preset is configuration, not a running listener. Review Auto-start on connect before saving a preset so future connections do not unexpectedly start it.

Forwarding is not destination authentication

The service reached through a tunnel still needs its own appropriate authentication and encryption. Do not expose a database or administrative service more broadly than intended, and do not treat a loopback listener as permission for arbitrary remote destinations.

SSH agent forwarding is a separate advanced capability. It can let a remote environment request authentication operations using your agent. Enable it only for trusted hosts and a specific need, not as a general fix for connection errors.

See connection routes and privacy boundaries before using an unfamiliar Gateway.

Features vary by release, platform and connection route. Check availability before planning your setup.

Search the guides

Search runs in your browser.

Your search stays here. No account or external search service.