Work

Port forwarding

Create local, remote and SOCKS5 tunnels as cards, or describe one in a sentence and let Gatesys SSH pick the port and test it.

Port forwarding lets you reach a service on or behind a server as if it ran on your computer, or the other way round. Each tunnel is a card you can switch on and off, and it rides the host’s existing session, jump chain included.

Tunnel types

TypeListens onTraffic goes toTypical use
Local -LThis computerA host and port, dialled out by the serverReach a database or web UI on the server’s network
Remote -RThe serverA host and port, dialled out by this computerLet the server reach a service on your side
SOCKS5 -DThis computerWherever each connection asks, dialled out by the serverPoint a browser or CLI at it to route everything through the server

A remote tunnel that binds a non-loopback address needs GatewayPorts yes in the server’s SSH config.

Describe a tunnel

The bar at the top of Port forwarding turns a sentence or a pasted command into a ready-to-start tunnel:

reach postgres on db-primary
10.0.3.40:6379 through edge-bastion
socks through edge-bastion
ssh -L 15432:localhost:5432 db-primary
db-primary'daki postgres'e bağlan
  1. Type or paste into the Describe a tunnel bar and press Enter.
  2. Check the draft card. Every value says where it came from: you said, saved host, catalog, measured, picked by Gatesys or model: check it. Roughly the same as shows the equivalent ssh command to copy.
  3. Click Create & start.

Gatesys SSH then connects to the host if needed, starts the forward, and makes one test connection through it. The card says Running only when that test gets through. Otherwise it says why, for example db-primary refused 127.0.0.1:5432 — nothing listening?, and offers Stop or Keep it.

How the local port is picked

ServiceLocal port
Data services: PostgreSQL, MySQL, Redis, MongoDB, SQL Server, ClickHouse, Elasticsearch, etcd, Cassandra, MemcachedThe service’s port plus 10000, for example 15432 or 16379, so a production database never answers on your local database’s port
Web ports under 1024Moved up by 8000, for example 8080 for port 80
SOCKS proxyStarts at 1080

A port already in use is swapped for a free one, and the card says so. The port a tunnel had last time is remembered per host and service, so saved database connections keep working.

Safe defaults

  • Tunnels listen on 127.0.0.1 only. Nothing else on your network can use them.
  • Hosts match exactly. A name that is close but not exact shows Did you mean db-primary? with Use db-primary, and nothing starts until you choose.
  • On production hosts, the way to connect is read-only first. The card’s client command opens a read-only session where the service has one (for example psql with default_transaction_read_only=on, or mysql with SET SESSION TRANSACTION READ ONLY), with a Writable switch. Redis and MongoDB have no read-only session, and the card says so.
  • Measured destinations. When the host’s facts are known, the destination port comes from what the host was measured listening on (measured · 2h). A port it was not listening on is flagged.
  • Remote tunnels come only from a pasted ssh -R. A sentence never creates one. The server is always asked to listen on 127.0.0.1, and a remote tunnel may not point at services this computer keeps to itself: its SSH, file sharing, Remote Desktop, screen sharing, the Docker API, Chrome DevTools, Ollama or LM Studio, however the address is written.

Rules on your computer read the sentence. A model helps only with sentences the rules cannot fully read, with Pro and the assistant on, and then only sees placeholders for every value. The full story is in Say it, Gatesys sets it up.

Create a tunnel by hand

  1. Connect to the host. Tunnels belong to a live session.
  2. In Port forwarding, click New rule.
  3. Choose the Session and the Type: Local -L, Remote -R or SOCKS5 -D.
  4. Set the bind address and Listen port, and for local and remote tunnels the Destination host and Destination port.
  5. Click Start tunnel.

Manage tunnels

Each card shows where it listens (Listening locally or Listening on the server), the destination (or socks5 dynamic) and the host it runs through.

  • The switch stops and starts the tunnel.
  • The copy button copies how to connect to it.
  • Connected for this tunnel means the host was connected quietly just to carry it: no metrics polling and no host-facts read until you open a terminal on it.

Every start and stop, whether by hand or because the connection closed, is written to the audit log with its host.

Tunnels and closing tabs

Closing a terminal tab whose connection carries tunnels asks first, and can keep the connection open for the tunnels. The question takes the keyboard from the terminal, so no keystroke reaches the shell behind it; Esc cancels. If the last shell exits on its own, you are asked the same, without a Cancel button.

Tunnels in Farabi’s answers

When Farabi suggests an ssh -L, -R or -D command, a note written by code reminds you that typed into the terminal it would open the tunnel on the server, not on this computer. Use Describe a tunnel to open it here.

Something unclear or wrong? Tell us.