Port forwarding
Create local, remote and SOCKS5 tunnels as cards, or describe one in a sentence and let Gatesys SSH pick the port and test it.
Port forwarding lets you reach a service on or behind a server as if it ran on your computer, or the other way round. Each tunnel is a card you can switch on and off, and it rides the host’s existing session, jump chain included.
Tunnel types
| Type | Listens on | Traffic goes to | Typical use |
|---|---|---|---|
Local -L | This computer | A host and port, dialled out by the server | Reach a database or web UI on the server’s network |
Remote -R | The server | A host and port, dialled out by this computer | Let the server reach a service on your side |
SOCKS5 -D | This computer | Wherever each connection asks, dialled out by the server | Point a browser or CLI at it to route everything through the server |
A remote tunnel that binds a non-loopback address needs GatewayPorts yes in the server’s SSH config.
Describe a tunnel
The bar at the top of Port forwarding turns a sentence or a pasted command into a ready-to-start tunnel:
reach postgres on db-primary
10.0.3.40:6379 through edge-bastion
socks through edge-bastion
ssh -L 15432:localhost:5432 db-primary
db-primary'daki postgres'e bağlan- Type or paste into the Describe a tunnel bar and press Enter.
- Check the draft card. Every value says where it came from: you said, saved host, catalog, measured, picked by Gatesys or model: check it. Roughly the same as shows the equivalent
sshcommand to copy. - Click Create & start.
Gatesys SSH then connects to the host if needed, starts the forward, and makes one test connection through it. The card says Running only when that test gets through. Otherwise it says why, for example db-primary refused 127.0.0.1:5432 — nothing listening?, and offers Stop or Keep it.
How the local port is picked
| Service | Local port |
|---|---|
| Data services: PostgreSQL, MySQL, Redis, MongoDB, SQL Server, ClickHouse, Elasticsearch, etcd, Cassandra, Memcached | The service’s port plus 10000, for example 15432 or 16379, so a production database never answers on your local database’s port |
| Web ports under 1024 | Moved up by 8000, for example 8080 for port 80 |
| SOCKS proxy | Starts at 1080 |
A port already in use is swapped for a free one, and the card says so. The port a tunnel had last time is remembered per host and service, so saved database connections keep working.
Safe defaults
- Tunnels listen on 127.0.0.1 only. Nothing else on your network can use them.
- Hosts match exactly. A name that is close but not exact shows Did you mean db-primary? with Use db-primary, and nothing starts until you choose.
- On production hosts, the way to connect is read-only first. The card’s client command opens a read-only session where the service has one (for example
psqlwithdefault_transaction_read_only=on, ormysqlwithSET SESSION TRANSACTION READ ONLY), with a Writable switch. Redis and MongoDB have no read-only session, and the card says so. - Measured destinations. When the host’s facts are known, the destination port comes from what the host was measured listening on (measured · 2h). A port it was not listening on is flagged.
- Remote tunnels come only from a pasted
ssh -R. A sentence never creates one. The server is always asked to listen on 127.0.0.1, and a remote tunnel may not point at services this computer keeps to itself: its SSH, file sharing, Remote Desktop, screen sharing, the Docker API, Chrome DevTools, Ollama or LM Studio, however the address is written.
Rules on your computer read the sentence. A model helps only with sentences the rules cannot fully read, with Pro and the assistant on, and then only sees placeholders for every value. The full story is in Say it, Gatesys sets it up.
Create a tunnel by hand
- Connect to the host. Tunnels belong to a live session.
- In Port forwarding, click New rule.
- Choose the Session and the Type: Local -L, Remote -R or SOCKS5 -D.
- Set the bind address and Listen port, and for local and remote tunnels the Destination host and Destination port.
- Click Start tunnel.
Manage tunnels
Each card shows where it listens (Listening locally or Listening on the server), the destination (or socks5 dynamic) and the host it runs through.
- The switch stops and starts the tunnel.
- The copy button copies how to connect to it.
- Connected for this tunnel means the host was connected quietly just to carry it: no metrics polling and no host-facts read until you open a terminal on it.
Every start and stop, whether by hand or because the connection closed, is written to the audit log with its host.
Tunnels and closing tabs
Closing a terminal tab whose connection carries tunnels asks first, and can keep the connection open for the tunnels. The question takes the keyboard from the terminal, so no keystroke reaches the shell behind it; Esc cancels. If the last shell exits on its own, you are asked the same, without a Cancel button.
Tunnels in Farabi’s answers
When Farabi suggests an ssh -L, -R or -D command, a note written by code reminds you that typed into the terminal it would open the tunnel on the server, not on this computer. Use Describe a tunnel to open it here.
Something unclear or wrong? Tell us.