SSH Tunneling and Port Forwarding: Accessing Remote Services Safely
SSH tunnels let you access remote databases and internal services without exposing them to the internet. Here is every forwarding mode I use. SSH tunneling is the technique I use to access remote services that are not exposed to the public internet. A database running on a server that only listens on localhost, an internal admin panel behind a firewall, a service on a machine with no public IP. all of these become accessible through an SSH tunnel without opening additional ports or setting up a VPN. After using SSH tunnels daily for years, I have a clear understanding of the three forwarding modes and when each one applies. Local Port Forwarding Local forwarding is the mode I use most often. It forwards a port on my local machine to a port on the remote server, or to a port reachable from the remote server. The connection goes from my machine through the SSH server to the destination. I use this to access a remote database that only listens on localhost. # Forward local port 5432 to remote localhost:5432 ssh -L 5432:localhost:5432 user@remote-server # Now connect to localhost:5432 locally, # and it tunnels…