SSH Tunneling: Securely Accessing Remote Services
SSH tunneling, also known as SSH port forwarding, is a mechanism in SSH that creates an encrypted tunnel between a local port and a remote port. This allows you to securely access network services that might otherwise be blocked by firewalls or inaccessible due to network topology. There are three main types: local, remote, and dynamic port forwarding. This document focuses on local and remote port forwarding.
1. Local Port Forwarding (-L)
Local port forwarding allows you to access a service on a remote machine (or a machine accessible from the remote machine) as if it were running on your local machine. Traffic from your local machine is forwarded through the SSH tunnel to the remote server and then on to the specified destination.
Example: Accessing a Web Interface
ssh -L 8080:localhost:8080 <user>@<remote-server-ip-or-hostname>Explanation:
This command maps port 8080 on your local machine to port 8080 on the remote-server’s localhost interface (accessed through the SSH tunnel).
-L <local_port>:<remote_host>:<remote_port>: The core of local forwarding.8080: This is the port on your local machine that you will open in your browser or connect to with a client.localhost:8080: This specifies that traffic reaching your local port8080should be forwarded tolocalhost:8080on the remote-server. Theremote_hostislocalhostfrom the perspective of the<remote-server-ip-or-hostname>.<user>@<remote-server-ip-or-hostname>: Your login credentials and the address of the SSH server.
Result: When you open http://localhost:8080 in your browser on your local machine, your request is effectively tunneled securely to localhost:8080 on the remote-server. This is commonly used to access remote web interfaces (like Argo CD, database GUIs, internal dashboards) securely without exposing them directly to the public internet.
2. Remote Port Forwarding (-R)
Remote port forwarding allows a remote host to connect to a service on your local machine. Traffic from a port on the remote machine is forwarded through the SSH tunnel to your local machine and then on to the specified destination.
Example: Exposing a Local Web Server to a Remote Developer
Suppose you have a web server running locally on port 3000, and you want a remote developer to access it via their machine’s port 8080.
ssh -R 8080:localhost:3000 <user>@<remote-server-ip-or-hostname>Explanation:
-R <remote_port>:<local_host>:<local_port>:8080: This is the port on the remote server that will be opened.localhost:3000: This specifies that traffic reaching the remote server’s port8080should be forwarded tolocalhost:3000on your local machine.
Result: A user on the remote server can now access your local web server by navigating to http://localhost:8080 on the remote machine. This is useful for exposing local development servers to others or to services running on the remote server.
Note: For both local and remote forwarding, the SSH connection must remain active for the tunnel to function. If the SSH session terminates, the tunnel will close.