Port forwarding
Port forwarding carries other connections through your SSH connection: a database on the server you want to reach from this Mac, a web server on this Mac you want the server to reach, or everything a browser does, made from the server.
Press ⌥⌘P while connected, or the tunnel button in the toolbar. The sheet lists the forwards running on this connection and adds new ones.
The three kinds
| Kind | Listens | Goes to | Like |
|---|---|---|---|
| Local | a port on this Mac | a host and port, as the server sees them | ssh -L |
| Remote | a port on the server | a host and port, as this Mac sees them | ssh -R |
| SOCKS | a port on this Mac | wherever each program using it asks | ssh -D |
Examples:
- The server's database on this Mac: Local, port 5432, forward to
localhost5432. Then connect your database tool to127.0.0.1:5432. - A database the server can reach but you cannot: Local, port 5432,
forward to
db.internal5432. - Show the server a site running on this Mac: Remote, server port 8080,
forward to
localhost3000. On the server,curl localhost:8080reaches it. - Browse as if from the server: SOCKS, port 1080. Set the browser's SOCKS5
proxy to
127.0.0.1:1080, orcurl --socks5-hostname 127.0.0.1:1080 ….
A local or SOCKS forward listens on 127.0.0.1, so only this Mac can use it. A
remote forward listens on the server's localhost unless its sshd allows more
(GatewayPorts). Port 0 takes any free port, and the list shows which.
Keeping forwards with a server
Tick Start it on every connection when adding a forward to a saved server, and it starts each time you connect; the list marks it saved. The trash button stops a forward and, if it was saved, forgets it.
Forwards from ~/.ssh/config (LocalForward, RemoteForward,
DynamicForward) for the host also start when you connect, and so do -L,
-R and -D from the command line.
What the list shows
Each forward shows what it listens on and where it goes, how many connections are open through it and how many there have been, and the bytes sent from this Mac (↑) and received (↓). Stop stops it; Start starts it again.
Forwards stop when you disconnect, and start again by themselves when etrans gets a dropped connection back.
When it does not work
- Could not listen on 127.0.0.1:5432: something on this Mac uses the port already. Pick another.
- The server would not listen on localhost:8080. It may be in use, or remote forwarding may be off (AllowTcpForwarding).
- A local forward whose target cannot be reached closes each connection made to it; check the host and port as the server sees them.