Master SSH Tunnels: Local and Remote Port Forwarding
SSH tunnels are extremely handy when you need to reach services across network boundaries without changing firewall rules, opening public ports, or installing extra proxy software.
With nothing but the standard ssh client, you can reach a port bound to localhost on a remote machine,
jump through a bastion into a private VPC, expose a service running on your laptop to the outside world,
or turn one SSH connection into a proxy for an entire network.
However, there are different types and flavors of SSH tunnels,
and picking the right one for the job and constructing the required ssh command can be challenging.
Local (ssh -L) and remote (ssh -R) tunnels look deceptively similar,
but they open listening ports on opposite sides of the SSH connection.
Static and dynamic tunnels come with different sets of tradeoffs.
Bastions and jump hosts add another layer of indirection.
The good news is that once you understand where the listening socket is created, where the target service lives, and which side initiates the connection, the flags stop being magic. This skill path is designed to build that understanding through practice.

The skill path opens with a comprehensive tutorial and then moves through a number of hands-on challenges, each running in a real multi-host network topology:
- Reach an internal debug port on a remote VM with local port forwarding.
- Query a private VPC service through an SSH bastion host.
- Harden that bastion into per-role access tiers with
sshdforwarding controls. - Reach a loopback-bound port on a private server by combining a jump host with local port forwarding.
- Expose a local service to the Internet through a reverse tunnel.
- Publish a home network device on a public gateway with your workstation as a jump host.
- Reach a whole VPC through a single SSH SOCKS proxy (dynamic local forwarding).
- Expose a whole home network through a reverse SOCKS proxy (dynamic remote forwarding).
By the end of this skill path, you'll be able to look at a network topology, decide whether you need a local or remote tunnel, choose between static and dynamic forwarding, and build the SSH command that reaches or exposes the service on the correct side of the firewall.
Prerequisites
- Linux command-line knowledge
- Basic familiarity with
ssh(connecting to a host, key-based authentication) - A rough idea of TCP ports and the
localhostvs. external-interface distinction
Premium Materials
Official Content Pack required
This platform is funded entirely by the community. Please consider supporting iximiuz Labs by upgrading your membership to unlock access to this and all other learning materials in the Official Collection.
Support Development