SSH tunnels let you reach an internal service (a database, a Redis instance, an admin panel) without exposing it to the internet. In SSHive they are part of the profile: open its Advanced options, add a Local (
-L) or Remote (
-R) tunnel or set a SOCKS5 port (
-D), and the tunnels open with the SSH connection, close with it, and come back after an automatic reconnection.
Local forwarding brings a remote port to your Mac, remote forwarding publishes a port of your Mac on the server, and the SOCKS5 proxy sends any app that speaks SOCKS through the server; when the app passes a host name, the server resolves it. The free version includes 1 local tunnel. Pro adds remote tunnels and the SOCKS5 proxy, and allows up to 10 local tunnels, 5 remote tunnels and a single SOCKS5 port per profile on the Mac. On iPhone and iPad, local and remote tunnels work too (remote ones with Pro, with no per-profile cap), but there is no SOCKS5 proxy.
The
SSH tunnel guide sets up a first forward, the
SOCKS5 guide covers the browser side, and a tunnel is also the safe way to reach
RDP or
VNC behind a firewall.