Skip to main content

SSH Tunnels

Local forwarding (-L), remote forwarding (-R), and SOCKS5 proxy (-D) for IPv4 addresses and domain names. Up to 10 local + 5 remote tunnels per profile (Free includes 1 local tunnel; Pro unlocks remote & SOCKS5).

SSH tunnels let you reach an internal service (a database, a Redis instance, an admin panel) without exposing it to the internet. In SSHive they are part of the profile: open its Advanced options, add a Local (-L) or Remote (-R) tunnel or set a SOCKS5 port (-D), and the tunnels open with the SSH connection, close with it, and come back after an automatic reconnection. Local forwarding brings a remote port to your Mac, remote forwarding publishes a port of your Mac on the server, and the SOCKS5 proxy sends any app that speaks SOCKS through the server; when the app passes a host name, the server resolves it. The free version includes 1 local tunnel. Pro adds remote tunnels and the SOCKS5 proxy, and allows up to 10 local tunnels, 5 remote tunnels and a single SOCKS5 port per profile on the Mac. On iPhone and iPad, local and remote tunnels work too (remote ones with Pro, with no per-profile cap), but there is no SOCKS5 proxy. The SSH tunnel guide sets up a first forward, the SOCKS5 guide covers the browser side, and a tunnel is also the safe way to reach RDP or VNC behind a firewall.

Where it runs and what it costs

Runs on
Mac, iPhone and iPad (SOCKS5 proxy on the Mac only)
Free
1 local tunnel (-L).
Pro
$12.99 once, for Mac, iPhone and iPad. Remote tunnels (-R) and the SOCKS5 proxy (-D), with up to 10 local and 5 remote tunnels per profile on the Mac.
Compare Free and Pro

Key capabilities

Local forwarding (-L): reach a remote service as if it ran on your Mac

Remote forwarding (-R, Pro): publish a port of your Mac on the server

SOCKS5 proxy (-D, Pro, Mac only) for IPv4 addresses and host names, which the server resolves

Tunnels open and close with the SSH connection, and come back after an automatic reconnection

Real-world tunnel scenarios

Reach a private database

Add a local tunnel to your bastion's profile, 5432 → mydb.internal:5432, then connect TablePlus, DBeaver or psql to localhost:5432. The database never listens on a public address, and your SSH login is what lets you in.

Show a local dev server

A remote tunnel (Pro) publishes your Vite dev server, port 5173, on port 8080 of the server. OpenSSH binds it to the server's loopback unless GatewayPorts is set to yes or clientspecified in sshd_config, so either enable that or let the server's reverse proxy forward to it.

Browse through your own server

On hotel Wi-Fi, give your home server's profile a SOCKS5 port (Pro, on the Mac), say 1080, and point Firefox at localhost:1080 with its option to proxy DNS through SOCKS v5. Pages and DNS lookups leave from your home connection, encrypted up to there.

SSH tunnels, frequently asked questions

Why not just use a VPN?+
A VPN routes everything, usually needs something installed at both ends, and is a lot of machinery to reach one database. An SSH tunnel is narrow: only the ports you name are forwarded, over an SSH login the server already accepts, and the server logs it like any other session.
Are tunnels included in the free version?+
The free version includes 1 local tunnel (-L). Remote tunnels (-R) and the SOCKS5 proxy (-D) need Pro, a single purchase of $12.99 for the Mac, iPhone and iPad. With Pro, a profile on the Mac can hold up to 10 local and 5 remote tunnels plus one SOCKS5 port.
Do tunnels work on iPhone and iPad?+
Local and remote tunnels do: a local tunnel is free, remote tunnels need Pro, and Pro sets no per-profile cap there. The SOCKS5 proxy is not available on iPhone and iPad; it is a Mac feature.
What happens to tunnels when the connection drops?+
They go down with it and come back with it. SSHive retries the SSH connection 5 times, 1, 2, 4, 8, and 16 seconds apart, and reopens the profile's tunnels as soon as it is back; a client such as psql only needs to reconnect to localhost.

Related SSHive features

SSH Terminal

GPU-accelerated terminal

Remote Desktop (RDP)

Embedded remote desktop

VNC Viewer

Built-in VNC viewer

Try SSH Tunnels in SSHive