↑ ↓ select, Enter open, Esc close

Expose a local service on a server with a reverse SSH tunnel

Adjust the values, the command updates live
user@server
ssh -N -R 8080:127.0.0.1:3000 webuser@server.example.com

Opens port 8080 on the server and forwards all connections to it through the tunnel to port 3000 on your own machine. Useful for briefly making a local development environment or a machine behind NAT reachable from the server. By default the port on the server only listens on 127.0.0.1.

Note: For the port to be reachable from outside, GatewayPorts must be enabled in sshd_config. That is rarely needed and should be considered carefully.

Also searched as

  • ssh reverse tunnel example
  • ssh remote port forwarding
  • expose localhost behind nat via ssh

Related one-liners

All in SSH

Read first, then run.

The commands on myline.de act directly on servers, files and databases. A wrong path or placeholder can delete data irreversibly or make a server unreachable.

  • All commands are provided without warranty and are not tested on every system.
  • Understand what a command does before running it, and check every placeholder.
  • Make a backup first and, if possible, try it on a test system.
  • You run commands at your own risk. Liability for damages is excluded to the extent permitted by law.