Tunnels and port forwarding

Save local, reverse and dynamic SOCKS5 tunnels as rules and start them with one click or automatically.

What tunnels are for#

A tunnel carries network traffic through an SSH connection. You can reach a database that only listens on the server, open a service on your computer to the server, or route an application through the server with a SOCKS5 proxy. Ravelon saves tunnels as rules in your vault, so you set them up once.

Create a tunnel#

Open Tunnels in the sidebar and click New tunnel. Enter a name, choose the host under Through host and pick the Type:

TypeWhat it does
Local (-L)Listens on your computer and reaches a service on the remote side, for example a database on the server.
Reverse (-R)Listens on the server and reaches a service on your computer.
Dynamic (-D)Runs a SOCKS5 proxy on your computer. Names are resolved on the server side.

Then enter the ports and the destination. The Bind address decides where the tunnel listens. 127.0.0.1 keeps it off the network, so only programs on your own computer can use it.

Start and stop#

Click Start next to a rule. If the host is not connected yet, Ravelon connects first. Stop ends the tunnel. A tunnel uses the same connection as your terminals and the file browser to that host, so it needs no extra sign-in.

With Start automatically once the host connects, the tunnel starts as soon as you open a session to that host. If the port is busy, Ravelon reports it once instead of retrying in a loop.

Note: Locking the vault closes all SSH sessions, and with them their tunnels.

Example#

To reach PostgreSQL on a server that only listens locally, create a Local tunnel through that server with local port 5432, remote host 127.0.0.1 and remote port 5432. After starting it, connect your database tool to 127.0.0.1:5432 on your computer.

Last updated 30 September 2026