Port forwarding

Mobile SSH dey support local SSH port forwarding for both Android and iOS. One local port for di device go dey listen on 127.0.0.1 and go dey forward traffic through di SSH connection go reach remote host and port.

Android also get VPN page for SSH VPN, local SOCKS5 proxy, WireGuard, Shadowsocks and OpenVPN. These profiles separate from di local forwards wey dey below.

Syntax for saved tunnel

Port-forwarding rules dey comma-separated. Each entry dey use one of two forms:

PORT
LOCAL:REMOTEHOST:REMOTE

Short form:

8080

Dis one go bind 127.0.0.1:8080 on di device and forward am go localhost:8080 from di server side.

Full form:

3000:localhost:3000

Dis one go bind 127.0.0.1:3000 on di device and forward am through SSH go localhost:3000 on di remote side.

Multiple forwards:

8080, 3000:localhost:3000, 15432:db.internal:5432

Add tunnel to saved server

  1. Open Saved Servers.
  2. Add or edit one server profile.
  3. Enter di forwarding rules for di Port forwards field.
  4. Save di server.
  5. Connect to di server.

Di app go apply di saved forwards after di SSH session don connect.

Tunnels na di server profile own

Local forwards dey inside saved server profile and start when server connect. To change dem, edit profile and reconnect.

Tunnel wey you save go return every time you connect, including after reconnect for new network.

IPv6 destination

You must bracket IPv6 destination so di colons no go confuse wit di port separator:

8080:[2001:db8::1]:80

Bare IPv6 address wey no get bracket dem dey reject am as ambiguous instead of reading am wrong quietly. Di same bracket form dey work for server address field, wit optional port after am ([fe80::1]:22).

Address binding

Mobile SSH dey bind local forwards to 127.0.0.1 on di device. E be so on purpose: e dey keep di tunnel local to di device and e dey avoid IPv6-only loopback wahala. Oda apps on di same device fit connect to di forwarded local port if di operating system allow dia network access.

Common examples

To access web service wey dey run on di remote server:

8080

Then open http://127.0.0.1:8080 from any browser on di same device.

To access development server:

3000:localhost:3000

To access internal database wey you fit reach from di SSH server:

15432:db.internal:5432

Connect through jump hosts

For both platforms, saved SSH server fit connect through ordered saved bastions. Edit di destination, add dem under Connect through, then arrange dem. Each hop use im own credentials; expanded route fit get up to eight hops.

Phone reach first bastion; every next address must dey reachable from di previous server. Local forwards, terminal and SFTP use di same verified SSH route. Forward destination dey reached from di last SSH server. Each bastion must allow onward TCP forwarding, and every identity get checked before login. These routes need SSH, dem no work with Eternal Terminal.

VPN routing for Android

Open VPN from home, add or import profile with name, then tap Start. Approve Android VPN prompt. Icon become Stop routing while enabled; pencil edit, bin delete. VPN types wey you use plenty show first.

Android allow one device VPN at a time. Starting another profile replace di previous VPN. Local SSH SOCKS5 proxy fit continue through non-SSH VPN. Tailscale use separate app; Mobile SSH VPN replace im connection. Manage IKEv2/IPsec for Android VPN settings, no be inside Mobile SSH.

SSH VPN and SOCKS5 proxy

Use domains like example.org, wey cover di name and subdomains. Identified domains wey no dey list use normal network. Direct IPs or addresses from encrypted DNS no fit match reliably, so dem use SSH. SSH VPN apply app and website selections together; you choose SOCKS5 participants by configuring each client.

Remote DNS default na 1.1.1.1:53; use numeric resolver wey SSH server fit reach. While reconnect or authentication dey pending, SSH traffic stay blocked while known bypass destinations continue normally. Stop, profile switch, permission revocation or app termination end protection. These clients no promise Android always-on or lockdown protection.

WireGuard, Shadowsocks and OpenVPN

Di app carry these protocol engines. Shadowsocks and OpenVPN no get SSH VPN app-and-website selectors. VPN no fit give server internet access wey provider or administrator don restrict.

Quick Settings tile

Start VPN profile once to select am for Mobile SSH VPN tile. Tile highlight while Mobile SSH VPN enabled, including while e dey connect or reconnect. Tap to stop, tap again to start remembered profile. E no start SOCKS5 or stop another app VPN.

For Android 13 and newer, first time you open VPN e request permission to add tile. If you decline, or Android older, add am through Quick Settings → Edit. Deleted profile or missing permission open VPN page for setup.

Troubleshooting tunnels