termal.in

Tunnels · port forwarding

An SSH tunnel manager — no more -L from memory.

Save port forwards to the host they run through and flip each one on with a switch. Say what you want in plain words — reach a remote service locally, expose a local one, or proxy through the box — and Termalin sets the SSH direction. Local, remote and SOCKS forwards, an auto-start option, and the live local address ready to copy.

Free tier · 14-day Pro trial · Windows, macOS & Linux

01  /  three directions, plain words

Local, remote and SOCKS — without the flags.

Most tunnels break because the direction got flipped. Termalin's builder asks what you're trying to do and picks -L, -R or -D for you, then shows only the fields that intent needs.

  • ▸Local (-L) — reach a remote database or admin panel on your own localhost.
  • ▸Remote (-R) — expose a service on your laptop through the server's port.
  • ▸SOCKS (-D) — a local proxy that sends a browser or tool out through the host.
tunnels · db-primary
● 127.0.0.1:5432 → localhost:5432  local ● 127.0.0.1:1080  · SOCKS ○ server:8080 → localhost:3000  remote   # ● on · ○ off  ·  copy the local address, one click

02  /  saved and restartable

Set it once, start it with a switch.

Each forward is saved to its host and sits in a list with a live indicator. Toggle one on and it binds to loopback and shows its local address ready to copy; toggle it off and the port is freed. Tick auto-start and it comes up automatically whenever you connect that host — so the tunnel your database tab needs is just there. Edits are only allowed while a tunnel is stopped, so a running forward never changes underneath you.

03  /  reach what's private

Tunnel to the thing that isn't on the internet.

A local forward is the classic way to reach a database that only listens on localhost — Termalin's own database client uses exactly this to connect Postgres, MySQL, Redis and more through an SSH host. Need a hop first? ProxyJump through one bastion is supported. And when you'd rather not open an inbound SSH port at all, a keyless Connector reaches into a private network with an outbound-only link. The deeper how-to lives in our guides to SSH port forwarding and reverse tunnels.

04  /  agents can drive it

Let an agent open the forward it needs.

Tunnels aren't only for you. Termalin's built-in MCP server gives an AI agent tunnel_open, tunnel_close and tunnel_list, so Claude Code or another client can stand up the forward it needs to reach a service, do the work, and close it — all under the same per-host policy, consent and audit log that govern every other thing the agent touches. How agent access works →

Questions

Is there a GUI for SSH port forwarding?

Yes — Termalin gives SSH tunnels a real interface. You describe the forward in plain words — "reach this service through this server" — and it sets the SSH direction for you, instead of making you remember -L, -R and -D. Each tunnel is saved to its host and flipped on or off with a switch.

What kinds of tunnel can it open?

Local (-L) forwards, to reach a remote service on your own localhost; remote (-R) forwards, to expose a local service on the server; and a SOCKS (-D) proxy, to send a browser or tool out through the host. Each has a small purpose-built form — you fill only the fields that direction needs.

Does it remember my tunnels?

Yes — forwards are saved per host and listed with a live status. Turn one on and its local address is shown and copyable; mark it auto-start and it comes up whenever you connect that host. Nothing runs until you say so, and turning a tunnel off frees its port.

Can I run a SOCKS proxy over SSH?

Yes — add a SOCKS tunnel, pick a local port (1080 by default), and point a browser or tool at 127.0.0.1 on that port to route traffic through the SSH host. It binds to loopback, so the proxy is reachable only from your machine.

Can an AI agent open a tunnel for me?

Yes — Termalin's MCP server exposes tunnel_open, tunnel_close and tunnel_list, so an agent like Claude Code can stand up a forward to reach a database or service and tear it down afterwards, under the same per-host policy and audit log as everything else it does.

Your port forwards, saved and one switch away.

Local, remote and SOCKS tunnels described in plain words, saved to their host, and started when you connect — inside a full SSH client. Free, with no host limits; new accounts get Pro free for 14 days.

Free tier · 14-day Pro trial · the Connector · database client