An SSH tunnel sends other connections through an SSH session to a server you can log into, so that server becomes the exit for your traffic. It needs no extra software on a typical Linux server, because OpenSSH already does it. Two built-in forms:

  • ssh -D 1080 user@server opens a local SOCKS5 proxy on port 1080; point an app at it and the app's traffic leaves from the server.
  • ssh -L 9000:target:8080 user@server forwards one local port to one host and port reachable from the server.

Both work with an ordinary SSH login and no admin rights on the server.

sshuttle

sshuttle turns SSH into a transparent tunnel for whole subnets, so programs need no proxy setting. It needs no admin on the remote, only a Python interpreter, and runs as your SSH user there. It forwards TCP, and DNS if you add --dns; on its default nat and nft methods it does not carry UDP. In testing, TCP to a tunnelled subnet worked, a DNS query over --dns worked, and a plain UDP query did not. It needs root on your own machine to install the firewall rules.

Chisel

Chisel is a single binary that tunnels TCP and UDP over HTTP, useful where only web ports are open. The same binary runs as chisel server on one side and chisel client on the other, authenticates with a shared credential, and exposes SOCKS or specific port forwards. It upgrades an HTTP connection to a WebSocket and runs an encrypted session inside it, and its UDP forwarding works where sshuttle's does not.

Where it fits

An SSH tunnel, like Shadowsocks, gives you one exit, the server you log into, not a pool. It is for reaching your own infrastructure or using a server you control as a single egress, covered next to the provider protocols in Shadowsocks vs SOCKS5 vs HTTP proxy. For forcing a stubborn app down a proxy on Linux, ProxyChains pairs with the local SOCKS port an SSH tunnel exposes.

Common confusion

An SSH tunnel encrypts the hop to your server, not the hop from the server to the target. The target still sees the server's IP and its reputation, the same as any single forward proxy.