---
title: "Port forwarding"
description: "Local, remote, and dynamic forwards — preconfigured or added mid-session."
---
## Ports you did not ask to forward
When a pane is on a remote machine, tty7 watches what its processes are
listening on and forwards those ports for you. Start a dev server on the remote
`:3000` and a moment later a notice says it is at `http://localhost:3000` —
same number, no rule to write.
The **Ports** section of the Info panel is the whole list: one row per listener,
the process that owns it, and where it comes out on this machine. The globe
opens it in a browser, the copy tile takes the address that works from here,
and ✕ takes the forward back down.
Ports are forwarded once each. Remove one and it stays removed — the offer is
made a single time per port, not on every poll.
The local port matches the remote one whenever it is free here. When it is not —
something else on this machine already has `:3000` — the OS picks another and
the row says which.
Turn the whole thing off under **Settings → Terminal → Links → Forward remote
ports** (`ssh_loopback_forward: false`).
In a remote workspace the ports are found by the **`tty7-server` on that
machine** — the panes are its, and this machine's daemon has never heard of
them. A server too old to answer says so in the Ports section rather than
showing an empty list; updating it is what fixes that. Panes that ssh'd
somewhere from inside a local pane are a different case: those processes
belong to no tty7 server, so nothing lists them.
## The three kinds
| | What it does |
|---|---|
| **Local** (`L`) | A port on this machine reaches a service on the remote side |
| **Remote** (`R`) | A port on the remote machine reaches a service here |
| **Dynamic** (`D`) | A SOCKS proxy on this machine, routed through the connection |
## Adding one to a profile
**Settings → SSH →** a profile **→ Port forwarding → + Add rule**. Rules saved
here open with the connection, every time.
A Local or Remote rule needs a listen port and a target; a Dynamic rule needs
only the listen port. An incomplete rule tells you so rather than being saved
half-configured.
Each rule takes an optional description — *"what it's for"* — because six months
later `8080 → 3000` explains nothing.
## Adding one mid-session
The **+** on the Ports section — or *SSH: Port Forwarding* in Search
Everywhere — opens a form asking for one thing: the port the remote is serving on.
It comes out here under the same number, and the form says so before you commit
to it.
**Advanced** opens the rest of the grammar: remote and dynamic forwards, a bind
host other than loopback, a target on some third machine, a description. You
need it about as often as you need `ssh -R`.
These live only as long as the session unless you save them into the profile.
## Switching a rule off
Every forward in the Ports section has a switch. Off, the forward lets go of
its port but keeps its whole rule — kind, ports, target, description — so it
can be switched back on without retyping anything. That is how one local port
is pointed at different places: keep one rule per target on the same port, and
switch on the one you want.
Only one of them can hold the port at a time. Switching one on while another
still has its port is refused, and the notice names the forward to switch off
first.
Rules from a profile carry their switch into it, so the next connection opens
the same set. The same switch sits beside each rule under **Settings → SSH →**
a profile **→ Port forwarding**; a rule saved switched off is listed but not
opened. Rules added mid-session are still gone when the session ends, on or
off.
## Links in the terminal
⌘-clicking a `localhost:PORT` link inside a remote pane opens the
forward for that port if there is not one yet, then the browser. Same machinery
as the Ports list, reached from the output instead of the panel.
## Jump hosts and proxies
Multi-hop connections are configured per profile:
- **Jump host** — point at another saved profile, or use a `ProxyJump` chain
- **ProxyCommand** — an arbitrary transport command, with `%h`, `%p`, `%r`
substituted
- **SOCKS5 proxy** / **HTTP proxy** — `host:port`, under **Advanced → Proxies**
These proxy settings are for reaching the SSH server. tty7's *own* network
traffic — update checks, release downloads, remote-server installs — uses
`http_proxy` in `config.json`, the system proxy, or the `HTTP_PROXY` family.
Programs running in a pane are unaffected either way; they inherit their proxy
from their own environment, as in any terminal.