Cover
Foto profil

Bembi Pramudya

@beemind

Hi! I am Bembi Pramudya, a developer from Indonesia. I spend my free time building software, tinkering with web tools, and exploring frontend design.

DeveloperIndonesiabembee.cc
Tutorial

An Always-On SSH Reverse Tunnel with systemd

Bembi Pramudya
Bembi PramudyaSep 15, 2026 · 5 min read
An Always-On SSH Reverse Tunnel with systemd

Sometimes we need a service on a laptop or local VPS to be reachable from the internet — demos for friends, webhooks, or a personal dashboard. With no public IP, an SSH reverse tunnel is the answer.

The basic command is one line: ssh -R 80:localhost:3000 user@server. The server forwards its port 80 to port 3000 on your local machine. The problem: SSH connections can drop at any time.

The tidiest solution on Linux is systemd. Create a service unit with Restart=always and a growing RestartSec (backoff), so the tunnel retries automatically on every failure.

[Unit]
Description=Reverse tunnel to server
After=network-online.target
[Service]
ExecStart=/usr/bin/ssh -N -R 80:127.0.0.1:3000 user@server
Restart=always
RestartSec=10
[Install]
WantedBy=multi-user.target

Enable it with systemctl enable --now tunnel.service, and the tunnel lives across reboots and revives itself on drops. Add a small script to log the public URL to a file, so you always know its latest address.

I use this pattern to expose a local dashboard — simple, no extra software, and proven stable for days.