Approved TCP access

TCP tunnels expose services that do not speak HTTP, such as SSH, databases or game servers. TCP access must be approved for your account before you can create a TCP tunnel.

Request access

Email support@portlark.com from your account address and describe your use case. Approval is independent of your plan: a paid plan does not include TCP automatically, and approval does not add tunnel slots. A TCP tunnel uses one slot of your tunnel allowance, like an HTTP tunnel.

Create and connect

  1. In the dashboard, choose New tunnel, select TCP and enter the local host:port, for example 127.0.0.1:22.
  2. Connect with portlark connect or your Agent.
  3. Use the public host and port shown in the dashboard or printed by the CLI:
[TCP] home-ssh
  Local service: 127.0.0.1:22
  Public URL: tcp://<public-host>:<public-port>
  Public host: <public-host>
  Public port: <public-port>

For example, SSH to that address with:

ssh -p <public-port> user@<public-host>

Security

  • Raw TCP is forwarded as-is. It does not add TLS to your protocol, so use protocols with their own encryption and authentication (SSH, TLS-enabled database connections).
  • Do not expose unauthenticated databases, remote desktops or administration interfaces.
  • Anyone on the internet can try to connect to the public port. Use strong credentials or keys and keep the service updated.

Last updated

Report an issue with this page