---
title: How to SSH Reverse Tunnel to a Remote DB Server in an AWS Private Subnet using an EC2 Bastion Jump Host
description: Do you have publicly inaccessible database that you need to SSH into? Using SSH Reverse Tunneling, you can securely connect to the database.
image: https://blog.ippon.tech/hubfs/Imported_Blog_Media/SSH-Reverse-Title-3.png
---

[Skip to main content](https://blog.ippon.tech/ssh-reverse-tunnel-to-private-database#main)

[![IpponLogoKleinBlue](https://blog.ippon.tech/hs-fs/hubfs/IpponLogoKleinBlue.png?width=219&height=64&name=IpponLogoKleinBlue.png) ![IpponLogoKleinBlue](https://blog.ippon.tech/hs-fs/hubfs/IpponLogoKleinBlue.png?width=219&height=64&name=IpponLogoKleinBlue.png) ![IpponLogoKleinBlue](https://blog.ippon.tech/hs-fs/hubfs/IpponLogoKleinBlue.png?width=168&height=49&name=IpponLogoKleinBlue.png) ![IpponLogoKleinBlue](https://blog.ippon.tech/hs-fs/hubfs/IpponLogoKleinBlue.png?width=168&height=49&name=IpponLogoKleinBlue.png)](https://ipponusa.com/)

- [Home](https://ipponusa.com)
- [Show submenu for About About](https://ipponusa.com/about-us) 
    - [Who We Are](https://ipponusa.com/who-we-are)
    - [Careers](https://ipponusa.com/careers)
    - [Show submenu for Our Partners Our Partners](https://ipponusa.com/our-partners/) 
          - [AWS](https://ipponusa.com/our-partners/aws/)
          - [Snowflake](https://ipponusa.com/our-partners/snowflake/)
          - [Databricks](https://ipponusa.com/our-partners/databricks/)
          - [Microsoft](https://ipponusa.com/our-partners/microsoft/)
- [Show submenu for Services Services](https://ipponusa.com/services) 
    - [Snowflake](https://ipponusa.com/service/snowflake-concierge/)
    - [Artificial Intelligence](https://ipponusa.com/service/artificial-intelligence/)
    - [Data & Analytics](https://ipponusa.com/service/data-analytics/)
    - [Cloud Strategy](https://ipponusa.com/service/cloud-strategy/)
    - [Platform Modernization](https://ipponusa.com/service/platform-moderization/)
    - [Product Innovation](https://ipponusa.com/service/product-innovation/)
    - [Operating Model](https://ipponusa.com/service/operating-model/)
- [Blogs](https://blog.ippon.tech/)
- [Success Stories](https://ipponusa.com/success-stories/)
- [Show submenu for Resources Resources](https://ipponusa.com/resources/) 
    - [eBooks](https://ipponusa.com/ebooks/)
    - [The Data Pour](https://info.ippon.tech/the-data-pour)
    - [Videos & Webinars](https://info.ippon.tech/videos-and-webinars)
    - [Media Center](https://ipponusa.com/media-center/)

Search

Open main navigation

Close main navigation

- [Home](https://ipponusa.com)
- Show submenu for About About 
  
    - About
    - [About](https://ipponusa.com/about-us)
    - [Who We Are](https://ipponusa.com/who-we-are)
    - [Careers](https://ipponusa.com/careers)
    - Show submenu for Our Partners Our Partners 
      
          - Our Partners
          - [Our Partners](https://ipponusa.com/our-partners/)
          - [AWS](https://ipponusa.com/our-partners/aws/)
          - [Snowflake](https://ipponusa.com/our-partners/snowflake/)
          - [Databricks](https://ipponusa.com/our-partners/databricks/)
          - [Microsoft](https://ipponusa.com/our-partners/microsoft/)
- Show submenu for Services Services 
  
    - Services
    - [Services](https://ipponusa.com/services)
    - [Snowflake](https://ipponusa.com/service/snowflake-concierge/)
    - [Artificial Intelligence](https://ipponusa.com/service/artificial-intelligence/)
    - [Data & Analytics](https://ipponusa.com/service/data-analytics/)
    - [Cloud Strategy](https://ipponusa.com/service/cloud-strategy/)
    - [Platform Modernization](https://ipponusa.com/service/platform-moderization/)
    - [Product Innovation](https://ipponusa.com/service/product-innovation/)
    - [Operating Model](https://ipponusa.com/service/operating-model/)
- [Blogs](https://blog.ippon.tech/)
- [Success Stories](https://ipponusa.com/success-stories/)
- Show submenu for Resources Resources 
  
    - Resources
    - [Resources](https://ipponusa.com/resources/)
    - [eBooks](https://ipponusa.com/ebooks/)
    - [The Data Pour](https://info.ippon.tech/the-data-pour)
    - [Videos & Webinars](https://info.ippon.tech/videos-and-webinars)
    - [Media Center](https://ipponusa.com/media-center/)
- Search
- [Contact Us](https://ipponusa.com/contact/)

[Contact Us](https://ipponusa.com/contact/)

# How to SSH Reverse Tunnel to a Remote DB Server in an AWS Private Subnet using an EC2 Bastion Jump Host

![Nima Binayifaal](https://app.hubspot.com/settings/avatar/d41d8cd98f00b204e9800998ecf8427e)

 by [Nima Binayifaal](https://blog.ippon.tech/author/nima-binayifaal)

December 7, 2020

![How to SSH Reverse Tunnel to a Remote DB Server in an AWS Private Subnet using an EC2 Bastion Jump Host](https://blog.ippon.tech/hubfs/Imported_Blog_Media/SSH-Reverse-Title-3.png)

[AWS](https://blog.ippon.tech/tag/aws/) [Cloud](https://blog.ippon.tech/tag/cloud/) [DevOps](https://blog.ippon.tech/tag/devops/) [SSH](https://blog.ippon.tech/tag/ssh/) [Database](https://blog.ippon.tech/tag/database/)

 

December 7, 2020

Do you have publicly inaccessible database that you need to SSH into? Using SSH Reverse Tunneling, aka SSH Reverse Port Forwarding, you can securely connect to the database without directly opening it up to a vector of attack.

Resources in private subnets are notoriously hard to connect to (by design). With AWS you have VPNs and AWS Direct Connect as options, but the overhead isn't worth it unless you have very specific requirements. That's where SSH port forwarding/tunneling + Bastion Hosts come in.

This post goes hand in hand with another piece I will be uploading soon; the purpose of that post being a beginner's DevOps/Cloud Architect's guide to bringing up the foundational infrastructure featured below. I will post a link here when that goes up.

 

## What is SSH Reverse Tunneling?

With a traditional SSH, your machine can connect to a remote instance.

![](https://blog.ippon.tech/hs-fs/hubfs/Imported_Blog_Media/SSH-Connection-4.png?width=695&height=234&name=SSH-Connection-4.png)

Traditional SSH

 

 

SSH reverse tunneling on the other hand, sets up an omnidirectional connection between a port on your local machine and a port on the remote instance.

![](https://blog.ippon.tech/hs-fs/hubfs/Imported_Blog_Media/SSH-Reverse-Tunneling--1--Jan-18-2024-06-05-18-2320-PM.png?width=730&height=404&name=SSH-Reverse-Tunneling--1--Jan-18-2024-06-05-18-2320-PM.png)

 

 

Your local machine initiates a connection by forwarding a port on the remote instance to your local machine. You can then use that established connection to set up a **new** connection from your local machine back to the remote instance. The end-state of this interaction being that you can connect your local machine to the remote instance, so that you can use the tunnel (*in reverse)* to connect from the server to your local machine. Fortunately for us, this process is way easier to do than it is to understand.

## Our Infrastructure Topology

Zooming out, we can see the individual resources we're dealing with. In your AWS cloud you have a VPC (Virtual Private Cloud) that has one public subnet and one private subnet.

![](https://blog.ippon.tech/hs-fs/hubfs/Imported_Blog_Media/Topology-Jan-18-2024-06-05-14-9322-PM.png?width=1281&height=558&name=Topology-Jan-18-2024-06-05-14-9322-PM.png)

 

 

The public subnet has a lightweight EC2 instance (t2.nano in our case) whose only function is to act as a jump server. It doesn't even have PSQL installed. This bastion host's security group allows inbound connections on port 22 (SSH) and already has my public key and user profile on it.

![](https://blog.ippon.tech/hs-fs/hubfs/Imported_Blog_Media/BH-instance-1-2.png?width=426&height=185&name=BH-instance-1-2.png)

*Our bastion host's security group (sg-096afe51bf07b5e3c) allows inbound connections on port 22 (SSH) from all IP addresses.*

 

 

The private subnet has a PostgresSQL database with an attached security group *(sg-00d981dc294ce24f0)* that allows inbound connections from our bastion host's security group *(sg-096afe51bf07b5e3c)*

![](https://blog.ippon.tech/hs-fs/hubfs/Imported_Blog_Media/PSQL-SG-BIG-Jan-18-2024-06-05-19-2815-PM.png?width=1148&height=252&name=PSQL-SG-BIG-Jan-18-2024-06-05-19-2815-PM.png)

Our PostgresSQL database's security group ( *sg-00d981dc294ce24f0) allows inbound connections from our bastion host's security group*

 

 

## Using SSH Reverse Tunneling

First, we want to establish a reverse tunnel through our bastion host (75.101.188.93) to our PostgresSQL DB (postgrestest.cewfon7xqsuk.us-east-1.rds.amazonaws.com). To do so, we want to open up a terminal window on our local machine and write the following command:

```
ssh -i [private key] -N -L [local port]:[database host]:[remote port] [remote username]@[remote host]
```

where

- "ssh -i" is what we use to tell SSH what private key to use
- \[private key\] is your private ssh key
- -N sets up the tunnel without running any remote commands
- -L tells the tunnel to answer on the local side of the runnel
- \[local port\] should match the port number of your database. For PSQL this is 5432
- \[database host\] is your database's endpoint listed in the **Connectivity and Security** tab of of your database
- \[remote port\] should match the port number of your database.
- \[remote username\] is the username
- \[remote host\] is your ec2 IP address

 

![](https://blog.ippon.tech/hs-fs/hubfs/Imported_Blog_Media/Our-SSH-Reverse-Tunnel-Initiation-Cropped-1-Jan-18-2024-06-05-18-9179-PM.png?width=1138&height=253&name=Our-SSH-Reverse-Tunnel-Initiation-Cropped-1-Jan-18-2024-06-05-18-9179-PM.png)

This is what it looks like for me

 

 

That's it, our reverse tunnel is now sitting open for as long as we keep this terminal window open. Now all we have to do is to open up a new terminal window on our local machine and connect to our PostgresSQL database using:

```
psql -U [db username] -p [local port] -h localhost
```

where

- psql is the command we use to talk to postgres
- -U says what user to use
- \[db username\] is the existing user on the psql db we want to connect as
- -p says what port we want to use
- \[local port\] is the local port we used to connect from before
- -h says which host to connect to
- localhost is the same as 127.0.0.1, since were connecting to a locally forwarded port that leads to the tunnel

![](https://blog.ippon.tech/hs-fs/hubfs/Imported_Blog_Media/Connecting-to-Postgres-Cropped-Jan-18-2024-06-05-20-0413-PM.png?width=1138&height=367&name=Connecting-to-Postgres-Cropped-Jan-18-2024-06-05-20-0413-PM.png)

 

 

And we're in. A super complicated concept that only takes two short alphanumerical lines to put into practice.

## Conclusion

Aside from the theory behind SSH Reverse Tunneling, the hardest part is setting up the infrastructure to support it. I will be covering just that in my next post.

## Related Articles

##### [![Linux Server Security: Essential Hardening](https://blog.ippon.tech/hs-fs/hubfs/The%20Data%20Pour%20Social%20Media%20copy-3.png?width=520&height=294&name=The%20Data%20Pour%20Social%20Media%20copy-3.png) SSH • June 18, 2025 Linux Server Security: Essential Hardening 7 min read](https://blog.ippon.tech/linux-server-security-essential-hardening)

### Comments

### Subscribe to Our Blog!

Stay informed with the latest insights and updates by signing up for our weekly blog newsletter – delivered straight to your inbox!

[Back to blog homepage »](https://blog.ippon.tech/)

![IpponLogoKleinBlue](https://blog.ippon.tech/hs-fs/hubfs/IpponLogoKleinBlue.png?width=247&height=73&name=IpponLogoKleinBlue.png "IpponLogoKleinBlue")

Ippon is a consulting and expertise firm, who is convinced that technology is a source of progress for society. We help our clients leverage their digital assets to design an appropriate strategy and deploy their transformation roadmap at scale.

#### Navigation

- [Home](https://ipponusa.com/)
- [About](https://ipponusa.com/about-us/)
- [Services](https://ipponusa.com/services/)
- [Blogs](https://blog.ippon.tech/?__hstc=223043268.1036d82247623b329dfefe4e92697801.1714729179243.1714729179243.1714729179243.1&__hssc=223043268.2.1714729179244&__hsfp=803678701)
- [eBooks](https://ipponusa.com/ebooks/)
- [The Data Pour](https://info.ippon.tech/the-data-pour?__hstc=223043268.1036d82247623b329dfefe4e92697801.1714729179243.1714729179243.1714729179243.1&__hssc=223043268.2.1714729179244&__hsfp=803678701)

[Contact Us](https://ipponusa.com/contact/)

[Join Us](https://ipponusa.com/careers/)

#### Services

- [Data & Analytics](https://ipponusa.com/service/data-analytics/)
- [Cloud Strategy](https://ipponusa.com/service/cloud-strategy/)
- [Artificial Intelligence](https://ipponusa.com/service/artificial-intelligence/)
- [Operating Model](https://ipponusa.com/service/operating-model/)
- [Platform Modernization](https://ipponusa.com/service/platform-moderization/)
- [Product Innovation](https://ipponusa.com/service/product-innovation/)

#### Ippon International

- [France](https://fr.ippon.tech/?__hstc=223043268.1036d82247623b329dfefe4e92697801.1714729179243.1714729179243.1714729179243.1&__hssc=223043268.2.1714729179244&__hsfp=803678701)
- [Australia](https://au.ippon.tech/?__hstc=223043268.1036d82247623b329dfefe4e92697801.1714729179243.1714729179243.1714729179243.1&__hssc=223043268.2.1714729179244&__hsfp=803678701)

- #### Contact
- Ippon Technologies  
  [3431 West Leigh Street Richmond, VA 23230, USA](https://maps.app.goo.gl/RySm6SAwZnsxeiLz9)
- [(844) 477- 6687](tel:8444776687)
- [Sales@ipponusa.com](mailto:Sales@ipponusa.com)

<https://www.facebook.com/IpponUSA/> <https://www.youtube.com/c/ipponusa> <https://www.linkedin.com/company/ippon-technology>

©Copyright 2024 Ippon USA. All Rights Reserved.   |   [Terms and Conditions](https://ipponusa.com/privacy-policy/)   |   [Privacy Policy](https://ipponusa.com/privacy-policy/)   |   [Website by Skol Marketing](https://skolmarketing.com/)

```json
{
  "@context" : "https://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "Nima Binayifaal",
    "url" : "https://blog.ippon.tech/author/nima-binayifaal"
  },
  "dateModified" : "2024-01-29T17:01:10.796Z",
  "datePublished" : "2020-12-07T14:06:00.000Z",
  "headline" : "How to SSH Reverse Tunnel to a Remote DB Server in an AWS Private Subnet using an EC2 Bastion Jump Host",
  "image" : [ "https://blog.ippon.tech/hubfs/Imported_Blog_Media/SSH-Reverse-Title-3.png" ],
  "mainEntityOfPage" : {
    "@id" : "https://blog.ippon.tech/ssh-reverse-tunnel-to-private-database",
    "@type" : "WebPage"
  },
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "url" : "https://blog.ippon.tech/hubfs/logo_SVG.svg"
    },
    "name" : "Ippon Technologies"
  }
}
```