This page explains SSH tunneling (also called SSH port forwarding), how it can be used to get into an internal corporate network from the Internet, and how to prevent SSH tunnels at a firewall. SSH tunneling is a powerful tool, but it can also be abused.

Without forced tunneling, Internet-bound traffic from your VMs in Azure will always traverse from Azure network infrastructure directly out to the Internet, without the option to allow you to inspect or audit the traffic. Unauthorized Internet access can potentially lead to information disclosure or other types of security breaches.

Firefox will send its traffic through the SSH tunnel, while other applications will use your Internet connection normally. When doing this in Firefox, select "Manual proxy configuration", enter "" into the SOCKS host box, and enter the dynamic port into the "Port" box.

Tunneling traffic through a secure channel protects your data from being readable once intercepted. Also, someone watching your connections will only see one connection (the SSH connection to the SSH server) and not any of the possibly many Internet connections that may be tunneled through it. This hides information about which sites you visit.