FreeVPNNet

How to set up SSH Tunnel on Windows

An SSH tunnel sends your traffic through the server using a username and password. Besides plain SSH, the server also accepts SSH over TLS and over WebSocket, which help on restrictive networks.

Last reviewed

What you need

  • An active SSH configuration from this site
  • Hostname, ports, username and password from your configuration page

App

Bitvise SSH Client

Get it from bitvise.com

Official source only.

Where each detail goes

Account details and the matching fields in the app
On your configuration pageIn the app or settings
HostnameHost / Server
PortSSH port
SSL/TLS portSSL/TLS (stunnel) port, with SNI if shown
WebSocket portWebSocket port (and path for WS+TLS)
Username / PasswordUsername / Password

Steps

  1. Install Bitvise SSH Client from bitvise.com (link above).

    Illustration of step 1: Install Bitvise SSH Client from bitvise.com (link above).
    Illustration — your app may look slightly different.
  2. On the Login tab enter Host: your Hostname, Port: your Port, Username: your username, Initial method: password, and your password.

    Illustration of step 2: On the Login tab enter Host: your Hostname, Port: your Port, Username: your username, Initial method: password, and your password.
    Illustration — your app may look slightly different.
  3. On the Services tab enable SOCKS/HTTP Proxy Forwarding on 127.0.0.1 port 1080.

    Illustration of step 3: On the Services tab enable SOCKS/HTTP Proxy Forwarding on 127.0.0.1 port 1080.
    Illustration — your app may look slightly different.
  4. Click Log in and accept the server key on first connection.

    Illustration of step 4: Click Log in and accept the server key on first connection.
    Illustration — your app may look slightly different.
  5. Set Windows (Settings → Network & internet → Proxy) or your browser to use the SOCKS proxy 127.0.0.1:1080.

    Illustration of step 5: Set Windows (Settings → Network & internet → Proxy) or your browser to use the SOCKS proxy 127.0.0.1:1080.
    Illustration — your app may look slightly different.

Check that it works

The app shows it is connected (or the terminal stays open without errors). Search the web for "what is my IP" in a browser that uses the tunnel.

Disconnect

Click Log out and turn the proxy setting off.

Troubleshooting

Permission denied / auth failed

Copy the username and password again from your configuration page. The configuration may have expired.

Connection times out

Your network may block port 22. Switch the app to SSL/TLS or WebSocket mode using the ports on your configuration page.

Only the browser uses the VPN

That is normal for a SOCKS proxy on computers. Set the proxy in the system network settings to cover more apps.