Port Forwarding and Tunnels

A forward carries a TCP connection inside the SSH session. -L (local) makes a port on your machine lead to an address as seen from the server, so MySQL 524 can stay bound to the server's loopback, with 3306 closed, and still serve your laptop's client. -D makes a local SOCKS proxy that exits at the server, and -R (remote) opens a server port that leads back to your machine, say to demo a site running on your laptop.

Local, dynamic and remote forwards over one connectionShell
ssh -f -N -L 13306:127.0.0.1:3306 web1     # local 13306 -> MySQL on the server
mysql --defaults-extra-file=t.cnf -h 127.0.0.1 -P 13306 -e 'SELECT CURRENT_USER(), @@version;'
ssh -O forward -D 1080 web1                # SOCKS proxy on local port 1080
curl -s -o /dev/null -w '%{http_code} via SOCKS\n' \
  --socks5-hostname 127.0.0.1:1080 http://localhost/
ssh -O forward -R 19090:127.0.0.1:80 web1  # server's 19090 -> your port 80
ssh -O exit web1
Output
CURRENT_USER()  @@version
ch01_07@localhost       9.7.2
200 via SOCKS
Exit request sent.

-f -N backgrounds ssh without running a command, and thanks to ControlMaster (SSH Config and Jump Hosts) each ssh -O forward adds a tunnel to that one connection. ss -tlnp showed both ends on loopback only: ssh on local port 13306, sshd-session on the server's 19090. For a tunnel that must outlive network drops, run it from a systemd 142,543 unit (Your Own Unit File) with ServerAliveInterval 60 and ExitOnForwardFailure yes. On the server, AllowTcpForwarding no (Hardening sshd) or PermitOpen limits what an account may tunnel.