# Reach devices next to your Pi

A tunnel does not have to end on the Pi. Its target is any host the Pi can
reach — a NAS, a printer, a camera, a controller. One agent on one Pi is
enough for the whole network, because the devices being reached run nothing
at all.

## The target is the Pi's choice

Every tunnel has a target: a host and a port, written from the Pi's point of
view. The default target host is `127.0.0.1` — the Pi itself,
which is how [hosting a
website from the Pi](https://relayssh.com/docs/host-a-website/) works. Set it to `192.168.1.50` or
`printer.local` instead, and the relay still delivers every
connection to the Pi — but the Pi passes it on, opening a plain TCP
connection to that host on its own network.

The relay never sees your network. It hands the connection to the Pi through
the reverse tunnel, and the Pi makes the local hop. Host names resolve on the
Pi too, so `printer.local` means whatever it means on your
network, not on the relay.

## What it is for

Devices that cannot run an agent. A printer, an IP camera, a router, a smart
plug, a PLC — none of them will ever run your software, and none of them
need to. The Pi is the one machine you control, and a tunnel per service is
all it takes: `192.168.1.50:5000` for the NAS web UI,
`printer.local:631` for printing, `192.168.1.1:80` for
the router. Each tunnel gets its own stable public port on the relay.

## Public tunnel, or SSH forward?

A public tunnel makes the target reachable by anyone who finds the port.
That is the point for a website — and the wrong default for a login page.
For admin interfaces, management consoles, and anything industrial, forward
through the Pi's SSH tunnel instead:

```sh
ssh -L 8443:192.168.1.50:8443 -p 20001 pi@relayssh.com
```

Then open `https://localhost:8443`. The path is the same — relay,
reverse tunnel, Pi, LAN — but it only exists inside your SSH session, and
your device checks your key before any of it happens. Nothing is exposed to
the internet. If a thing has a password prompt, reach it this way.

## Boundaries

A tunnel forwards one TCP port to one target. This is not a VPN: there is no
subnet routing, no device discovery, and UDP does not traverse it. Anything
that speaks TCP works — HTTP, RTSP over TCP, Modbus TCP, SSH itself. Older
agents ignore the target host and forward to the Pi itself, so update the
agent before pointing a tunnel at a neighbor — re-running the install
command is the upgrade.
