Reach devices next to your Pi
A tunnel does not have to end on the Pi. Its target is any host the Pi can reach — a NAS, a printer, a camera, a controller. One agent on one Pi is enough for the whole network, because the devices being reached run nothing at all.
The target is the Pi's choice
Every tunnel has a target: a host and a port, written from the Pi's point of
view. The default target host is 127.0.0.1 — the Pi itself,
which is how hosting a
website from the Pi works. Set it to 192.168.1.50 or
printer.local instead, and the relay still delivers every
connection to the Pi — but the Pi passes it on, opening a plain TCP
connection to that host on its own network.
The relay never sees your network. It hands the connection to the Pi through
the reverse tunnel, and the Pi makes the local hop. Host names resolve on the
Pi too, so printer.local means whatever it means on your
network, not on the relay.
What it is for
Devices that cannot run an agent. A printer, an IP camera, a router, a smart
plug, a PLC — none of them will ever run your software, and none of them
need to. The Pi is the one machine you control, and a tunnel per service is
all it takes: 192.168.1.50:5000 for the NAS web UI,
printer.local:631 for printing, 192.168.1.1:80 for
the router. Each tunnel gets its own stable public port on the relay.
Public tunnel, or SSH forward?
A public tunnel makes the target reachable by anyone who finds the port. That is the point for a website — and the wrong default for a login page. For admin interfaces, management consoles, and anything industrial, forward through the Pi's SSH tunnel instead:
ssh -L 8443:192.168.1.50:8443 -p 20001 pi@relayssh.com
Then open https://localhost:8443. The path is the same — relay,
reverse tunnel, Pi, LAN — but it only exists inside your SSH session, and
your device checks your key before any of it happens. Nothing is exposed to
the internet. If a thing has a password prompt, reach it this way.
Boundaries
A tunnel forwards one TCP port to one target. This is not a VPN: there is no subnet routing, no device discovery, and UDP does not traverse it. Anything that speaks TCP works — HTTP, RTSP over TCP, Modbus TCP, SSH itself. Older agents ignore the target host and forward to the Pi itself, so update the agent before pointing a tunnel at a neighbor — re-running the install command is the upgrade.