If tunnel machine is router: tunnel machine: ssh -g username@ssh.es.aau.dk -nNfL 1234:ordbogen.com:80 iptables -t nat -A OUTPUT -m tcp -p tcp -d ordbogen.com -j REDIRECT --to-port 1234 iptables -t nat -A PREROUTING -m tcp -p tcp -d ordbogen.com -j REDIRECT --to-port 1234 client: nothing :) If tunnel machine is NOT router: tunnel machine: ssh -g username@ssh.es.aau.dk -nNfL 1234:ordbogen.com:80 iptables -t nat -A OUTPUT -m tcp -p tcp -d ordbogen.com -j REDIRECT --to-port 1234 client: sudo iptables -t nat -A OUTPUT -m tcp -p tcp -d ordbogen.com -j DNAT --to-destination TUNNEL_MACHINE_IP:1234