Feature: TCP Tunneling

Secure TCP tunneling for seamless infrastructure access

Connect to internal infrastructure, including databases, servers and other TCP-based applications, without exposing credentials or making changes to the network.

Keeper interface displaying infrastructure resources with options to start secure TCP tunnels, enabling encrypted access to databases and servers without exposing them directly to a network.

How TCP tunneling works in Keeper

Initiate the tunnel from a PAM record in the Keeper Desktop App

The Keeper Desktop client opens a local port on your machine

All traffic sent to the port is securely transmitted through an encrypted tunnel to the Keeper Gateway

The Keeper Gateway forwards traffic to the target IP:port defined in the PAM record

You connect to the system using any native application through your local host and port

Secure access made simple

Establish encrypted tunnels instantly

Initiate secure, end-to-end encrypted TCP tunnels with a single click, no manual configuration, scripting or network adjustments required. Access to infrastructure is immediate, controlled and seamless.

Keeper interface showing an active secure tunnel to a MySQL production database, with local port mapping and connection details for encrypted remote access.

Seamless integration with your preferred tools

Connect using trusted applications like MySQL Workbench, pgAdmin, DBeaver, SQL Server Management Studio, PuTTY and others, without altering existing workflows or compromising security standards.

Enforce zero-trust access by design

Every session is secured by Keeper's zero-trust, zero-knowledge architecture. Credentials are never exposed to the end user, and access is continuously verified.

KeeperPAM settings screen configuring Just-in-Time (JIT) access for a MySQL database, with options for ephemeral account creation, privilege elevation, and RBAC.

Enable access only when it's required

Provision Just-In-Time (JIT) access to critical systems with precise time and policy controls. Sessions expire automatically, eliminating standing privilege and reducing the attack surface.

Simplify database access with KeeperDB Proxy

KeeperDB Proxy automatically injects ephemeral or static secrets into database tunnels through the Keeper Gateway, giving users seamless access with session recording and query logging built in.

Keeper interface showing an active secure database tunnel with local port mapping, connection details and proxy status, enabling encrypted access to a production database through KeeperDB.
Keeper external logging settings page displaying integrations with SIEM and security monitoring platforms, including Amazon S3 Bucket, CrowdStrike Falcon Next-Gen, Cortex XSIAM, Datadog, Devo, Elastic, Google Security Operations, IBM QRadar SIEM and LogRhythm.

Maintain full oversight of every session

Capture detailed telemetry and audit trails for every privileged session. Keeper integrates with SIEM platforms to ensure compliance, forensic readiness and real-time visibility.

Why choose KeeperPAM for secure TCP tunneling?

Eliminate VPN complexity

No need for VPNs, bastion hosts or exposed ports. Tunnels connect over outbound HTTPS and WebRTC, reducing infrastructure maintenance and risk.

Strengthen security posture

All credentials remain encrypted and isolated within the Keeper Vault. Privileged access is ephemeral, auditable and policy-driven.

Move faster across hybrid and multi-cloud environments

Tunnels work across AWS, Azure, GCP, on-prem environments and hybrid networks. KeeperPAM standardizes access across your entire infrastructure.

Frequently asked questions

What tools are supported?

Any local application that connects over TCP is supported. Popular examples include database clients, SSH clients and application debuggers.

Is any installation required?

Yes, Keeper Gateway must be installed in the network where the target systems reside. No client installation is needed beyond the Keeper Desktop app.

How are tunnels secured?

All tunnels are encrypted end-to-end using Keeper's zero-knowledge architecture. Credentials are never exposed, and connections are restricted through policy.

Can I use tunneling without exposing credentials?

Yes, users never receive direct access to credentials when using Keeper tunneling. Access is provisioned securely through Keeper's infrastructure without exposing credentials on the endpoint.

Is session activity recorded?

Yes, all tunnel activity is logged. KeeperPAM supports detailed session telemetry and integrates with SIEM platforms.

Withdraw Cookie ConsentWe value your privacy

We use cookies on our site to give you the best browsing experience, serve personalized ads about our products and content, and analyze website traffic. To learn more, please refer to our Privacy Policy.

Sign up for a Free Trial

Buy Now