A PostgreSQL server on host db01 listens only on 127.0.0.1 port 5432. From your workstation you want to reach it by connecting to port 15432 on your own machine, tunnelled over SSH. Which command sets that up?

LPIC-1 Exam 102-500, objective 110. Security hard

Machine-checked — no person has signed for it. This question was read against the source cited below by an automated pass, which found no contradiction. That is a weaker claim than it sounds: the same kind of process wrote the question, so it can confirm its own mistake.

Treat it as a good draft rather than as settled fact, and read the source below before you rely on it. It is not used in mock exams here — only questions a person has signed for are.

How these questions are written — where each question comes from, what the verification ledger records, and what happens when one is found wrong.

The options

Not correct ssh -R 15432:localhost:5432 db01

Wrong direction. -R is remote forwarding: it opens a listening port on db01 that is forwarded back to your workstation. You would be publishing a local service to the server, not reaching the server's service.

Not correct ssh -D 15432 db01

Wrong. -D creates a dynamic SOCKS proxy on port 15432. It is useful for a browser, but the client application must speak SOCKS and no fixed destination is bound, so a plain psql connection to localhost:15432 fails.

Not correct ssh -X db01

Wrong. -X enables X11 forwarding so graphical applications started on db01 can display on your workstation. It forwards no TCP port of your choosing.

Correct ssh -L 15432:localhost:5432 db01

Correct. -L is local forwarding: ssh listens on port 15432 on your workstation and forwards each connection through the tunnel, where db01 opens it to localhost:5432 — the loopback address as seen from db01.

Why

The -L argument reads [bind_address:]port:host:hostport, and the crucial subtlety is that host:hostport is resolved by the far end of the connection, which is why localhost here means db01's own loopback interface. By default the local listener binds only to 127.0.0.1; GatewayPorts and an explicit bind address are needed to expose it to other machines. -R is the mirror image, listening on the remote side, and -D is a SOCKS proxy rather than a point-to-point forward.

Where this comes from

Cited
LPI exam objective 110.3
What it says
Tunnel a TCP connection through SSH using port forwarding.

Practise this

Reading one question is not practice. The trainer will draw a short set from objective 110 and space the ones you get wrong.

Practise LPIC-1 Exam 102-500

More questions on this objective

All questions on Security

Practise LPIC-1 Exam 102-500