SSH-CONNECT
In short: The SSH sub-protocol that runs on top of the encrypted connection and provides “channels” for the rest of the SSH traffic.
In more detail: Internally, SSH is divided into several sub-protocols: SSH-TRANS establishes the basic encrypted connection, SSH-USERAUTH handles the user’s authentication over it, and SSH-CONNECT manages several logical channels at the same time on this authenticated connection (e.g. an interactive shell session and at the same time a forwarded port). This layered model makes it possible, for example, to multiplex several terminal sessions or tunnels over a single TCP connection.
In Depth
SSH-CONNECT’s channel mechanism is the reason why a single SSH login window can do several things at once without establishing a new connection several times: each requested function (an interactive shell, a forwarded port, an SFTP session, an X11 window) gets its own logical channel within the same TCP connection. Each channel has its own flow control — a slow channel doesn’t automatically block the others.
Typical channel types are session (interactive shell or a single command), direct-tcpip (local port forwarding — e.g. ssh -L 5432:localhost:5432 server, to use a remote database as if it were running locally) and forwarded-tcpip (remote port forwarding, the opposite direction). This design makes SSH much more than just a remote access tool for the command line — it’s the basis for secure tunnelling of arbitrary TCP connections through a single authenticated session.
See also: SSH, SSH-TRANS, SSH-USERAUTH, Multiplexing