I have users on my Debian box that can Tunnel traffic via SSH Logins however I want to have control over where they can Tunnel traffic to.

How do I setup Debian so that users in a group (lets call it thegroup) can only Tunnel traffic to mywebsite.com:80, theotherwebsite:80 and anyip:1060 via SSH?

Really stuck with this and any help would be greatly appreciated!