Well, let's spawn a `socat` an the remote side as well:

$ sudo socat TUN:,up EXEC:'ssh -l root HOST "socat TUN:,up"'
$ sudo socat TUN:,up EXEC:'ssh -l root HOST "socat TUN:,up -"'

The right argument (`EXEC:"…"`) spaws `ssh` logs into `HOST` and starts a `socat` which is connected to a tunnel device.