Skip to main content
← Back to news

Deploying an HTTPS Website on a NAT VPS: Nginx + acme.sh

Published 10/8/2026, 04:15:08 · Updated 10/8/2026, 04:15:08

Running an HTTPS site on a NAT VPS comes down to two things: mapping a port to internal 80 / 443, and using the right certificate challenge.

Step 1: confirm the port mapping

  • On the order details page, map a mappable public port to internal 80 (HTTP) or 443 (HTTPS).
  • From outside the URL is http://public-ip:your-port, not the default 80 / 443.
  • Skip this and nothing will ever load from outside.

Step 2: use DNS-01 for the certificate

  • Let's Encrypt's HTTP-01 challenge needs port 80; on a NAT plan the public port is assigned by the system and is usually not 80.
  • So use DNS-01: acme.sh with a plugin such as dns_cf (Cloudflare) validates through a DNS TXT record.
  • DNS-01 also supports wildcards (e.g. *.example.com).

Step 3: Nginx reverse proxy

  • Nginx listens on internal 80 (the internal port your public port maps to).
  • Nginx terminates TLS and reverse-proxies to your app (e.g. 127.0.0.1:3000).
  • Point the certificate at acme.sh's output and reload Nginx after renewal.

Step 4: DDNS (optional)

  • The egress IP rotates daily; if you serve by domain name, use DDNS so the A record follows the current egress IP.
  • Not needed if you only use public-ip:port.

Common pitfalls

  • Certificate issued but the browser still complains: make sure you visit https:// with the correct port.
  • Renewal fails: the DNS-01 API token lacks permission or has expired.
  • Nothing loads at all: check the mapping exists, Nginx is running, and the internal firewall allows it.

Next steps