Deploying an HTTPS Website on a NAT VPS: Nginx + acme.sh
Published 10/8/2026, 04:15:08 · Updated 10/8/2026, 04:15:08
Running an HTTPS site on a NAT VPS comes down to two things: mapping a port to internal 80 / 443, and using the right certificate challenge.
Step 1: confirm the port mapping
- On the order details page, map a mappable public port to internal 80 (HTTP) or 443 (HTTPS).
- From outside the URL is http://public-ip:your-port, not the default 80 / 443.
- Skip this and nothing will ever load from outside.
Step 2: use DNS-01 for the certificate
- Let's Encrypt's HTTP-01 challenge needs port 80; on a NAT plan the public port is assigned by the system and is usually not 80.
- So use DNS-01: acme.sh with a plugin such as dns_cf (Cloudflare) validates through a DNS TXT record.
- DNS-01 also supports wildcards (e.g. *.example.com).
Step 3: Nginx reverse proxy
- Nginx listens on internal 80 (the internal port your public port maps to).
- Nginx terminates TLS and reverse-proxies to your app (e.g. 127.0.0.1:3000).
- Point the certificate at acme.sh's output and reload Nginx after renewal.
Step 4: DDNS (optional)
- The egress IP rotates daily; if you serve by domain name, use DDNS so the A record follows the current egress IP.
- Not needed if you only use public-ip:port.
Common pitfalls
- Certificate issued but the browser still complains: make sure you visit https:// with the correct port.
- Renewal fails: the DNS-01 API token lacks permission or has expired.
- Nothing loads at all: check the mapping exists, Nginx is running, and the internal firewall allows it.
Next steps
- Read the port and access policy
- More troubleshooting in the Help Center
