Skip to main content
← Back to news

NAT VPS Port Forwarding in Practice: SSH, Web (80/443) and DDNS

Published 10/8/2026, 04:01:12 · Updated 10/8/2026, 04:01:12

Access to a NAT VPS relies on port forwarding: point a public port at a port inside your instance. Once that clicks, both SSH and a website will work.

How ports are assigned

  • SSH permanently occupies one public port and points at internal port 22; it is not part of the editable mappings.
  • The remaining public ports can be mapped freely to any internal port, including 80 and 443.
  • Public ports are assigned by the system and cannot be chosen; need more — move up a plan.

Logging in over SSH

  • Your order details page shows the public host, your SSH port, the account and the initial password.
  • Always include the port: ssh account@public-ip -p your-ssh-port.
  • Change the password immediately after your first login.

Serving a website on 80 / 443

  • On the order details page, map a mappable public port to internal 80 or 443.
  • From outside the URL is still http://public-ip:your-port.
  • The web server and its TLS certificate are installed and renewed by you inside the instance (acme.sh / certbot work fine).

What DDNS is for

  • The egress IP rotates automatically every day, so a hard-coded A record will go stale.
  • If you need a stable entry point, use DDNS so the domain follows the current egress IP.
  • For SSH or short-lived connections, public-ip:port is enough.

Troubleshooting

  • Connection refused: the path is fine but nothing is listening inside (or the service is not running).
  • Timeout / nothing at all: check that the port mapping exists and the instance is running.
  • A site loads but is not yours: confirm the mapping points at internal 80 / 443, not another port.

Next steps