NAT VPS Port Forwarding in Practice: SSH, Web (80/443) and DDNS
Published 10/8/2026, 04:01:12 · Updated 10/8/2026, 04:01:12
Access to a NAT VPS relies on port forwarding: point a public port at a port inside your instance. Once that clicks, both SSH and a website will work.
How ports are assigned
- SSH permanently occupies one public port and points at internal port 22; it is not part of the editable mappings.
- The remaining public ports can be mapped freely to any internal port, including 80 and 443.
- Public ports are assigned by the system and cannot be chosen; need more — move up a plan.
Logging in over SSH
- Your order details page shows the public host, your SSH port, the account and the initial password.
- Always include the port: ssh account@public-ip -p your-ssh-port.
- Change the password immediately after your first login.
Serving a website on 80 / 443
- On the order details page, map a mappable public port to internal 80 or 443.
- From outside the URL is still http://public-ip:your-port.
- The web server and its TLS certificate are installed and renewed by you inside the instance (acme.sh / certbot work fine).
What DDNS is for
- The egress IP rotates automatically every day, so a hard-coded A record will go stale.
- If you need a stable entry point, use DDNS so the domain follows the current egress IP.
- For SSH or short-lived connections, public-ip:port is enough.
Troubleshooting
- Connection refused: the path is fine but nothing is listening inside (or the service is not running).
- Timeout / nothing at all: check that the port mapping exists and the instance is running.
- A site loads but is not yours: confirm the mapping points at internal 80 / 443, not another port.
Next steps
- Read the port and access policy
- Not sure how many ports you need? See plans and pricing
- More troubleshooting in the Help Center
