Port Forwarding
Port Forwarding
Open specific ports on your Static IP to reach a home server, NAS, security camera, or game host from anywhere on the internet, securely through the OrbVPN tunnel.
What Is Port Forwarding?
Most home and mobile internet connections sit behind NAT, which means devices on your network cannot be reached directly from the internet. You can browse out, but nothing can connect in. That makes it impossible to run a service, a personal web server, a NAS, a game host, a security camera, that you want to access remotely.
Port Forwarding on your OrbVPN Static IP fixes this. You tell OrbMesh that traffic arriving at a specific port on your dedicated public IP should be routed through the VPN tunnel to your device. Anyone (or any system) you authorize can then reach your service at your-static-ip:port, from anywhere, while every byte still travels inside your encrypted tunnel.
Requires a Static IP
Port Forwarding is built on the 1:1 NAT of a Static IP allocation. You need an active Static IP in the region where you want to forward ports, because the inbound DNAT rule maps your dedicated public address back to your device.
How It Works
When you create a port-forward rule, OrbMesh programs a destination-NAT (DNAT) rule on the server. Traffic hitting the chosen external port on your public IP is rewritten and sent down the tunnel to the internal port on your device.
Choose External and Internal Ports
Pick the external port that the internet connects to, and the internal port your device's service listens on. They can be the same or different.
Select a Protocol
Choose TCP, UDP, or both, depending on what your service uses. Web servers and SSH are TCP; many games and voice services use UDP.
OrbMesh Programs the Rule
The server adds a DNAT rule mapping your-static-ip:external-port to your-device:internal-port through the VPN tunnel. The rule moves from Configuring to Active.
Connect From Anywhere
Anyone you share the address with reaches your service at your Static IP and external port. The traffic enters the exit server and is tunneled to you securely.
Rule Lifecycle
Each rule has a clear status, Pending, Configuring, Active, Disabled, Error, or Deleted, so you always know whether it is live. You can also enable or disable a rule without deleting it, for example to temporarily close a service.
Protocols and Ports
TCP
For connection-oriented services: web servers, SSH, remote desktop, NAS file sharing, and most application protocols.
UDP
For datagram services: many multiplayer games, VoIP, video calls, and real-time streaming protocols.
Both
Forward TCP and UDP on the same port pair in one rule, for services that use both transports.
External vs Internal Ports
The external port is what the internet sees on your public IP; the internal port is what your device listens on. Mapping a non-standard external port (say 8443) to a standard internal one (443) is a simple way to reduce automated scanning noise against your service.
How Many Ports You Get
Every Static IP plan includes a baseline number of port-forwarding rules per region. Need more? Add-on packs extend your capacity without changing your Static IP plan.
Included With Your Plan
Static IP tiers include from one rule per region on Personal up to three rules per region on Business and Enterprise. These are ready to use the moment your allocation is active.
Port Forwarding Add-On Packs
Expand capacity with add-on packs: Basic (5 ports), Standard (10), Advanced (25), and Power (50). Stack packs as your needs grow.
Track Your Usage
OrbVPN shows your port-forwarding limits at a glance, how many rules are included, how many come from add-on packs, how many are in use, and how many remain, so you always know your available headroom.
Creating a Port-Forward Rule
Open Your Allocation
In the Static IP screen, select the regional allocation where you want to forward a port. You will see its public IP and existing rules.
Add a New Rule
Tap Add Port Forward. Enter the external port (internet-facing) and the internal port (your device's service).
Pick the Protocol
Select TCP, UDP, or Both to match your service. Add an optional description so you remember what the rule is for.
Save and Wait for Active
Save the rule. OrbMesh provisions the DNAT mapping; when the status reads Active, your service is reachable at your Static IP and external port.
Test the Connection
From an external network, connect to your-static-ip:external-port. If it does not respond, confirm your device's service is running and listening on the internal port.
Common Use Cases
Home Server & NAS
Reach a self-hosted website, file server, or NAS from outside your home, all through the encrypted tunnel rather than exposing your router.
Game Hosting
Host a multiplayer game session that friends can join from anywhere using your Static IP and forwarded port.
Remote Cameras & IoT
Access security cameras, home automation hubs, and other IoT devices remotely without opening ports on your home router.
Remote Administration
Securely reach SSH or remote-desktop endpoints on your devices at a fixed, predictable address you control.
Security Best Practices
Port Forwarding opens a doorway to your device, so treat it with the same care as any public-facing service.
Forward Only What You Need
Create rules only for services you actively use, and disable or delete them when you no longer need remote access.
Secure the Service Itself
The tunnel protects traffic in transit, but the exposed service still needs strong authentication. Use good passwords, keys, and up-to-date software.
Use Non-Standard External Ports
Mapping an unusual external port to your standard internal port cuts down on automated scanning and brute-force noise.
Monitor and Review
Periodically review your active rules in the app. Remove any you no longer recognize or need to keep your attack surface minimal.
Your VPN Stays Protected
Port-forwarding rules apply only to your own dedicated Static IP and route exclusively to your device. They do not weaken OrbVPN's network or expose other users, each user's forwarded ports are isolated to their own allocation.
Reach Your Devices From Anywhere
Pair Port Forwarding with a Static IP to securely expose your home server, NAS, cameras, or game host through the encrypted OrbVPN tunnel.