Port Forwarding

Reach Your Devices

Port Forwarding

Open specific ports on your Static IP to reach a home server, NAS, security camera, or game host from anywhere on the internet, securely through the OrbVPN tunnel.

0
Protocols
0
Server-Side Routing
0
Ports (Power Pack)
0
Tunnel Protected

What Is Port Forwarding?

Most home and mobile internet connections sit behind NAT, which means devices on your network cannot be reached directly from the internet. You can browse out, but nothing can connect in. That makes it impossible to run a service, a personal web server, a NAS, a game host, a security camera, that you want to access remotely.

Port Forwarding on your OrbVPN Static IP fixes this. You tell OrbMesh that traffic arriving at a specific port on your dedicated public IP should be routed through the VPN tunnel to your device. Anyone (or any system) you authorize can then reach your service at your-static-ip:port, from anywhere, while every byte still travels inside your encrypted tunnel.

Requires a Static IP

Port Forwarding is built on the 1:1 NAT of a Static IP allocation. You need an active Static IP in the region where you want to forward ports, because the inbound DNAT rule maps your dedicated public address back to your device.


How It Works

When you create a port-forward rule, OrbMesh programs a destination-NAT (DNAT) rule on the server. Traffic hitting the chosen external port on your public IP is rewritten and sent down the tunnel to the internal port on your device.

1

Choose External and Internal Ports

Pick the external port that the internet connects to, and the internal port your device's service listens on. They can be the same or different.

2

Select a Protocol

Choose TCP, UDP, or both, depending on what your service uses. Web servers and SSH are TCP; many games and voice services use UDP.

3

OrbMesh Programs the Rule

The server adds a DNAT rule mapping your-static-ip:external-port to your-device:internal-port through the VPN tunnel. The rule moves from Configuring to Active.

4

Connect From Anywhere

Anyone you share the address with reaches your service at your Static IP and external port. The traffic enters the exit server and is tunneled to you securely.

Rule Lifecycle

Each rule has a clear status, Pending, Configuring, Active, Disabled, Error, or Deleted, so you always know whether it is live. You can also enable or disable a rule without deleting it, for example to temporarily close a service.


Protocols and Ports

TCP

For connection-oriented services: web servers, SSH, remote desktop, NAS file sharing, and most application protocols.

UDP

For datagram services: many multiplayer games, VoIP, video calls, and real-time streaming protocols.

Both

Forward TCP and UDP on the same port pair in one rule, for services that use both transports.

External vs Internal Ports

The external port is what the internet sees on your public IP; the internal port is what your device listens on. Mapping a non-standard external port (say 8443) to a standard internal one (443) is a simple way to reduce automated scanning noise against your service.


How Many Ports You Get

Every Static IP plan includes a baseline number of port-forwarding rules per region. Need more? Add-on packs extend your capacity without changing your Static IP plan.

Included With Your Plan

Static IP tiers include from one rule per region on Personal up to three rules per region on Business and Enterprise. These are ready to use the moment your allocation is active.

Port Forwarding Add-On Packs

Expand capacity with add-on packs: Basic (5 ports), Standard (10), Advanced (25), and Power (50). Stack packs as your needs grow.

Track Your Usage

OrbVPN shows your port-forwarding limits at a glance, how many rules are included, how many come from add-on packs, how many are in use, and how many remain, so you always know your available headroom.


Creating a Port-Forward Rule

1

Open Your Allocation

In the Static IP screen, select the regional allocation where you want to forward a port. You will see its public IP and existing rules.

2

Add a New Rule

Tap Add Port Forward. Enter the external port (internet-facing) and the internal port (your device's service).

3

Pick the Protocol

Select TCP, UDP, or Both to match your service. Add an optional description so you remember what the rule is for.

4

Save and Wait for Active

Save the rule. OrbMesh provisions the DNAT mapping; when the status reads Active, your service is reachable at your Static IP and external port.

5

Test the Connection

From an external network, connect to your-static-ip:external-port. If it does not respond, confirm your device's service is running and listening on the internal port.


Common Use Cases

Home Server & NAS

Reach a self-hosted website, file server, or NAS from outside your home, all through the encrypted tunnel rather than exposing your router.

Game Hosting

Host a multiplayer game session that friends can join from anywhere using your Static IP and forwarded port.

Remote Cameras & IoT

Access security cameras, home automation hubs, and other IoT devices remotely without opening ports on your home router.

Remote Administration

Securely reach SSH or remote-desktop endpoints on your devices at a fixed, predictable address you control.


Security Best Practices

Port Forwarding opens a doorway to your device, so treat it with the same care as any public-facing service.

Forward Only What You Need

Create rules only for services you actively use, and disable or delete them when you no longer need remote access.

Secure the Service Itself

The tunnel protects traffic in transit, but the exposed service still needs strong authentication. Use good passwords, keys, and up-to-date software.

Use Non-Standard External Ports

Mapping an unusual external port to your standard internal port cuts down on automated scanning and brute-force noise.

Monitor and Review

Periodically review your active rules in the app. Remove any you no longer recognize or need to keep your attack surface minimal.

Your VPN Stays Protected

Port-forwarding rules apply only to your own dedicated Static IP and route exclusively to your device. They do not weaken OrbVPN's network or expose other users, each user's forwarded ports are isolated to their own allocation.

Reach Your Devices From Anywhere

Pair Port Forwarding with a Static IP to securely expose your home server, NAS, cameras, or game host through the encrypted OrbVPN tunnel.

Get OrbVPN