NAT VPS - how it works and limits¶
A NAT VPS is a Linux server without its own public IP. Traffic from the internet hits a shared host IP, and only a dedicated port block is forwarded into your machine.
NAT VPS vs regular VPS¶
| VPS with public IP | NAT VPS | |
|---|---|---|
| Public address | dedicated IP | shared host IP |
| Ports | usually the full range (1–65535) | fixed block, e.g. 20 ports |
| SSH | usually port 22 |
first port of your block (not 22) |
| Isolation | separate VM / container | container with hard resource caps |
When NAT is enough
Great for panels, bots, small APIs, proxies, tests and apps that only need a few open ports. If you need the full port range or a dedicated IP, pick a classic VPS.
Ports and SSH access¶
After the server is created you get, among other things:
- Host IP (public address you connect to)
- Port block, e.g.
20040–20059(20 ports) - root password (or a key, if configured)
Mapping is 1:1: IP:20040 → port 20040 inside your VPS, IP:20041 → 20041, and so on.
SSH¶
OpenSSH listens on the first port of the block, not on 22.
Example: block 20040–20059 → SSH on port 20040.
Guest firewall
If you enable ufw / firewalld inside the VPS, allow the same SSH port sshd uses (the first port of the block), not only 22.
More SSH clients: SSH login.
Your own services (HTTP, games, panels)¶
Run the service on a port from your block, or bind/proxy it there. From the internet you connect to:
A port outside your block is not reachable from the internet.
Resource limits¶
Every NAT VPS has hard limits. You cannot use a neighbour’s or the host’s resources beyond your plan.
CPU¶
- You get a core count such as
1or2. - Fractions are allowed, e.g.
0.5(half a core), enforced with a hard CFS quota in Incus. - The guest may see pinned CPUs; real usage cannot exceed the allocation.
RAM¶
- Limit in MiB (e.g.
256,512,1024). - When memory is exhausted, processes may be killed (OOM) - that is expected for a hard cap.
Disk¶
- Rootfs size in GiB (e.g.
5,10). dfshows the VPS quota, not the whole host disk.- Host block devices are hidden from the guest (
lsblkdoes not list host disks).
Bandwidth (Mbps)¶
- Link speed cap in both directions (ingress + egress), e.g.
50or100Mbit. - This is instantaneous rate, not monthly volume.
0/ unlimited in a plan means no hard rate cap (depending on the package).
Monthly transfer (GiB)¶
- Cap on total traffic both ways (download + upload) in a UTC calendar month.
- Example:
1024 GiB≈ 1 TiB per month. - The counter resets at the start of the next UTC month.
When monthly transfer is exceeded
After the monthly quota is used up, the NIC is heavily throttled (to about 8 kbit/s) so a trickle of admin access (e.g. SSH) remains. Full speed returns at the next month or after the quota is raised in the plan / panel.
Isolation (short)¶
A NAT VPS runs as an unprivileged container with hard separation:
- you only see your own CPU / RAM / disk / network within the limits
- no access to other VPS on the same host (bridge isolation)
- no access to the host SSH/API from inside the guest
- no lateral move into the host’s private networks (Docker, etc.)
All containers share the host kernel - this is the LXC model, not a full virtual machine.
Example plan - what the numbers mean¶
| Parameter | Example | Meaning |
|---|---|---|
| CPU | 0.5 |
half core (hard cap) |
| RAM | 256 MiB |
max memory |
| Disk | 5 GiB |
rootfs |
| Bandwidth | 50 Mbit |
max link speed |
| Traffic | 100 GiB |
transfer / UTC month |
| Ports | 20 |
e.g. 20040–20059, SSH = first |
FAQ¶
Why can’t I open port 80 / 443 / 22?
Those ports must be inside your block. If your block is e.g. 20040–20059, expose the service on one of those ports.
Can I run Docker / nested containers?
Usually no - nesting and privileged mode are disabled for security.
Does a neighbour steal my CPU?
Not within your hard cap. You have your own limit; host overload can slow every guest, but it does not take away your allocated quota.
How do I check usage?
In the panel (when available) and inside the guest with htop / free -h / df -h. Monthly transfer is accounted on the platform from the VPS NIC counters.
Support¶
Access details and plan limits are in the AlfaHost panel. Connection or quota issues: support@alfahost.eu.