Skip to content

NAT VPS - how it works and limits

A NAT VPS is a Linux server without its own public IP. Traffic from the internet hits a shared host IP, and only a dedicated port block is forwarded into your machine.

NAT VPS vs regular VPS

VPS with public IP NAT VPS
Public address dedicated IP shared host IP
Ports usually the full range (1–65535) fixed block, e.g. 20 ports
SSH usually port 22 first port of your block (not 22)
Isolation separate VM / container container with hard resource caps

When NAT is enough

Great for panels, bots, small APIs, proxies, tests and apps that only need a few open ports. If you need the full port range or a dedicated IP, pick a classic VPS.

Ports and SSH access

After the server is created you get, among other things:

  • Host IP (public address you connect to)
  • Port block, e.g. 20040–20059 (20 ports)
  • root password (or a key, if configured)

Mapping is 1:1: IP:20040 → port 20040 inside your VPS, IP:20041 → 20041, and so on.

SSH

OpenSSH listens on the first port of the block, not on 22.

ssh root@YOUR.PUBLIC.IP -p FIRST_PORT

Example: block 20040–20059 → SSH on port 20040.

Guest firewall

If you enable ufw / firewalld inside the VPS, allow the same SSH port sshd uses (the first port of the block), not only 22.

More SSH clients: SSH login.

Your own services (HTTP, games, panels)

Run the service on a port from your block, or bind/proxy it there. From the internet you connect to:

YOUR.PUBLIC.IP:PORT_FROM_BLOCK

A port outside your block is not reachable from the internet.

Resource limits

Every NAT VPS has hard limits. You cannot use a neighbour’s or the host’s resources beyond your plan.

CPU

  • You get a core count such as 1 or 2.
  • Fractions are allowed, e.g. 0.5 (half a core), enforced with a hard CFS quota in Incus.
  • The guest may see pinned CPUs; real usage cannot exceed the allocation.

RAM

  • Limit in MiB (e.g. 256, 512, 1024).
  • When memory is exhausted, processes may be killed (OOM) - that is expected for a hard cap.

Disk

  • Rootfs size in GiB (e.g. 5, 10).
  • df shows the VPS quota, not the whole host disk.
  • Host block devices are hidden from the guest (lsblk does not list host disks).

Bandwidth (Mbps)

  • Link speed cap in both directions (ingress + egress), e.g. 50 or 100 Mbit.
  • This is instantaneous rate, not monthly volume.
  • 0 / unlimited in a plan means no hard rate cap (depending on the package).

Monthly transfer (GiB)

  • Cap on total traffic both ways (download + upload) in a UTC calendar month.
  • Example: 1024 GiB ≈ 1 TiB per month.
  • The counter resets at the start of the next UTC month.

When monthly transfer is exceeded

After the monthly quota is used up, the NIC is heavily throttled (to about 8 kbit/s) so a trickle of admin access (e.g. SSH) remains. Full speed returns at the next month or after the quota is raised in the plan / panel.

Isolation (short)

A NAT VPS runs as an unprivileged container with hard separation:

  • you only see your own CPU / RAM / disk / network within the limits
  • no access to other VPS on the same host (bridge isolation)
  • no access to the host SSH/API from inside the guest
  • no lateral move into the host’s private networks (Docker, etc.)

All containers share the host kernel - this is the LXC model, not a full virtual machine.

Example plan - what the numbers mean

Parameter Example Meaning
CPU 0.5 half core (hard cap)
RAM 256 MiB max memory
Disk 5 GiB rootfs
Bandwidth 50 Mbit max link speed
Traffic 100 GiB transfer / UTC month
Ports 20 e.g. 20040–20059, SSH = first

FAQ

Why can’t I open port 80 / 443 / 22?
Those ports must be inside your block. If your block is e.g. 20040–20059, expose the service on one of those ports.

Can I run Docker / nested containers?
Usually no - nesting and privileged mode are disabled for security.

Does a neighbour steal my CPU?
Not within your hard cap. You have your own limit; host overload can slow every guest, but it does not take away your allocated quota.

How do I check usage?
In the panel (when available) and inside the guest with htop / free -h / df -h. Monthly transfer is accounted on the platform from the VPS NIC counters.

Support

Access details and plan limits are in the AlfaHost panel. Connection or quota issues: support@alfahost.eu.