frp: Expose Services Behind NAT With a Fast Reverse Proxy Tunnel

frp: Expose Services Behind NAT With a Fast Reverse Proxy Tunnel

frp (“fast reverse proxy”) solves a common self-hosting problem: your server is at home behind NAT or carrier-grade NAT (CGNAT), so you cannot open ports to it. With frp, a small client at home connects outward to a server you rent with a public IP, and that server forwards traffic back through the tunnel.

It is one of the most-starred networking projects on GitHub.

How it works

ComponentRuns onJob
frpsA VPS with a public IPAccepts tunnels and public traffic
frpcYour home serverConnects out to frps and forwards traffic to local services

Because frpc connects outward, no inbound ports are needed at home.

Protocols

  • TCP and UDP port forwarding (SSH, game servers, WireGuard)
  • HTTP and HTTPS with virtual hosts, so many sites share one public IP
  • STCP (secret TCP): only clients with the shared secret can connect, nothing is publicly exposed
  • XTCP: peer-to-peer connections with NAT hole punching, falling back when not possible
  • Encryption, compression, load balancing, health checks, and a dashboard

Configuration

Configuration uses TOML (YAML and JSON also work; the old INI format is deprecated). A minimal pair:

# frps.toml (on the VPS)
bindPort = 7000
auth.token = "change-me-long-random"
# frpc.toml (at home)
serverAddr = "vps.example.com"
serverPort = 7000
auth.token = "change-me-long-random"

[[proxies]]
name = "ssh"
type = "tcp"
localIP = "127.0.0.1"
localPort = 22
remotePort = 6000

Always set an auth token, and only expose what you need: a public TCP port is reachable by the whole internet. For web services, terminate HTTPS with a reverse proxy, and prefer STCP or a VPN for anything administrative. Run both sides as systemd services.

frp or the alternatives?

frp is the simplest choice when you have a VPS and want full control over raw port forwarding.

License

Apache License 2.0.