You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

无需配置路由器转发规则,借助OpenVPN实现通过AWS公网IP远程访问本地Web服务器的技术咨询

无需配置路由器转发规则,借助OpenVPN实现通过AWS公网IP远程访问本地Web服务器的技术咨询

Hey there! Let's break this down step by step since you already have your OpenVPN server on AWS up and running—great job getting that far!

First, let's clarify why just opening the port in AWS's firewall didn't work: that rule only lets external traffic reach your AWS server, but the server has no idea where to send that traffic next. Your local machine is connected to the AWS server via a VPN tunnel (in a private subnet), so we need to set up port forwarding on the AWS OpenVPN server to route those public port requests to your local client.

Here's how to set it up:

  • Find your local machine's VPN internal IP: After connecting to the OpenVPN server, check the IP assigned to your VPN adapter on your local machine, or run openvpn-status on your AWS server to see the list of connected clients and their IPs (it'll look something like 10.8.0.6—this is the private IP your client uses within the VPN).

  • Enable IP forwarding on the AWS server: This lets the server route traffic between the public internet and the VPN subnet. Edit /etc/sysctl.conf, uncomment the line net.ipv4.ip_forward=1, then run sysctl -p to apply the change immediately.

  • Add iptables port forwarding rules: Let's say you want to forward traffic from your AWS public IP's port 8080 to your local web server's port 80. Run these two commands:

    # Forward incoming public port 8080 traffic to your local client's port 80
    iptables -t nat -A PREROUTING -p tcp --dport 8080 -j DNAT --to-destination 10.8.0.6:80
    # Make sure return traffic can route back to the internet
    iptables -t nat -A POSTROUTING -p tcp -d 10.8.0.6 --dport 80 -j MASQUERADE
    

    To keep these rules after a server reboot:

    • For Ubuntu/Debian: Run iptables-save > /etc/iptables/rules.v4
    • For RHEL/CentOS (if using iptables instead of firewalld): Run service iptables save
  • Test it out: From an external network (not your local network), visit yourAwsPublicIp:8080—you should see your local web server's content!

Now, about how portmap.io works: It uses a reverse tunnel/remote port forwarding model. Your local machine initiates an outbound connection to portmap's servers, creating a persistent tunnel. When someone visits portmap's public IP and your assigned port, their traffic is sent through that pre-established tunnel to your local machine. This avoids needing router port forwarding because outbound connections are almost always allowed by default on home routers—no need to open inbound ports. The OpenVPN method we set up above follows a similar logic: your local client connects outbound to the AWS server, and the AWS server routes public traffic through that tunnel to you.

One quick note: If your client's VPN IP changes every time you connect, you can set up a fixed IP for your client in OpenVPN (using the client-config-dir directive on the server) or use a script that automatically updates the iptables rules when your client connects.

备注:内容来源于stack exchange,提问作者seriously

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.04.23 13:02:33