What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

FRP publishes a service behind NAT or a firewall by having a client on your local machine connect outward to a server with a public IP address. The public server runs frps; the machine beside your app runs frpc. Start with one TCP mapping: match the client’s serverPort to the server’s bindPort, point localPort at your service, and choose a public-side remotePort. FRP’s official project README describes support for TCP and UDP, HTTP and HTTPS routing by domain, and P2P mode; this guide keeps the first setup to TCP.

Understand which machine and port does what

You need a publicly reachable host and a machine on the network where the service runs. The public host relays connections; it does not need to run the app itself.

  • Public server (Server A): runs frps and is reachable from the internet.
  • LAN machine (Server B): runs frpc next to the service. The client makes an outbound connection to Server A.
  • Local service: the address and port frpc can reach on Server B, such as 127.0.0.1:22 for SSH.
  • Public proxy port: the port on Server A that outside clients use to reach the forwarded service.

There are three separate port values. The server’s bindPort is where frps accepts the client connection. The client’s serverPort must match it. The proxy’s localPort is the private service port, while remotePort is the public-side service port. The official SSH-over-TCP example uses 7000 for the client-to-server connection and 6000 for public SSH access.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Set up one TCP proxy first

Use the same FRP release for both machines and consult the configuration format and command options for that release. The official README says TOML, YAML, and JSON have been supported since v0.52.0; INI is deprecated and planned for removal, and new features are added only to TOML, YAML, or JSON. The snippets below use TOML, as do the project’s examples.

#1 Best Overall
Sale
ASUS RT-AX1800S Dual Band WiFi 6 Extendable Router, Subscription-Free Network Security, Parental Control, Built-in VPN, AiMesh Compatible, Gaming & Streaming, Smart Home
  • New-Gen WiFi Standard – WiFi 6(802.11ax) standard supporting MU-MIMO and OFDMA technology for better efficiency and throughput.Antenna : External antenna x 4. Processor : Dual-core (4 VPE). Power Supply : AC Input : 110V~240V(50~60Hz), DC Output : 12 V with max. 1.5A current.
  • Ultra-fast WiFi Speed – RT-AX1800S supports 1024-QAM for dramatically faster wireless connections
  • Increase Capacity and Efficiency – Supporting not only MU-MIMO but also OFDMA technique to efficiently allocate channels, communicate with multiple devices simultaneously
  • 5 Gigabit ports – One Gigabit WAN port and four Gigabit LAN ports, 10X faster than 100–Base T Ethernet.
  • Commercial-grade Security Anywhere – Protect your home network with AiProtection Classic, powered by Trend Micro. And when away from home, ASUS Instant Guard gives you a one-click secure VPN.

On the public server: configure frps

Save this as frps.toml on Server A:

bindPort = 7000

Allow inbound connections to port 7000 on the public server’s firewall and, if applicable, its hosting-provider security rules. This is the FRP client connection port, not the port the outside user will use for SSH.

On the LAN machine: configure frpc

Save this as frpc.toml on Server B. Replace PUBLIC_SERVER_IP with Server A’s public IP address. This example forwards SSH running on Server B at 127.0.0.1:22:

serverAddr = "PUBLIC_SERVER_IP"
serverPort = 7000

[[proxies]]
name = "ssh"
type = "tcp"
localIP = "127.0.0.1"
localPort = 22
remotePort = 6000

If your service listens on a different address or port, change localIP and localPort to an address reachable from Server B. Choose a remotePort that is permitted and unused on Server A.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #2
NETGEAR Nighthawk WiFi 6 Router R6700AX, Up to 1,500 sq ft, 1.8 Gbps
  • NIGHTHAWK WIFI 6 ROUTER FOR YOUR WHOLE HOME: Delivers fast, reliable WiFi across every room of your apartment or small home for streaming, gaming, video calls, and smart home devices, all running at the same time without slowing each other down.
  • WORKS WITH YOUR EXISTING INTERNET SERVICE: Pairs with your existing modem or gateway via ethernet. Compatible with most cable, fiber, DSL, and satellite providers. Some gateways and modem router combos may require bridge mode. No coax needed.
  • SET UP AND MANAGE YOUR NETWORK WITH THE NIGHTHAWK APP: Download the free Nighthawk app on iOS or Android for guided setup. Manage WiFi, run speed tests, pause devices, and set up guest networks from anywhere. Active internet required.
  • READY FOR THE DEVICES YOU ALREADY OWN: Your phones, laptops, and TVs work right out of the box. WiFi 6 delivers speeds up to 1.8 Gbps across 2.4 GHz and 5 GHz bands. Backward compatible with WiFi 5 and earlier.
  • COVERAGE IN EVERY ROOM: Covers up to 1,500 sq. ft. for up to 20 connected devices. Walls, floors, and interference can reduce range. Larger or multi-story homes may benefit from a NETGEAR Orbi mesh WiFi system.

Start both processes and connect

Following the official example’s command pattern, run the server on Server A and the client on Server B:

./frps -c ./frps.toml
./frpc -c ./frpc.toml

Then connect from an outside machine using the public server address and the proxy port:

ssh -p 6000 USER@PUBLIC_SERVER_IP

Replace USER with the account name on the SSH service. This command pattern is the project’s documented example, not a claim of hands-on testing here. Apply your service’s own access controls and adapt firewall rules to the host and provider; allow only the connection and proxy ports you need.

Rank #3
NETGEAR Nighthawk WiFi 6 Router (RAX36) – Router Only, AX3000 3 Gbps Wireless Speed – Dual-Band Gigabit Internet – Covers 2,000 sq. ft., 25 Devices – Built-in VPN, USB 3.0, Gaming
  • Coverage up to 2,000 sq. ft. for up to 25 devices
  • Ultrafast AX3000 speeds up to 3Gbps with WiFi 6 technology for uninterrupted streaming, HD video gaming, and web conferencing
  • This router does not include a built-in cable modem. A separate cable modem (with coax inputs) is required for internet service.
  • Connects to your existing cable modem and replaces your WiFi router. Compatible with any internet service provider up to 1Gbps including cable, satellite, fiber, and DSL
  • Plug in computers, game consoles, streaming players, and more with 4 x 1G Ethernet ports

Choose a TCP port or a domain-based web route

TCP with a remote port is the simplest starting point and works for SSH or another TCP service. The outside user needs the public server’s address and chosen port. HTTP or HTTPS hostname routing is useful when you want web services available at hostnames, especially when routing more than one service, but it adds DNS and virtual-host configuration.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Approach What outside users connect to Additional setup
TCP proxy Public IP or name plus the proxy’s remotePort Allow the selected public port through the server’s firewall and provider rules.
HTTP/HTTPS proxy A hostname that resolves to the public server Configure DNS, the matching client hostname, and the server’s HTTP or HTTPS virtual-host listener.

What domain routing requires

The official full frps example shows vhostHTTPPort and vhostHTTPSPort listeners and a subDomainHost setting for subdomain routing. The full frpc example shows HTTP proxies using customDomains or a subdomain, with a local web-service port. Point the hostname’s DNS records at Server A and make the hostname in the client proxy match the name requested by visitors. Allow the relevant public vhost ports through the server’s firewall.

Decide where TLS terminates before promising encrypted access to the application. FRP’s transport TLS settings concern the frpc-to-frps connection; they do not by themselves establish that every application connection is encrypted end to end or that the service is private. The project examples describe proxy and transport settings, but a certificate and termination arrangement depends on the web service and deployment.

Rank #4
Sale
AVID POWER Compact Wood Router Tool for Woodworking 630W 5.3 Amp, Trim Bits
  • Strong Motor, Power for Your Woodworks: With 630W 5.3 Amp motor, this trim router provides sufficient power & smooth operation for woodworking projects, no excessive vibration. Air vent prevents overheat and motor burnt-out during prolonged use. Replacement brushes for extended lifespan & consistent performance over time
  • High Speed & 3 Guide Modes for Efficient Woodworking: 35,000 RPM allow users to finish work pieces efficiently, with straight guide and roller gudie included, suitable for intricate detailed cutting, routing, slotting, grooving and trimming door hinges, etc.
  • Precise Depth Adjustments & Secure Fixed Base: This hand router features smooth depth adjustment system for precise height setting. Secure fix base ensures stable fine positioning for intricate cuts during routing
  • Collet, Router Bits & Accessories Included, Easy to Install: Palm router includes 1/4” collet and 5pcs 1/4 shank router bits, edge & roller router guide. It’s easy to change router bit with 2 wrenches
  • Ergonomic & Comfortable to Use: Rubber handheld router base secures grip. Corded electric and lightweight design enhances flexibility

Secure the tunnel and limit exposure

Match authentication on both sides

The project README documents token authentication as the default and requires the client and server authentication settings to match. Configure a strong, unique secret on both sides, and keep the real value out of public configuration examples. File-based token sourcing and OIDC client credentials are also documented alternatives; use the version-specific README if you need those options.

Understand what transport TLS does

The README says transport TLS is enabled by default since v0.50.0 through the transport.tls.enable and transport.tls.disableCustomTLSFirstByte settings. It also documents transport.tls.force = true as an optional server setting to accept only TLS connections. These settings protect the FRP transport connection; they are not a substitute for authentication at the exposed service.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Restrict ports and protect administration

Expose only the ports required for your proxy. The allowPorts setting in the full server example can restrict which ports clients may bind. That example also binds its dashboard to localhost and contains example credentials; do not expose an administrative dashboard publicly with default credentials.

Best Value
TEMO Solid Carbide Fiberglass Router Bit w 1/4" Shank and 3/4" Cutting Head
  • Solid Carbide Fiberglass Router Bit
  • Excellent for cutting through fiberglass, carbon fiber, fiber cement, drywall, resin, FRP, GRP, and other composite materials
  • 135 degree cutting point
  • 2" total length, 3/4" long cutting head 1/4" diameter shank
  • US-BASED CUSTOMER SERVICE: Available by chat, email, phone, or visit us at our customer service center in La Crosse, WI.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Verify the configuration before expanding it

Check the client configuration before attempting to add more proxies. The project README documents:

frpc verify -c ./frpc.toml

It also documents frpc status -c ./frpc.toml for proxy status; retrieving status requires the client web API to be enabled as described in the README. Check the command options for your installed release, and read both client and server logs if the connection does not come up.

Avoid copying a full example file wholesale: the official full frps example is labeled as a reference and warns that using it directly may cause issues. Extract only settings you need and confirm they apply to your installed version.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Troubleshoot in the order traffic travels

  1. Check Server A first. Confirm frps is running and its bindPort is reachable from the internet. Check both the host firewall and any provider security rules.
  2. Check the client’s destination. Confirm serverAddr resolves to the intended public host and serverPort matches Server A’s bindPort.
  3. Test the private service locally. From Server B, confirm the service is listening at the localIP and localPort in the proxy configuration.
  4. Check the public proxy port. Confirm remotePort is allowed, is not already occupied on Server A, and is permitted by any allowPorts restriction.
  5. Check authentication. Verify both files use matching authentication configuration and the same token if token authentication is configured.
  6. For HTTP or HTTPS, check routing details. Confirm DNS points to Server A, the appropriate vhost listener is configured, and the hostname in the client proxy matches the hostname requested by the visitor.
  7. Verify, inspect status, and read logs. Use the documented verification and status commands where applicable; inspect both sides’ logs before adding settings or more proxies.

If antivirus software quarantines frpc, the project README warns that some products may mistakenly flag it because reverse-proxy tools can bypass firewall port restrictions. Treat a warning carefully: obtain the binary from the official project release source and verify that it is the expected file rather than disabling protections broadly.

What you need if you do not already have a public host

The basic topology requires an internet-reachable machine running frps. A VPS is one possible way to get such a host, but existing public infrastructure can serve the role too. A domain is optional for the basic TCP setup and useful for HTTP/HTTPS hostname routing. FRP itself is software; the documented setup does not require a specific computer, router, or other physical product.

Quick Recap

Bestseller No. 3
NETGEAR Nighthawk WiFi 6 Router (RAX36) – Router Only, AX3000 3 Gbps Wireless Speed – Dual-Band Gigabit Internet – Covers 2,000 sq. ft., 25 Devices – Built-in VPN, USB 3.0, Gaming
NETGEAR Nighthawk WiFi 6 Router (RAX36) – Router Only, AX3000 3 Gbps Wireless Speed – Dual-Band Gigabit Internet – Covers 2,000 sq. ft., 25 Devices – Built-in VPN, USB 3.0, Gaming
Coverage up to 2,000 sq. ft. for up to 25 devices; Plug in computers, game consoles, streaming players, and more with 4 x 1G Ethernet ports
$99.99
Bestseller No. 5
TEMO Solid Carbide Fiberglass Router Bit w 1/4' Shank and 3/4' Cutting Head
TEMO Solid Carbide Fiberglass Router Bit w 1/4" Shank and 3/4" Cutting Head
Solid Carbide Fiberglass Router Bit; 135 degree cutting point; 2" total length, 3/4" long cutting head 1/4" diameter shank
$18.99

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.