iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more
FRP publishes a service behind NAT or a firewall by having a client on your local machine connect outward to a server with a public IP address. The public server runs frps; the machine beside your app runs frpc. Start with one TCP mapping: match the client’s serverPort to the server’s bindPort, point localPort at your service, and choose a public-side remotePort. FRP’s official project README describes support for TCP and UDP, HTTP and HTTPS routing by domain, and P2P mode; this guide keeps the first setup to TCP.
Understand which machine and port does what
You need a publicly reachable host and a machine on the network where the service runs. The public host relays connections; it does not need to run the app itself.
- Public server (Server A): runs
frpsand is reachable from the internet. - LAN machine (Server B): runs
frpcnext to the service. The client makes an outbound connection to Server A. - Local service: the address and port
frpccan reach on Server B, such as127.0.0.1:22for SSH. - Public proxy port: the port on Server A that outside clients use to reach the forwarded service.
There are three separate port values. The server’s bindPort is where frps accepts the client connection. The client’s serverPort must match it. The proxy’s localPort is the private service port, while remotePort is the public-side service port. The official SSH-over-TCP example uses 7000 for the client-to-server connection and 6000 for public SSH access.
Set up one TCP proxy first
Use the same FRP release for both machines and consult the configuration format and command options for that release. The official README says TOML, YAML, and JSON have been supported since v0.52.0; INI is deprecated and planned for removal, and new features are added only to TOML, YAML, or JSON. The snippets below use TOML, as do the project’s examples.
#1 Best Overall
- New-Gen WiFi Standard – WiFi 6(802.11ax) standard supporting MU-MIMO and OFDMA technology for better efficiency and throughput.Antenna : External antenna x 4. Processor : Dual-core (4 VPE). Power Supply : AC Input : 110V~240V(50~60Hz), DC Output : 12 V with max. 1.5A current.
- Ultra-fast WiFi Speed – RT-AX1800S supports 1024-QAM for dramatically faster wireless connections
- Increase Capacity and Efficiency – Supporting not only MU-MIMO but also OFDMA technique to efficiently allocate channels, communicate with multiple devices simultaneously
- 5 Gigabit ports – One Gigabit WAN port and four Gigabit LAN ports, 10X faster than 100–Base T Ethernet.
- Commercial-grade Security Anywhere – Protect your home network with AiProtection Classic, powered by Trend Micro. And when away from home, ASUS Instant Guard gives you a one-click secure VPN.
On the public server: configure frps
Save this as frps.toml on Server A:
bindPort = 7000
Allow inbound connections to port 7000 on the public server’s firewall and, if applicable, its hosting-provider security rules. This is the FRP client connection port, not the port the outside user will use for SSH.
On the LAN machine: configure frpc
Save this as frpc.toml on Server B. Replace PUBLIC_SERVER_IP with Server A’s public IP address. This example forwards SSH running on Server B at 127.0.0.1:22:
serverAddr = "PUBLIC_SERVER_IP"
serverPort = 7000
[[proxies]]
name = "ssh"
type = "tcp"
localIP = "127.0.0.1"
localPort = 22
remotePort = 6000
If your service listens on a different address or port, change localIP and localPort to an address reachable from Server B. Choose a remotePort that is permitted and unused on Server A.
Quick wins for a faster PC:
Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Clear out junk files and repair common Windows errorsFree Scan →Scan for outdated or missing drivers - takes under a minuteDriver Scan →Rank #2
- NIGHTHAWK WIFI 6 ROUTER FOR YOUR WHOLE HOME: Delivers fast, reliable WiFi across every room of your apartment or small home for streaming, gaming, video calls, and smart home devices, all running at the same time without slowing each other down.
- WORKS WITH YOUR EXISTING INTERNET SERVICE: Pairs with your existing modem or gateway via ethernet. Compatible with most cable, fiber, DSL, and satellite providers. Some gateways and modem router combos may require bridge mode. No coax needed.
- SET UP AND MANAGE YOUR NETWORK WITH THE NIGHTHAWK APP: Download the free Nighthawk app on iOS or Android for guided setup. Manage WiFi, run speed tests, pause devices, and set up guest networks from anywhere. Active internet required.
- READY FOR THE DEVICES YOU ALREADY OWN: Your phones, laptops, and TVs work right out of the box. WiFi 6 delivers speeds up to 1.8 Gbps across 2.4 GHz and 5 GHz bands. Backward compatible with WiFi 5 and earlier.
- COVERAGE IN EVERY ROOM: Covers up to 1,500 sq. ft. for up to 20 connected devices. Walls, floors, and interference can reduce range. Larger or multi-story homes may benefit from a NETGEAR Orbi mesh WiFi system.
Start both processes and connect
Following the official example’s command pattern, run the server on Server A and the client on Server B:
./frps -c ./frps.toml
./frpc -c ./frpc.toml
Then connect from an outside machine using the public server address and the proxy port:
ssh -p 6000 USER@PUBLIC_SERVER_IP
Replace USER with the account name on the SSH service. This command pattern is the project’s documented example, not a claim of hands-on testing here. Apply your service’s own access controls and adapt firewall rules to the host and provider; allow only the connection and proxy ports you need.
Rank #3
- Coverage up to 2,000 sq. ft. for up to 25 devices
- Ultrafast AX3000 speeds up to 3Gbps with WiFi 6 technology for uninterrupted streaming, HD video gaming, and web conferencing
- This router does not include a built-in cable modem. A separate cable modem (with coax inputs) is required for internet service.
- Connects to your existing cable modem and replaces your WiFi router. Compatible with any internet service provider up to 1Gbps including cable, satellite, fiber, and DSL
- Plug in computers, game consoles, streaming players, and more with 4 x 1G Ethernet ports
Choose a TCP port or a domain-based web route
TCP with a remote port is the simplest starting point and works for SSH or another TCP service. The outside user needs the public server’s address and chosen port. HTTP or HTTPS hostname routing is useful when you want web services available at hostnames, especially when routing more than one service, but it adds DNS and virtual-host configuration.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
| Approach | What outside users connect to | Additional setup |
|---|---|---|
| TCP proxy | Public IP or name plus the proxy’s remotePort |
Allow the selected public port through the server’s firewall and provider rules. |
| HTTP/HTTPS proxy | A hostname that resolves to the public server | Configure DNS, the matching client hostname, and the server’s HTTP or HTTPS virtual-host listener. |
What domain routing requires
The official full frps example shows vhostHTTPPort and vhostHTTPSPort listeners and a subDomainHost setting for subdomain routing. The full frpc example shows HTTP proxies using customDomains or a subdomain, with a local web-service port. Point the hostname’s DNS records at Server A and make the hostname in the client proxy match the name requested by visitors. Allow the relevant public vhost ports through the server’s firewall.
Decide where TLS terminates before promising encrypted access to the application. FRP’s transport TLS settings concern the frpc-to-frps connection; they do not by themselves establish that every application connection is encrypted end to end or that the service is private. The project examples describe proxy and transport settings, but a certificate and termination arrangement depends on the web service and deployment.
Rank #4
- Strong Motor, Power for Your Woodworks: With 630W 5.3 Amp motor, this trim router provides sufficient power & smooth operation for woodworking projects, no excessive vibration. Air vent prevents overheat and motor burnt-out during prolonged use. Replacement brushes for extended lifespan & consistent performance over time
- High Speed & 3 Guide Modes for Efficient Woodworking: 35,000 RPM allow users to finish work pieces efficiently, with straight guide and roller gudie included, suitable for intricate detailed cutting, routing, slotting, grooving and trimming door hinges, etc.
- Precise Depth Adjustments & Secure Fixed Base: This hand router features smooth depth adjustment system for precise height setting. Secure fix base ensures stable fine positioning for intricate cuts during routing
- Collet, Router Bits & Accessories Included, Easy to Install: Palm router includes 1/4” collet and 5pcs 1/4 shank router bits, edge & roller router guide. It’s easy to change router bit with 2 wrenches
- Ergonomic & Comfortable to Use: Rubber handheld router base secures grip. Corded electric and lightweight design enhances flexibility
Secure the tunnel and limit exposure
Match authentication on both sides
The project README documents token authentication as the default and requires the client and server authentication settings to match. Configure a strong, unique secret on both sides, and keep the real value out of public configuration examples. File-based token sourcing and OIDC client credentials are also documented alternatives; use the version-specific README if you need those options.
Understand what transport TLS does
The README says transport TLS is enabled by default since v0.50.0 through the transport.tls.enable and transport.tls.disableCustomTLSFirstByte settings. It also documents transport.tls.force = true as an optional server setting to accept only TLS connections. These settings protect the FRP transport connection; they are not a substitute for authentication at the exposed service.
Restrict ports and protect administration
Expose only the ports required for your proxy. The allowPorts setting in the full server example can restrict which ports clients may bind. That example also binds its dashboard to localhost and contains example credentials; do not expose an administrative dashboard publicly with default credentials.
Best Value
- Solid Carbide Fiberglass Router Bit
- Excellent for cutting through fiberglass, carbon fiber, fiber cement, drywall, resin, FRP, GRP, and other composite materials
- 135 degree cutting point
- 2" total length, 3/4" long cutting head 1/4" diameter shank
- US-BASED CUSTOMER SERVICE: Available by chat, email, phone, or visit us at our customer service center in La Crosse, WI.
Verify the configuration before expanding it
Check the client configuration before attempting to add more proxies. The project README documents:
frpc verify -c ./frpc.toml
It also documents frpc status -c ./frpc.toml for proxy status; retrieving status requires the client web API to be enabled as described in the README. Check the command options for your installed release, and read both client and server logs if the connection does not come up.
Avoid copying a full example file wholesale: the official full frps example is labeled as a reference and warns that using it directly may cause issues. Extract only settings you need and confirm they apply to your installed version.
PC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Crashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minuteTroubleshoot in the order traffic travels
- Check Server A first. Confirm
frpsis running and itsbindPortis reachable from the internet. Check both the host firewall and any provider security rules. - Check the client’s destination. Confirm
serverAddrresolves to the intended public host andserverPortmatches Server A’sbindPort. - Test the private service locally. From Server B, confirm the service is listening at the
localIPandlocalPortin the proxy configuration. - Check the public proxy port. Confirm
remotePortis allowed, is not already occupied on Server A, and is permitted by anyallowPortsrestriction. - Check authentication. Verify both files use matching authentication configuration and the same token if token authentication is configured.
- For HTTP or HTTPS, check routing details. Confirm DNS points to Server A, the appropriate vhost listener is configured, and the hostname in the client proxy matches the hostname requested by the visitor.
- Verify, inspect status, and read logs. Use the documented verification and status commands where applicable; inspect both sides’ logs before adding settings or more proxies.
If antivirus software quarantines frpc, the project README warns that some products may mistakenly flag it because reverse-proxy tools can bypass firewall port restrictions. Treat a warning carefully: obtain the binary from the official project release source and verify that it is the expected file rather than disabling protections broadly.
What you need if you do not already have a public host
The basic topology requires an internet-reachable machine running frps. A VPS is one possible way to get such a host, but existing public infrastructure can serve the role too. A domain is optional for the basic TCP setup and useful for HTTP/HTTPS hostname routing. FRP itself is software; the documented setup does not require a specific computer, router, or other physical product.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

