I'm just here to say I understood maybe 40% of this thread and I'm somehow running a mail server. The bakery pays for it. Portland internet is expensive enough without me breaking things.
NAT VPS port forwarding: my provider's panel vs manual iptables
Tabs vs spaces started my divorce and NAT panel sync started my second one. I use Hetzner now, no NAT nonsense, IPv4 included at 4.51 EUR. Nuremberg latency to Kyiv is 35ms, acceptable.
This.
They don't need to. I'm talking about scheduled maintenance windows, node retirement, the host that catches fire in St. Louis. Your systemd unit restarts fine, sure, until they change the internal bridge subnet from 10.0.0.0/24 to 10.0.1.0/24 and your DNAT points to a ghost.
I've had three emails about "network improvements" this year. Each time the internal addressing shifted.
How much is Hetzner cloud these days? I need something in EU for a game server, NAT or not.
CX11 is 4.51 EUR, 1 vCPU 2GB RAM 20GB NVMe, one IPv4 included. No NAT games. They have Falkenstein, Nuremberg, Helsinki, Hillsboro. I use Falkenstein for EU and Hillsboro for backup.
Update: the JSON edit work for 2 days then Contabo panel overwrite with empty array. I think their API push from central server every few hour. Back to iptables + systemd unit lah, at least reliable.
This is why I say WireGuard. No port forward, no panel, no problem. My clients connect to Buenos Aires server, I forward traffic to Contabo VPS behind NAT. One stable endpoint, the IPv4 price no matter.