Back to articles
Technology Insight

Building a Private Tunneling Server (FRP/Chisel) to Publicize Services from Local to the Internet

April 17, 2026
Building a Private Tunneling Server with FRP and Chisel

Building a Private Tunneling Server (FRP/Chisel) to "Publicly" Expose Local Services to the Internet in 2026

During software development and managing a Home Lab, we often encounter a major hurdle: Internal servers sit behind the ISP's NAT layer without a static IP, making external access from the Internet impossible. Instead of using paid services like Ngrok with numerous limitations, building your own Tunneling Server on a personal VPS using FRP or Chisel is the most optimal, secure, and professional solution today.

1. What is Tunneling? Why do Developers and Labbers need it?

Tunneling is a technique that creates a secure "pipe" connecting a Local server (with no public IP) to a VPS (with a static public IP). When users access the VPS's IP, data is forwarded through this pipe directly to your home server.

  • Product Demos: You are running a NestJS web app on port 3000 at home but want distant clients to view it live via a professional domain name.
  • Remote Management: Access your Proxmox dashboard, Home Assistant, or SSH into your desktop from anywhere without risky Port Forwarding on your Modem.
  • Bypassing CGNAT: Most ISPs now use CGNAT, making traditional port forwarding nearly impossible.

// Data structure example simulating packet forwarding logic
interface TunnelPacket {
  originIp: string;
  vpsPort: number;
  localTargetIp: string;
  localPort: number;
  payload: string;
}

function forwardTraffic(packet: TunnelPacket): void {
  console.log(`Routing data from VPS:${packet.vpsPort} to Local:${packet.localPort}`);
  // Logic to establish a socket connection between VPS and Local Client
}

const webRequest: TunnelPacket = {
  originIp: "123.45.67.89",
  vpsPort: 8080,
  localTargetIp: "192.168.1.10",
  localPort: 3000,
  payload: "GET /index.html HTTP/1.1"
};

forwardTraffic(webRequest);
 

2. FRP (Fast Reverse Proxy) - The Top Choice for Performance

FRP is a powerful reverse proxy application that helps you publicly expose internal services to the internet quickly. FRP consists of two main components: frps (Server running on VPS) and frpc (Client running on Local machine).

2.1. Server-side Configuration (VPS)

On the VPS, you need to configure the frps.toml file to define the communication port for the Client (usually 7000) and the HTTP/HTTPS ports for public access.


// Simulating frps.toml configuration in a management system
interface FrpServerConfig {
  bindPort: number;        // Communication port between client and server
  vhostHttpPort: number;   // Public HTTP service port
  authMethod: "token";
  token: string;           // Security key to prevent unauthorized tunnel usage
}

const serverConfig: FrpServerConfig = {
  bindPort: 7000,
  vhostHttpPort: 80,
  authMethod: "token",
  token: "mySecretToken2026"
};

console.log(`FRP Server is listening on port: ${serverConfig.bindPort}`);
 

2.2. Client-side Configuration (Local Machine)

On your home computer, configure frpc.toml to specify which service you want to expose. For example: exposing a ReactJS app running on port 5173 to the internet via port 8080 of the VPS.


// Simulating frpc.toml configuration for a ReactJS app
interface FrpClientProxy {
  name: string;
  type: "tcp" | "udp" | "http";
  localIp: string;
  localPort: number;
  remotePort?: number;
}

const reactAppProxy: FrpClientProxy = {
  name: "react-web-demo",
  type: "tcp",
  localIp: "127.0.0.1",
  localPort: 5173,
  remotePort: 8080 // Accessed via VPS_IP:8080
};

console.log(`Initializing tunnel for service: ${reactAppProxy.name}`);
 

3. Chisel - Tunneling over HTTP/HTTPS

If your environment has extremely strict firewalls (only allowing ports 80 or 443), then Chisel is your secret weapon. Chisel encapsulates all tunnel data inside the HTTP protocol, making it easy to bypass Deep Packet Inspection (DPI) systems.

Chisel is particularly useful when you are at an office and want to access your Home Lab without IT blocking unusual ports.

Comparison Criteria FRP (Fast Reverse Proxy) Chisel (TCP over HTTP)
Speed Extremely fast, optimized for TCP/UDP Average (due to HTTP overhead)
Firewall Bypassing Quite good Excellent (Uses ports 80/443)
Complexity Requires detailed config files Quick to run via CLI

4. Security for Tunneling Servers: Prevention is Better than Cure

Exposing a local service to the internet means opening a door into your internal network. If not properly secured, hackers can exploit the tunnel to attack your home servers.

  • Token Authentication: Always use strong Tokens in FRP/Chisel configurations to prevent unauthorized connections.
  • Use TLS/SSL: Enable Transport Encryption to ensure data is not intercepted on its way from home to the VPS.
  • IP Whitelisting: If only demoing for a specific client, use the Firewall (UFW) on the VPS to only allow that client's IP to access the tunnel port.

// Security check function for tunnel connections
function validateTunnelConnection(clientToken: string, expectedToken: string, clientIp: string): boolean {
  const isAuthorized = clientToken === expectedToken;
  const isSafeIp = !["1.1.1.1", "8.8.8.8"].includes(clientIp); // Assuming blacklisted IPs
  
  if (isAuthorized && isSafeIp) {
    console.log(`Connection successful from: ${clientIp}`);
    return true;
  }
  console.error("Warning: Unauthorized access denied!");
  return false;
}

validateTunnelConnection("user_token_abc", "expected_token_123", "192.168.50.5");
 

5. Optimizing Latency for the Tunnel

Latency when accessing services via a tunnel depends on the physical distance between: User -> VPS -> Home Server. To optimize:

  1. Choose a Local VPS: If you are in Vietnam, pick a VPS in Hanoi or HCM City to minimize the ping between your home machine and the VPS.
  2. KCP Protocol: FRP supports the KCP protocol, which helps transfer data more smoothly on unstable networks (high packet loss).
  3. Data Compression: Enable use_compression = true to reduce bandwidth consumption.

6. Managing Tunnels with Docker and Dashboards

To keep the system running stably 24/7, you should deploy the FRP Server as a Docker Container. This helps automatically restart the tunnel if the VPS reboots or the application crashes.


// Docker Compose configuration example for FRP Server
const dockerComposeConfig = {
  version: "3",
  services: {
    frps: {
      image: "snowdreamtech/frps:latest",
      container_name: "frps-server",
      volumes: ["./frps.toml:/etc/frp/frps.toml"],
      ports: ["7000:7000", "80:80", "443:443"],
      restart: "always"
    }
  }
};

console.log("Ready to deploy FRP Server with Docker Compose");
 

7. Conclusion: Unlocking the Power of Your Home Lab

Building your own Private Tunneling Server not only helps you master the technology but also saves millions in annual costs for commercial tunnel services. With a cheap VPS and open-source tools like FRP or Chisel, your only limit is your creativity.

Checklist before going "Public":

  1. Is the Tunnel Password/Token complex enough?
  2. Is the Local service itself secured (Login/Auth)?
  3. Does the VPS have enough bandwidth for multiple users?
  4. Have you configured auto-start (Systemd/Docker) for both the Server and Client?

Hopefully, this guide helps you break through local network barriers, confidently demo products, and manage your Home Lab system like a pro!