# How to for self hosting behind NAT?

**URL:** <https://openziti.discourse.group/t/how-to-for-self-hosting-behind-nat/5255>\
**Category:** General Questions\
**Created:** [October 20, 2025, 11:34am UTC](https://openziti.discourse.group/t/how-to-for-self-hosting-behind-nat/5255 "2025-10-20T11:34:04Z")\
**Posts on this page:** 1\
**Showing post:** 7

<div class="post-metadata">

**Author:** ![ZerotrustExplorer](https://avatars.discourse-cdn.com/v4/letter/z/f9ae1b/32.png) [@ZerotrustExplorer](https://openziti.discourse.group/u/ZerotrustExplorer)\
**Post date:** [October 20, 2025, 7:24pm UTC](https://openziti.discourse.group/t/how-to-for-self-hosting-behind-nat/5255/7 "2025-10-20T19:24:52Z")

</div>

So am trying with the below:

VM IP: 192.168.1.250

/etc/hosts on the VM:

mydomainname.tld \<WAN\_ADDRESS\>

.env:  
ZITI\_IMAGE=openziti/quickstart  
ZITI\_VERSION=latest  
ZITI\_CONTROLLER\_RAWNAME=ziti-controller

ZITI\_CTRL\_PORT=8440  
ZITI\_EDGE\_CONTROLLER\_PORT=8441  
ZITI\_EDGE\_ROUTER\_PORT=8442  
ZITI\_EDGE\_ROUTER\_LISTENER\_BIND\_PORT=10080  
ZITI\_ZAC\_PORTTLS=8443

EXTERNAL\_DNS=mydomainname.tld  
ZITI\_NETWORK\_NAME=${EXTERNAL\_DNS}  
ZITI\_CONTROLLER\_HOSTNAME=${EXTERNAL\_DNS}

ZITI\_EDGE\_ROUTER\_RAWNAME=${EXTERNAL\_DNS}  
ZITI\_EDGE\_ROUTER\_DESIRED\_RAWNAME=${EXTERNAL\_DNS}  
ZITI\_EDGE\_ROUTER\_HOSTNAME=${EXTERNAL\_DNS}

ZITI\_EDGE\_ROUTER\_ROLES=public

docker-compose-yaml from: [Connect Desktop Tunneler to Docker Quickstart on seperate host - #3 by TheLumberjack](https://openziti.discourse.group/t/connect-desktop-tunneler-to-docker-quickstart-on-seperate-host/1191/3)

router port forwards:

incoming on WAN ADDRESS: 8440 - 8442 TCP to 192.168.250

incoming on WAN ADDRESS: 6262 TCP to 192.168.250

incoming on WAN ADDRESS:10080 TCP to 192.168.250

I can use nginx to reverse proxy zac so am not including 8443 here.

I would use things like SNI but I already am using mydomainname.tld for a webserver, on nginx and pihole I specify hostnames.

On running docker-compose up it remains stuck at:

ziti-console-1 | waiting for server key to exist...  
ziti-edge-router-1 | [25.387] ERROR ziti/router/env.(\*networkControllers).connectToControllerWithBackoff.func2: {error=[error connecting ctrl (dial tcp \<WAN\_ADDRESS\>:6262: i/o timeout)] endpoint=[tls:ziti:6262  
]} unable to connect controller

Not sure how to proceed.

---

_[View the full topic](https://openziti.discourse.group/t/how-to-for-self-hosting-behind-nat/5255)._
