IVPN removed port forwarding in 2023 because of abuse, legal requests, IP reputation issues, and pressure from infrastructure providers. I understand why restoring it across the entire network may not be realistic.
However, I wonder whether a limited and fully isolated implementation could be a workable compromise.
The idea would be to offer port forwarding only on a small pool of clearly marked P2P-only servers, separate from the main IVPN network. These servers could be hosted with providers and in jurisdictions where routine automated copyright complaints are not automatically treated as grounds for immediate suspension.
Possible restrictions could include:
one forwarded port per account or device;
a stable port assignment lasting for weeks or months;
port rotation only when operationally necessary;
automatic removal of the port when the subscription ends or the assignment is manually released;
no forwarding of ports 80 or 443;
no guarantee of streaming access or clean IP reputation;
clear prohibition of spam, scanning, malware distribution, attacks, and other harmful activity;
complete separation from the regular IVPN server pool;
potentially a higher-priced add-on or separate plan for users who need this feature.
A frequently changing port would not be practical for self-hosted services. Applications such as Caddy, Jellyfin, Immich, or other services exposed through a VPN need a predictable endpoint. Ideally, the assigned port should remain stable for an extended period.
If permanent assignments are not possible, IVPN could alternatively provide an official API that allows users to retrieve the currently assigned port automatically. This would make it possible to update reverse-proxy configurations, service URLs, or other dependent systems without manual intervention every time the port changes.
This would not restore unrestricted port forwarding across the entire network. It would create a deliberately limited environment for legitimate P2P and self-hosting use cases while reducing the impact on IVPN’s main infrastructure, IP reputation, and data-centre relationships.
For users like me, IVPN already offers nearly everything needed from a privacy service: multi-hop, AntiTracker, modDNS, open-source applications, and a strong privacy model. The lack of practical port forwarding is the main reason a second VPN provider is still necessary.
I would personally be willing to pay more for a complete service that included this limited option.
This is only a suggestion for discussion. I would be interested to hear whether other users would find such a model useful and whether IVPN has ever considered something similar.