A tunnel connects a domain you own to any server you run — on GreatHost or anywhere else. We terminate TLS, issue the certificate automatically and filter malicious traffic at the edge before a single request reaches your machine. No firewall changes, no exposing your real IP, no separate anti-DDoS bill.
No SSH into a load balancer, no manual certificates. Point, configure, done.
Add a CNAME record for your domain (or subdomain) pointing to control.greathost.es. Already got a domain? Perfect, you keep it.
Give us the IP and port where your app or server listens. We validate it, issue a free SSL certificate and wire up the routing automatically.
From then on, every request hits our edge first: rate limits, bot filtering and IP bans are applied before anything reaches your server.
If it speaks HTTP or HTTPS and listens on a port, a tunnel can put it online, safely, under your own domain.
Expose a service running on your home server, NAS or Raspberry Pi without opening ports on your router or leaking your home IP.
Give a Node, Python or any backend a real HTTPS domain to test webhooks, mobile app callbacks or third-party integrations properly.
Already renting a VPS somewhere else? Point a tunnel at it and get our anti-DDoS layer, analytics and free SSL without moving anything.
If your project has ever gone down from a flood of requests, this is exactly the problem tunnels solve: filtering happens before your server even sees the traffic.
Put a Pterodactyl panel, a bot dashboard or any internal tool behind a real domain, with an optional password gate on higher plans.
Share a clean, branded HTTPS link with a client or your team instead of an IP and a port number.
Every tunnel, even the cheapest one, gets real protection. Higher plans unlock more control and more history.
Per-IP request and connection limits stop floods before they can reach your app, tuned automatically to your protection level.
When traffic spikes look like an attack, "under-attack mode" kicks in on its own on Pro plans and above, tightening the rules until it settles.
Block specific IPs, CIDR ranges or entire countries yourself whenever you spot something you don't want reaching your server.
Requests, visitors, response times, status codes, countries, devices and browsers, all from the same pipeline that powers our own dashboards.
On Business and Enterprise, show your own branded page instead of a generic error whenever your destination is down for maintenance.
Lock a tunnel behind HTTP basic auth or restrict it to an allowlist of IPs, ideal for staging environments and internal tools.
One flat price per tunnel, billed monthly in coins. Upgrade, downgrade or cancel whenever you want.
Loading plans...
1 € ≈ 100 coins. Prices shown per tunnel, per 30-day period.
Still unsure about something? Here's what people usually ask before creating their first tunnel.
No. A tunnel just needs a public IP and port to reach your destination. It works with a GreatHost VPS, a server at home, a VPS from another provider, or anything else that can accept incoming HTTP/HTTPS connections.
You add a CNAME record (or an A record to the same IP) pointing your domain to control.greathost.es. We never touch the rest of your DNS zone, so your email, other subdomains and existing records are untouched.
Yes. We issue and renew a Let's Encrypt certificate automatically for every tunnel, at every plan level, at no extra cost.
Visitors get a clear error instead of a broken connection. On Business and Enterprise plans you can replace that default page with your own branded maintenance page.
Yes, from the tunnel's own management page. Tunnels are billed per 30-day period with no long-term contract, and you can pause, renew or delete a tunnel at any time.
A firewall protects your server once traffic already reaches it. A tunnel sits in front of your server at the network edge, so attack traffic is filtered before it ever gets close, and your real IP is never exposed publicly.
Create your first tunnel in a couple of minutes. Domain, IP, port and pick a plan — that's it.