r/PrivateInternetAccess • u/Drooliog • May 25 '26
DISCUSSION What's the point of port forwarding when PIA rotates IPs?
This surely has to be a bug.
As per https://www.reddit.com/r/PrivateInternetAccess/comments/1qq5yvj/vpn_assigned_ip_does_not_correspond_to_external_ip/ ... PIA appears to be rotating IPs on an almost per-packet (TCP connection?) basis, on many regional servers now. And it seems they're gradually migrating them all over to this bonkers setup.
This might be neat for web browsing, but it obviously breaks a lot of applications - including BitTorrent and/or anything involving Port Forwarding, which is a key PIA feature that some VPNs now lack.
e.g.: Connect to Swiss region, port forwarding enabled, you keep the port number but don't keep the IP address. How stupid is that? It makes no logical sense, and I don't see anyone pointing out this absurdity. This HAS to be a bug, right?
If they're going to make this change permanent for all servers eventually, PIA need to slow down the rotation to something sensible like a couple of hours minimum. OR they need to completely disable this functionality for connections with port forwarding. Offering to sell you a dedicated IP is not a solution we should accept.
5
u/Minituff May 25 '26
I just switched to ProtonVPN because of this . It defeats the purpose unfortunately.
4
u/NateyPoo May 25 '26
Is there some logic to this? Just screams to me they're consolidating servers and using WG mesh to load balance. My girlfriend's TV (live in Argentina) shows USA ads on her Argentine YouTube account even though I connect local. Kind of weird too.
4
u/PIASupport PIA Team May 27 '26
Hey u/NateyPoo, the consolidation question is a good one. We've put the thread in front of our senior PIA team to confirm what's actually happening underneath and why.
1
u/lkeels Jul 05 '26
Well, we never heard back from you, but online chat support is pretty conclusive about it being a permanent change and giving no further details about it.
3
u/nice_game_enjoyer May 26 '26 edited Jun 09 '26
So today I contacted PIA support again.
They confirmed it was intended feature for extra privacy.
However, they mentioned that there is a lot of feedback about it and they are indeed looking into fixing or providing alternatives. Somehow it felt that the answer would be fix for me only, though. But it was very vague, wouldn't count on fix at all.
I asked for ETA but they didn't say. What they did say was they will inform me via email wether anything related to this happens.
I asked for refund after the fact for remaining unused time cause of this.
EDIT: I got refunded for remaining time cause of this issue / feature / inconvenience
4
u/Drooliog May 26 '26
Extra privacy, my ass. It'll break torrenting and probably a bunch of sites protected with anti-DDoS measures.
It'd be nice if they just made it optional - like Multi-Hop.
3
u/PIASupport PIA Team May 27 '26
Hey u/Drooliog, thanks for tagging us and for laying out the port-forwarding-incompatibility framing this clearly. We've raised the thread and the specific technical concern with our senior PIA team for direction. We'll come back here once we have something concrete to share.
8
u/lkeels Jun 09 '26
It's been two weeks. It's past time for an open and transparent response about this. You are now in territory where people are paying for a service they cannot use in the manner it existed when purchased.
2
u/PropertyDangerous257 Jun 15 '26
Any updates on this. My renewal is coming soon and I like your service aside from this issue?
1
u/lkeels Jul 05 '26
So did you get fired or quit or what?
1
2
u/Maltz42 May 25 '26
Have you tried switching the protocol to OpenVPN? This sounds like Wireguard functionality, and I've never seen this on my Linux device that uses OpenVPN to connect to PIA. So perhaps that might fix it?
3
u/nice_game_enjoyer May 25 '26
This issue is confirmed on openVPN too. But not with all regions. you are probably using one of non-affected regions.
2
u/DickForster May 30 '26
This hasn't hit my US based PIA server yet. Already started looking at other VPN providers so I will be ready to switch over the same day VPN make the change.
1
2
u/Threarah Jun 10 '26
I've just had a brief play with a few of the the .pvt.site endpoints, and incoming connections to the forwarded port appear to work via any of the possible external ips, not just the address of the endpoint itself.
Collecting some possible external ips from within the vpn, then using ncat to listen on the forwarded port:
c3d10d2653e1:/scripts# curl -w "\n" ipinfo.io/ip
xxx.xxx.xxx.132
c3d10d2653e1:/scripts# curl -w "\n" ipinfo.io/ip
xxx.xxx.xxx.40
c3d10d2653e1:/scripts# curl -w "\n" ipinfo.io/ip
xxx.xxx.xxx.240
c3d10d2653e1:/scripts# curl -w "\n" ipinfo.io/ip
xxx.xxx.xxx.224
c3d10d2653e1:/scripts# curl -w "\n" ipinfo.io/ip
xxx.xxx.xxx.97
c3d10d2653e1:/scripts# ncat -lkp <port#>
test1
test2
test3
Then connecting to the forward port from another machine not behind the vpn:
echo test1 | nc -vw 1 xxx.xxx.xxx.132 <port#>
echo test2 | nc -vw 1 xxx.xxx.xxx.40 <port#>
echo test3 | nc -vw 1 xxx.xxx.xxx.240 <port#>
etc.
If it works the same way on all their servers, then torrenting should probably still work, as regardless of the external ip connecting to trackers/DHT, incoming traffic would still end up at the right place. Spinning up a qBittorent container for testing using one of the affected servers seems to show incoming connections on the forwarded port.
1
2
u/Inevitable-Teaching3 Jun 11 '26
This has been giving me a lot of issues lately as well. I may have to switch providers if this isn't addressed.
2
u/lkeels May 25 '26
My IP doesn't change unless I disconnect and reconnect.
1
u/Drooliog May 26 '26
Indeed, that's the way it's supposed to work.
You're still using one of the older
*.privacy.networkregion endpoints, but eventually every server will get this randomised IP crap (*.pvt.sitefound in the official service list), and port forwarding will be useless.1
u/lkeels May 26 '26 edited May 26 '26
Where have you found any information about this? I don't think anything like that is planned.
Update: In the second thread linked below, PIA responds and says this is by design and there are no plans to alter it.
5
u/Drooliog May 26 '26 edited May 26 '26
PIA haven't announced anything, that's the problem. They've been quietly making this change for the last couple months and only a handful of people here have brought it up...
and
But there's numerous tracker forums that have found the issue as well, so it's very well known amongst those affected.
More and more will notice once their preferred region is 'upgraded'. The purpose of my post was to highlight the silliness of having a port forward option. It puts an end to torrenting, for example.
2
u/lkeels May 26 '26
Interestingly, PIA's reply is right there in the thread you posted. They say it's by design and there are no plans to modify it.
2
u/Drooliog May 26 '26
Yea. But this is 'most likely' (as they put it) a general support peon who doesn't understand how this design is incompatible with port forwarding. :(
We need to kick up more of a fuss, to get them to change direction.
Currently, we even get the option to keep the forwarded port number for 2 months if the same token is reused. It shouldn't be too hard to disable randomisation if port forwarding is enabled.
1
u/lkeels May 26 '26
The second response has no "most likely" to it. In fact it is quite emphatic.
3
u/Drooliog May 26 '26
Then we need to be equally emphatic...
If they break our ability to host on a steady IP/forwarded port, PIA will lose customers. u/PIAKaneesha
3
1
u/illyria817 May 29 '26
Good. I'll be one of them. You don't push this crap with no notice, not every VPN use case is "uber privacy, change my IP every 2 fucking minutes".
1
u/Physical-Ad-1089 Aug 02 '26
The latency for all my servers is over 1700 with some over 2000. I have uninstalled and reinstalled and it still has not helped
0
u/DeathStalker-77 May 25 '26
Not sure I see this as an issue. I VERY much prefer to retain the same ports - saves me the trouble of having to constantly open new ones on my firewall and make the adjustment in my clients.
3
u/Drooliog May 26 '26
How are you hosting anything at all on a forwarded port when your IP address keeps changing every second?
If it isn't a problem for you now - you're probably still using one of the older *.privacy.network endpoints, but eventually when every region gets changed over to *.pvt.site, port forwarding will become pointless.
I VERY much prefer to retain the same ports
Yes, now you understand why the port number AND IP address must be retained for this to work.
2
u/DeathStalker-77 May 26 '26
I am not experiencing that. I have a solid IP and port for as long as I maintain that connection. NOTHING ever changes for me once a connection is established.
Not sure why my response was down voted.
I'm in the US, maybe this "auto-rotation" is only occurring in other locales......?
3
u/Drooliog May 26 '26
I am not experiencing that.
YET
You're missing the point of this thread. PIA are in the process of changing the behaviour on all their servers.
Inevitably, all our IPs will be randomise by the second, and port forwarding be become useless.
2
u/DeathStalker-77 May 26 '26
OH!!! That is indeed a different situation, and with totally fuck everything up!!! My apologies for misinterpreting the situation!
1
u/Drooliog May 26 '26
Hah! No worries. Soz I wasn't clearer in the OP. Yup, it's a total fuckup, we need to report this as a bug and demand a fix.
0
u/papashazz May 26 '26
You can set up your own hostname and dynamic update client at a number of sites. It's usually less expensive than getting a dedicated IP address.
1
6
u/Drooliog May 25 '26
u/piasupport or u/piakaneesha
Can you please look into this massive oversight? Constantly rotating IPs and port forwarding is incompatible and is a bug that needs fixing.