Wi-Fi & Home Networking

What Is Port Forwarding? A Safe Setup Guide

What is port forwarding? It is a router rule that sends new incoming traffic on a chosen port to a chosen device and service on your private network. You need it when an outside client must start a connection to something at home, such as a self-hosted game or server—not for ordinary browsing, streaming, or joining most online games.

What is port forwarding?

A home router uses network address translation (NAT) to let local devices share an outward connection. When an inside device starts a session, the router records where replies go. A new internet request has no mapping, so the router cannot choose a local destination.

A port-forwarding rule supplies that destination. It matches an outside address, port, and protocol, then rewrites the destination to a local IP address and port: public-IP:external-port → local-IP:internal-port. External and internal ports can match or differ, and TCP and UDP are separate choices. This destination-NAT rule does not encrypt or secure the target. See Ubiquiti’s explanation of port forwarding.

Think in layers: the router rule chooses the destination, the host firewall permits traffic, and the application must actually be listening on the selected port. All three have to agree.

When you need a port forward

The deciding question is simple: does something outside your network need to initiate a connection to a service inside it?

SituationManual forwarding?Reason
Hosting a serverUsually yesRemote clients need a predictable path.
Remote access to a camera, NAS, or computerSometimesA relay or VPN may avoid direct exposure; forward only if required.
Browsing, streaming, video calls, or joining a gameUsually noYour device starts the connection, so NAT can return the traffic.
Using a cloud relay or VPN to homeUsually noThe tunnel or relay creates the path.

Do not add a rule just because a game reports a restricted NAT type. The game may use relays, UPnP, or provider-side NAT, and a manual rule can be unnecessary or ineffective.

Prepare before you change the router

Start with the service’s networking instructions: its required port and protocol belong to the application, not the router brand. Record the target’s local address and make it stable with a router DHCP reservation when possible.

  1. Confirm the service. Make sure it is running and configured for remote connections. A rule cannot create a service that is not listening.
  2. Choose the target. Identify its active local IP. Avoid guest, VPN, disconnected, or wrong-device addresses.
  3. Check the host firewall. Allow only the intended application, protocol, and network profile.
  4. Check the public path. Compare Loqmi’s public IPv4 with the router WAN IPv4. A mismatch can mean double NAT, CGNAT, a VPN, or another gateway. 100.64.0.0/10 is a strong CGNAT clue; see what CGNAT means and RFC 6598.
  5. Plan for changes. A dynamic public IP can change; dynamic DNS may provide a stable hostname. See static versus dynamic IP addresses.
Do not use DMZ as a shortcut. A DMZ-host setting can send unsolicited traffic to one device far beyond the single service you intended to publish.

Find the target device’s local IP

Port forwarding is configured on the router; find the destination address on the device running the service. Router and Android menu names can vary by manufacturer.

Windows 11

Open Start > Settings > Network & internet, choose Wi-Fi and the connected network or Ethernet, then open Properties and read IPv4 address. See Microsoft’s Windows network settings guide.

macOS

Open Apple menu > System Settings > Wi-Fi > Details and read IP address. For Ethernet, use System Settings > Network > Ethernet > Details > TCP/IP; see Apple’s Mac Wi-Fi settings guide.

Linux

On Ubuntu, open Activities > Settings > Network or Wi-Fi, then select the settings button beside the active connection. In a terminal, run ip addr and read inet; skip lo and VPN interfaces. See Ubuntu’s IP-address guide.

Android

On Pixel-style Android, open Settings > Network & internet > Internet, tap the connected Wi-Fi network, and open its details. Samsung and other vendors may use Settings > Connections > Wi-Fi; see Google’s Android Wi-Fi guide.

iPhone or iPad

Open Settings > Wi-Fi, tap the info button beside the connected network, and read the local address under IPv4. This is the Wi-Fi address, not the cellular public address. See Apple’s iPhone Wi-Fi settings guide.

Create and test the rule

Enter the router rule

  1. Sign in to the router. If needed, use Loqmi’s router-login guide.
  2. Open Port Forwarding, Virtual Server, or NAT Forwarding. Vendor paths differ; Google calls the IPv6 version port opening.
  3. Add one narrow rule: name, reserved local IP, external and internal ports from the service documentation, and protocol. Select both only when required.
  4. Apply the rule, then verify the service and host firewall use the same protocol and port.

With two routers, the upstream router must send the traffic to the downstream router’s WAN address, and the downstream router must send it to the host. Bridge mode can remove that extra NAT layer.

Test from another network

Test outside the home LAN: turn off Wi-Fi on a phone and use cellular data, or ask someone on another connection. Enter your public IP or dynamic-DNS hostname and external port. An inside test may fail when outside access works because NAT loopback is unsupported.

Use Loqmi to confirm the public IP used by the test path. Use Loqmi’s speed test only as a performance baseline; speed results do not prove port reachability.

Troubleshoot a failed forward

Check each layer before adding a wider rule.

SymptomLikely causeNext fix
LAN works, outside failsWrong rule, host firewall, stopped service, or no public pathVerify locally, compare WAN with Loqmi, and check the firewall.
The rule breaks after rebootThe target got a new local IPRepair the DHCP reservation and update the rule.
WAN address is private or sharedDouble NAT or CGNAT upstreamForward through each router, use bridge mode, or ask the ISP for a public option.
TCP works but UDP does notWrong protocolRead the service documentation and match it.
Outside works, home failsNAT loopback is unsupportedUse the local address at home and public hostname outside.
Game still reports restricted NATRelay, UPnP, CGNAT, or a game-specific ruleCheck the game’s official guidance instead of forwarding unrelated ports.

Choose the narrowest option

Manual forwarding is one way to create an inbound path. Choose the least exposed option and remove it when the service is gone.

OptionWhat it doesWhen it fits
Manual forwardPersistent mapping to one host and service.A service that needs direct inbound traffic.
UPnPApplications request mappings automatically.Convenience when you accept less control; keep it off unless needed.
Port triggeringTemporary inbound path after an outbound trigger.Apps designed for it, not a permanent server.
VPN or relayAuthenticated outbound path instead of public exposure.Private remote access.
After publishing a service: keep the host and application updated, use strong authentication, prefer encrypted protocols, restrict source addresses when the router supports it, and review the forwarding list periodically. A forwarded port exposes the selected service—not your intent—so treat every connection as untrusted.

Key takeaways

  • A port forward maps inbound traffic to one local service; it is not a speed setting.
  • Reserve the target’s local IP, match the service protocol, and check the host firewall.
  • Compare the router WAN address with Loqmi; CGNAT or double NAT may block the rule upstream.
  • Test from cellular data or another network, not only from inside the LAN.
  • Use a VPN, relay, or narrow manual rule, and remove unused exposure.

Frequently asked questions

Do I need a static public IP for port forwarding?

No. A dynamic public address can still accept a forward while it remains assigned to your router. The inconvenience is that its value can change, so a dynamic-DNS hostname can follow it. A static public IP is useful for predictability, but it does not bypass CGNAT or guarantee that the ISP permits incoming traffic.

Can two devices use the same forwarded port?

Not for the same public IP, port, and protocol at the same time: the router would have no way to choose between them. Use different external ports when the application allows it, or use a relay, VPN, or service-specific method. Multiple external ports may still point to one internal device.

Why does a port checker say closed when my service is running?

A checker can report closed when the service is not listening on the requested protocol, the host firewall blocks it, the rule targets an old local address, or the ISP uses CGNAT. Some checkers also cannot handle a service that opens only on demand. Test from another network and inspect the router and host logs.

How do I remove port forwarding?

Open the router’s forwarding, virtual-server, or NAT page, disable or delete the rule, and apply the change. Then retest from an outside network and confirm the service is no longer reachable. Also review UPnP-created mappings and any IPv6 firewall rules, because removing one manual IPv4 rule may not remove other paths.

Sources

Related articles