What Is Port Forwarding? A Safe Setup Guide
What is port forwarding? It is a router rule that sends new incoming traffic on a chosen port to a chosen device and service on your private network. You need it when an outside client must start a connection to something at home, such as a self-hosted game or server—not for ordinary browsing, streaming, or joining most online games.
What is port forwarding?
A home router uses network address translation (NAT) to let local devices share an outward connection. When an inside device starts a session, the router records where replies go. A new internet request has no mapping, so the router cannot choose a local destination.
A port-forwarding rule supplies that destination. It matches an outside address, port, and protocol, then rewrites the destination to a local IP address and port: public-IP:external-port → local-IP:internal-port. External and internal ports can match or differ, and TCP and UDP are separate choices. This destination-NAT rule does not encrypt or secure the target. See Ubiquiti’s explanation of port forwarding.
When you need a port forward
The deciding question is simple: does something outside your network need to initiate a connection to a service inside it?
| Situation | Manual forwarding? | Reason |
|---|---|---|
| Hosting a server | Usually yes | Remote clients need a predictable path. |
| Remote access to a camera, NAS, or computer | Sometimes | A relay or VPN may avoid direct exposure; forward only if required. |
| Browsing, streaming, video calls, or joining a game | Usually no | Your device starts the connection, so NAT can return the traffic. |
| Using a cloud relay or VPN to home | Usually no | The tunnel or relay creates the path. |
Do not add a rule just because a game reports a restricted NAT type. The game may use relays, UPnP, or provider-side NAT, and a manual rule can be unnecessary or ineffective.
Prepare before you change the router
Start with the service’s networking instructions: its required port and protocol belong to the application, not the router brand. Record the target’s local address and make it stable with a router DHCP reservation when possible.
- Confirm the service. Make sure it is running and configured for remote connections. A rule cannot create a service that is not listening.
- Choose the target. Identify its active local IP. Avoid guest, VPN, disconnected, or wrong-device addresses.
- Check the host firewall. Allow only the intended application, protocol, and network profile.
- Check the public path. Compare Loqmi’s public IPv4 with the router WAN IPv4. A mismatch can mean double NAT, CGNAT, a VPN, or another gateway.
100.64.0.0/10is a strong CGNAT clue; see what CGNAT means and RFC 6598. - Plan for changes. A dynamic public IP can change; dynamic DNS may provide a stable hostname. See static versus dynamic IP addresses.
Find the target device’s local IP
Port forwarding is configured on the router; find the destination address on the device running the service. Router and Android menu names can vary by manufacturer.
Windows 11
Open Start > Settings > Network & internet, choose Wi-Fi and the connected network or Ethernet, then open Properties and read IPv4 address. See Microsoft’s Windows network settings guide.
macOS
Open Apple menu > System Settings > Wi-Fi > Details and read IP address. For Ethernet, use System Settings > Network > Ethernet > Details > TCP/IP; see Apple’s Mac Wi-Fi settings guide.
Linux
On Ubuntu, open Activities > Settings > Network or Wi-Fi, then select the settings button beside the active connection. In a terminal, run ip addr and read inet; skip lo and VPN interfaces. See Ubuntu’s IP-address guide.
Android
On Pixel-style Android, open Settings > Network & internet > Internet, tap the connected Wi-Fi network, and open its details. Samsung and other vendors may use Settings > Connections > Wi-Fi; see Google’s Android Wi-Fi guide.
iPhone or iPad
Open Settings > Wi-Fi, tap the info button beside the connected network, and read the local address under IPv4. This is the Wi-Fi address, not the cellular public address. See Apple’s iPhone Wi-Fi settings guide.
Create and test the rule
Enter the router rule
- Sign in to the router. If needed, use Loqmi’s router-login guide.
- Open Port Forwarding, Virtual Server, or NAT Forwarding. Vendor paths differ; Google calls the IPv6 version port opening.
- Add one narrow rule: name, reserved local IP, external and internal ports from the service documentation, and protocol. Select both only when required.
- Apply the rule, then verify the service and host firewall use the same protocol and port.
With two routers, the upstream router must send the traffic to the downstream router’s WAN address, and the downstream router must send it to the host. Bridge mode can remove that extra NAT layer.
Test from another network
Test outside the home LAN: turn off Wi-Fi on a phone and use cellular data, or ask someone on another connection. Enter your public IP or dynamic-DNS hostname and external port. An inside test may fail when outside access works because NAT loopback is unsupported.
Use Loqmi to confirm the public IP used by the test path. Use Loqmi’s speed test only as a performance baseline; speed results do not prove port reachability.
Troubleshoot a failed forward
Check each layer before adding a wider rule.
| Symptom | Likely cause | Next fix |
|---|---|---|
| LAN works, outside fails | Wrong rule, host firewall, stopped service, or no public path | Verify locally, compare WAN with Loqmi, and check the firewall. |
| The rule breaks after reboot | The target got a new local IP | Repair the DHCP reservation and update the rule. |
| WAN address is private or shared | Double NAT or CGNAT upstream | Forward through each router, use bridge mode, or ask the ISP for a public option. |
| TCP works but UDP does not | Wrong protocol | Read the service documentation and match it. |
| Outside works, home fails | NAT loopback is unsupported | Use the local address at home and public hostname outside. |
| Game still reports restricted NAT | Relay, UPnP, CGNAT, or a game-specific rule | Check the game’s official guidance instead of forwarding unrelated ports. |
Choose the narrowest option
Manual forwarding is one way to create an inbound path. Choose the least exposed option and remove it when the service is gone.
| Option | What it does | When it fits |
|---|---|---|
| Manual forward | Persistent mapping to one host and service. | A service that needs direct inbound traffic. |
| UPnP | Applications request mappings automatically. | Convenience when you accept less control; keep it off unless needed. |
| Port triggering | Temporary inbound path after an outbound trigger. | Apps designed for it, not a permanent server. |
| VPN or relay | Authenticated outbound path instead of public exposure. | Private remote access. |
Key takeaways
- A port forward maps inbound traffic to one local service; it is not a speed setting.
- Reserve the target’s local IP, match the service protocol, and check the host firewall.
- Compare the router WAN address with Loqmi; CGNAT or double NAT may block the rule upstream.
- Test from cellular data or another network, not only from inside the LAN.
- Use a VPN, relay, or narrow manual rule, and remove unused exposure.
Frequently asked questions
Do I need a static public IP for port forwarding?
No. A dynamic public address can still accept a forward while it remains assigned to your router. The inconvenience is that its value can change, so a dynamic-DNS hostname can follow it. A static public IP is useful for predictability, but it does not bypass CGNAT or guarantee that the ISP permits incoming traffic.
Can two devices use the same forwarded port?
Not for the same public IP, port, and protocol at the same time: the router would have no way to choose between them. Use different external ports when the application allows it, or use a relay, VPN, or service-specific method. Multiple external ports may still point to one internal device.
Why does a port checker say closed when my service is running?
A checker can report closed when the service is not listening on the requested protocol, the host firewall blocks it, the rule targets an old local address, or the ISP uses CGNAT. Some checkers also cannot handle a service that opens only on demand. Test from another network and inspect the router and host logs.
How do I remove port forwarding?
Open the router’s forwarding, virtual-server, or NAT page, disable or delete the rule, and apply the change. Then retest from an outside network and confirm the service is no longer reachable. Also review UPnP-created mappings and any IPv6 firewall rules, because removing one manual IPv4 rule may not remove other paths.
Sources
- RFC 6598: Shared Address Space
- Google Home and Nest Help: Port forwarding or port opening
- Ubiquiti Help: UniFi Gateway - Port Forwarding
- Microsoft Support: Essential Network Settings and Tasks in Windows
- Apple User Guide: Wi-Fi settings on Mac
- Apple User Guide: Manage Wi-Fi settings on iPhone
- Ubuntu Desktop Help: Find your IP address
- Android Help: Connect to Wi-Fi networks on your Android device