Guide
What is port forwarding?
Port forwarding tells your router where to send inbound connections. Learn how to set it up safely — and why CGNAT blocks it entirely.
On this page
Every device in your home shares one public IP address. That works beautifully for outbound traffic — your router remembers which device asked for what — but it creates a problem for the reverse direction: when a packet arrives from the internet asking for port 25565, which device should receive it? Port forwarding is the manual answer to that question.
Port forwarding in plain terms
A port is a numbered door on an IP address. Services listen on agreed ports: 443 for HTTPS, 22 for SSH, 25565 for a Minecraft server. Your router's NAT table maps outbound connections automatically, but unsolicited inbound connections are dropped by default — the property that keeps a home network safe.
A port-forward rule says: traffic arriving on the public address, port X, should be delivered to local device Y at port Z. The router then keeps that door open for anyone on the internet, which is exactly why it deserves care.
When you actually need it
- Hosting a game server so friends can connect directly, rather than through the game's relay service.
- Remote access to a camera, NVR or NAS — though a VPN or the vendor's encrypted cloud relay is a better pattern.
- Self-hosting a website, app or mail server from home. Works, but a small VPS is usually cheaper than the abuse handling.
- Remote desktop or SSH into a home machine — better done over a VPN or a mesh tool such as Tailscale, WireGuard or ZeroTier.
Plenty of things people forward do not need it: modern consoles and most apps use UPnP or a relay, and voice/video calls use NAT traversal (STUN) automatically. If you are not sure, you probably do not need a rule.
Setting it up
- Give the device a fixed local address. Create a DHCP reservation in the router (keyed to the device's MAC address — see MAC vs IP) so the rule does not break when the device reconnects.
- Find the admin panel at the gateway address — see how to find your router IP.
- Add the rule under Port Forwarding / Virtual Server / NAT. Prefer a narrow external port range, and forward only to the one device and port that needs it.
- Test from outside. A port checker website or a phone on mobile data — not the same Wi-Fi — tells you whether the door is really open. Testing from inside the network gives false negatives.
- Turn UPnP off once you are done, so applications cannot quietly open doors on their own.
If it refuses to work: CGNAT
If the rule is configured correctly but external tests still fail, check your router's WAN address. If it starts with 100.64–100.127, you are behind carrier-grade NAT: your ISP shares one public IPv4 address among many customers, and there is nowhere for inbound traffic to land. The workarounds:
- IPv6. Without a shared IPv4 pool, inbound connections to a properly firewalled v6 address work — see IPv4 vs IPv6 and IPv6 in 2026.
- A tunnel or mesh VPN (WireGuard, Tailscale, Cloudflare Tunnel) that keeps an outbound session open.
- Ask the ISP for a unique public IPv4, sometimes available for a small fee.
- A relay service from the game or app itself.
Doing it without getting owned
- Never expose SMB (445), RDP (3389) or an unauthenticated admin panel. These are scanned continuously and compromised within hours.
- Put a reverse proxy in front of any web service, terminate TLS, and keep the service patched. A proxy can add authentication, rate limiting and logging — see what a proxy server is.
- Use strong, unique credentials and key-only SSH. Update the service before you open the port, not after.
- Watch the logs. A sudden flood of attempts is normal internet background noise; a successful login you did not perform is not.
- Close what you are not using. A port-forward rule outlives the experiment that justified it.
Bottom line: port forwarding is a deliberate hole in your NAT for a service that must be reachable from outside. It does not change your public IP, it does not make you anonymous, and in a CGNAT world it may be impossible without IPv6 or a tunnel.
Frequently asked questions
Can I port forward if my ISP uses CGNAT?
Not on IPv4 — you do not have a unique public address to forward from. Use IPv6, a WireGuard/Tailscale/Cloudflare tunnel, or ask the ISP for a dedicated public IPv4.
Is port forwarding dangerous?
It removes the default protection for one port, so the risk is exactly the service behind it. Expose only updated, authenticated software, and never RDP, SMB or a router admin page.
Does port forwarding change my IP address?
No. It changes how inbound traffic to a port is handled, not your address. To change the address itself, see how to change your IP address.
Keep reading
- What is a DNS server?
- MAC address vs IP address
- Tor vs VPN
- What is 127.0.0.1?
- Does a VPN slow down your internet?
- Subnet masks and CIDR explained
- Are free VPNs safe?
- How to fix an IP address conflict
- How does a VPN work?
- How to tell if someone is using your Wi-Fi
- What is a proxy server?
- Is an IP address personal data?
- Browse all IP guides
- Check my public IP address
Check any other IP address
Investigating a suspicious login, a spam email header or a server log entry? Run any IPv4 or IPv6 address through the same geolocation and proxy checks.