What port forwarding actually does
Your router performs NAT (Network Address Translation). Every device at home has a private address such as 192.168.1.23 or 10.0.0.45, and the router shares a single public IP address among all of them. When your laptop opens a website, the router remembers which device made the request and routes the reply back to it.
Traffic that arrives unannounced from the internet is different. The router has no record of anyone asking for it and no idea which of your devices should get it, so it drops it. That default behavior is a big part of why home networks are reasonably safe. A port forwarding rule is the exception you write down: "anything arriving on TCP port 25565, send to 192.168.1.50."
A port is just a number from 0 to 65535 that identifies which service on a device a connection is meant for. Web servers typically use 443, SSH uses 22, Minecraft Java servers use 25565. The protocol matters too: TCP is used for most services, while games and voice chat lean heavily on UDP.
Do you actually need it?
Probably not, if all you want is one of these:
- Viewing a smart camera or doorbell from your phone. Ring, Nest, Arlo, Wyze, Eufy and similar products use cloud relays that work without any port changes.
- Remote Plex or NAS access through the vendor's service. Plex, Synology QuickConnect and similar features can relay connections, though direct connections usually perform better.
- Normal gaming. UPnP opens ports on demand on most routers and ISP gateways.
You likely do need it for:
- Hosting a dedicated game server (Minecraft, Valheim, ARK, Palworld and so on).
- Direct remote access to Plex or Jellyfin without relays.
- Running a self-hosted web app, VPN server (e.g. WireGuard on UDP 51820) or home lab service.
- Fixing a Strict NAT type on a console when UPnP is disabled or unreliable.
Try UPnP first
UPnP (Universal Plug and Play) lets a device ask the router to open the ports it needs, only while it needs them. Xbox and PlayStation consoles, many PC games and Plex all use it. It is enabled by default on most ISP gateways and consumer routers.
- Look for UPnP under Advanced, NAT, or Network settings in your router's admin page or app.
- Turn it on, then restart the console or app so it re-requests its ports.
- Recheck the NAT type in the console's network settings.
UPnP is convenient but it trusts any device on your network, including a compromised one. If you have many low-cost IoT gadgets, some people prefer to disable UPnP and write a few manual rules instead. Either approach is reasonable; just don't leave UPnP exposed on the WAN side, which no well-configured router does by default.
Manual port forwarding, step by step
1. Find the target device's local IP
Your router's Connected Devices or Client List page shows every device
and its address. You can also check on the device itself: on Windows run
ipconfig, on macOS open System Settings → Network, and consoles show it in
their network status screen.
2. Reserve that IP address
DHCP hands out addresses that can change after a reboot. Create a DHCP reservation (sometimes called static lease or address reservation) so the device always gets the same IP. Otherwise your rule may silently start pointing at your smart TV instead of your server.
3. Find the port forwarding page
Log in to the router (see how to log in to your router). The feature goes by several names:
- Port Forwarding — most brands, often under Advanced, NAT Forwarding or WAN
- Virtual Server — common on TP-Link and D-Link firmware
- Port Forwarding / Port Triggering — NETGEAR, under Advanced Setup
- WAN → Virtual Server / Port Forwarding — ASUS
- App-based settings — many mesh systems and ISP gateways (eero, Google/Nest, Xfinity, Spectrum) move this into the mobile app instead of a web page
Menu names change between firmware versions, so treat these as starting points rather than exact paths.
4. Fill in the rule
- Name / Service: something descriptive, like "Minecraft server".
- Protocol: TCP, UDP or Both. Use what the application's documentation specifies.
- External port (or range): the port people connect to from the internet.
- Internal port: the port the service listens on locally, usually the same number.
- Internal IP / Device: the reserved address from step 2.
- Enabled: on.
Save. Most routers apply the rule immediately; a few need a reboot.
Port forwarding on ISP gateways
If you rent equipment from your provider, the setting usually lives in the provider's app or a simplified web interface, and the options may be more limited than on a retail router:
- Xfinity: port forwarding is managed in the Xfinity app (or the xFi web interface) rather than the local admin page on current gateways. See the Xfinity router login guide.
- Spectrum: newer Spectrum routers are managed through the My Spectrum app; see the Spectrum router guide.
- AT&T: fiber gateways handle this under the firewall settings of the local admin page, which uses a separate device access code printed on the label. See the AT&T router guide.
- Verizon Fios: the Fios router's web interface and the My Fios app both expose port forwarding. See the Verizon Fios router guide.
- T-Mobile Home Internet: IPv4 port forwarding is not available because of CGNAT. See T-Mobile Home Internet login.
How to test the rule
- Make sure the service is actually running and listening. A port checker reports "closed" if nothing answers, even when the rule is correct.
- Check your public IP with ipinfo.io or whatismyip.com.
- Use a TCP port checker such as canyouseeme.org. Note that most online checkers only test TCP; UDP-only services need a real client test.
- For a real-world test, turn off Wi-Fi on your phone and connect over cellular data to your public IP and port.
Testing from inside your own network using the public IP may fail even when everything works, because not every router supports NAT loopback (hairpinning).
When port forwarding doesn't work
Double NAT
If you plugged your own router into an ISP gateway that is also routing, you have two NAT layers. Your router's WAN address will be private (for example 192.168.0.x or 10.0.0.x). The clean fix is to put the ISP gateway into bridge mode (cable gateways) or IP Passthrough (AT&T), or to put your own router into access point mode. The fallback is to forward the port on both devices: gateway → your router's WAN IP, then your router → the final device.
CGNAT
If your router's WAN address falls in 100.64.0.0 – 100.127.255.255, or doesn't match the public IP websites report, your ISP is sharing one public IPv4 address across many customers. Inbound IPv4 forwarding cannot work. See what CGNAT is and how to get around it.
Firewalls on the device
Windows Defender Firewall, macOS's firewall, or a NAS's built-in firewall can block the connection after the router has forwarded it. Allow the application or port on the device too.
ISP-blocked ports
Some residential ISPs block a handful of inbound ports such as 25 (email) and sometimes 80. If a common port won't open, try a higher external port (for example 8080 or 25566) mapped to the same internal port.
Frequently asked questions
What is port forwarding and when do I need it?
Port forwarding is a rule on your router that says: when traffic from the internet arrives on port X, send it to device Y on my home network. You need it when something outside your home has to start a connection to a device inside it: hosting a game server (Minecraft, Valheim), reaching a Plex or Jellyfin server remotely without the vendor's relay, accessing a NAS or self-hosted app, or improving NAT type on a console when UPnP isn't working. Ordinary browsing, streaming and most smart-home apps do not need it, because those connections start from inside your network.
Which ports do I need to open for gaming?
It depends on the platform and the game, and the lists change, so use the publisher's own support page as the source of truth. A few long-standing examples: Minecraft Java Edition servers listen on TCP 25565 by default; Xbox networking uses UDP 3074 (plus UDP 88, 500, 3544 and 4500); Plex Media Server uses TCP 32400. For most consoles and PC games, turning on UPnP is enough, because the game asks the router to open what it needs automatically. Manual rules are mainly for when UPnP is off or you are hosting a dedicated server.
Why is my NAT type Strict or Moderate?
Consoles grade your connection as Open (Type 1 / NAT Type A), Moderate (Type 2 / B) or Strict (Type 3 / C). Strict means unsolicited inbound connections are blocked, which can slow matchmaking and break party chat with some players. Common causes: UPnP disabled, double NAT (your own router behind an ISP gateway that is also routing), or CGNAT from your provider, which is common on 5G home internet. Fix the cause first: enable UPnP, put one of the two routers into bridge/passthrough mode, or see the CGNAT guide if your WAN address is shared.
Is opening ports a security risk?
It can be. An open port makes whatever is listening behind it reachable by anyone on the internet, and automated scanners find new open ports within hours. The risk depends on that service: an up-to-date game server or Plex install is low risk; an old IP camera with a default password or a NAS running outdated firmware is a real exposure. Open only what you need, forward to a device with a reserved IP, keep its firmware current, use strong unique passwords, and delete rules you no longer use. For remote access to cameras, NAS boxes or admin pages, a VPN (WireGuard, or a mesh VPN such as Tailscale) is usually the safer choice.
Can I port forward on T-Mobile or Verizon 5G Home Internet?
Generally not for IPv4. 5G and many fixed-wireless home internet services place customers behind carrier-grade NAT, so there is no public IPv4 address for a forwarding rule to work on. Some services provide public IPv6, which can work for apps that support it. Otherwise the usual workarounds are a tunnel or relay service (Tailscale, Cloudflare Tunnel, a small cloud VPS running WireGuard) or switching to a plan that includes a public or static IP.