Guides

How to Set Up Port Forwarding: Step-by-Step Guide

Set up port forwarding on your router step by step: add a rule, test it with a port checker, fix CGNAT and double NAT, and avoid risky ports like RDP.

7 min read · Updated: September 28, 2026

Port forwarding lets connections from the internet reach a specific device on your home or office network. You'll often need it to view a security camera remotely, host a game server or connect to a device at home while you're away. This guide explains how port forwarding works, what you need before you start, how to add a rule on your router step by step, how to test the result, how to fix common problems and which security pitfalls to avoid.

What Is Port Forwarding?

All the devices in your home reach the internet through your router's single public IP address, thanks to a technique called NAT (network address translation). Replies to connections your devices start are delivered to the right device automatically, but when a connection arrives from outside unannounced, the router has no idea which device it's meant for, so by default it rejects it. That behavior is also an important layer of protection for your home network.

A port is a number from 1 to 65535 that separates the different services on a device: web servers use ports 80 and 443, and Windows Remote Desktop uses 3389. A port forwarding rule tells your router something like: “send connections that arrive on port 8000 of my public IP address to port 8000 of the device at 192.168.1.50.”

Before You Start: Requirements

  • A public IP address of your own: if you're behind CGNAT, meaning your router's WAN address is between 100.64.x.x and 100.127.x.x, port forwarding won't work. Ask your provider for a public IP first; our static IP guide has the details.
  • A fixed local IP for the device: create a DHCP reservation on the router for the device you're forwarding to, or give it a static local IP manually. Otherwise, the rule breaks as soon as the address changes.
  • The port and protocol: check the device's or program's manual to find out which port it uses and whether it needs TCP, UDP or both.
  • Access to your router: you'll need the admin username and password; see our router login guide.

How to Set Up Port Forwarding, Step by Step

  1. Find the device's local IP address: on Windows, look for the “IPv4 Address” line in the output of ipconfig; on a camera or DVR, check its network settings, or use the connected devices list in your router.
  2. Log in to your router: type the default gateway address (often 192.168.1.1) into your browser and sign in with the admin credentials.
  3. Find the right menu: the name depends on the brand: “Port Forwarding,” “NAT,” “Virtual Server,” “Port Mapping” or “Applications,” for example. It's usually under “Advanced,” “Network” or “Security.”
  4. Add a new rule and fill in these fields:
    • Service name: a label that helps you recognize the rule, such as “Camera.”
    • External port: the port or port range people will connect to from the internet.
    • Internal IP address: the device's fixed local IP, such as 192.168.1.50.
    • Internal port: the port the device listens on; usually the same as the external port.
    • Protocol: TCP, UDP or, if you're not sure, both (“TCP/UDP” or “Both”).
    If your router has more than one internet connection (WAN interface) configured, choose the one that actually connects to the internet, such as the PPPoE connection.
  5. Save and apply: some routers need a restart before the rule takes effect.
  6. Test it: with the service running, check the port using our port checker as described below.

Example: a rule for a camera recorder

Say you want to reach a Hikvision recorder at 192.168.1.50 from its mobile app. You'd add a rule with external port 8000, internal IP 192.168.1.50, internal port 8000 and protocol TCP, then repeat it for port 554 if you use RTSP for live video. In the app, you'd enter your public IP address or DDNS hostname as the device address, with port 8000.

How to Test Port Forwarding

Our port checker tries to connect from our server to your public IP address on the TCP port you choose, so it tests your setup exactly the way the internet sees it. That matters: trying to reach your own public IP from inside the same network fails on routers without NAT loopback (hairpinning) support, even when the rule is correct.

  • Open: the rule works and the service accepts connections.
  • Closed: your IP address is reachable, but nothing is listening on that port. Make sure the program is running and the internal IP in the rule is correct.
  • Filtered: there's no response at all. The cause may be CGNAT, the device's firewall, a missing rule or ISP blocking.

The checker only tests TCP ports, so check UDP-only services (such as Minecraft Bedrock Edition) with the game's or program's own connection test. If you reach our site over IPv6, the test targets your IPv6 address; to test your IPv4 rule, temporarily disable IPv6 on your device.

Common Ports to Forward

UsePortProtocol
Hikvision camera / NVR80 (web), 554 (RTSP), 8000 (client)TCP
Dahua camera / DVR80 (web), 554 (RTSP), 37777TCP
XMEye-compatible DVR34567TCP
Minecraft Java Edition25565TCP
Minecraft Bedrock Edition19132UDP
Steam / Source game server (CS2)27015UDP (TCP for RCON)
Xbox Live3074TCP and UDP
Plex Media Server32400TCP
OpenVPN1194UDP (default)
WireGuard51820UDP (the conventional port)
Web server80, 443TCP
Remote Desktop (RDP)3389TCP; don't expose it directly (see below)

Camera and DVR ports can vary by model and firmware version, so go by the values shown in the device's network settings.

Game Consoles and NAT Type

PlayStation reports its NAT type as Type 1, 2 or 3 in its connection test, while Xbox shows Open, Moderate or Strict. Type 3 or Strict NAT can cause matchmaking and voice chat problems in multiplayer games. The most common causes are CGNAT, double NAT and UPnP being turned off on the router. With UPnP on, the console opens the ports it needs by itself. If you'd rather keep UPnP off, give the console a fixed local IP with a DHCP reservation and forward the ports listed by the game or the console maker.

Port Still Closed? Troubleshooting

  • CGNAT: if your router's WAN address differs from the IP on our home page and falls in the 100.64.0.0/10 range, nothing you do on the router will let connections through. Ask your provider for a public IP.
  • Double NAT: if you have your own router behind the provider's modem, your router's WAN address is a private one such as 192.168.1.x. Either put the provider's modem in bridge mode, or forward the port twice: first on the modem to your router's WAN address, then on your router to the device. Using the modem's DMZ feature to send all incoming traffic to your router is another option.
  • The device's firewall: on Windows, go to Windows Defender Firewall → Advanced settings → Inbound Rules and add an allow rule for the port. Some programs ask for this permission during installation.
  • The service isn't running or listens on the wrong address: if the program is closed or only listens on 127.0.0.1, it can't be reached from outside. Make sure it listens on all interfaces (0.0.0.0).
  • The local IP changed: if the device picked up a different IP after a restart, the rule points at nothing. Set up a DHCP reservation.
  • ISP blocking: some providers block certain ports, such as 25, 80 or 445. Use a different external port instead, for example forwarding external port 8080 to internal port 80.
  • Port conflicts: if the router's own remote management uses the same port (such as 80, 443 or 8080), the rule may not work; pick a different external port.

Security: What to Watch Out For

Every port you open is a door anyone on the internet can try, and bots scan the internet for open ports around the clock. Before you open a port, ask yourself whether you really need it.

  • Never expose RDP (3389), SMB (445) or Telnet (23) directly. These services are among the most common targets of ransomware and password-guessing attacks.
  • Use a VPN for remote access: set up your router's built-in VPN server or a solution such as WireGuard or OpenVPN, open just that one VPN port, and reach everything else through the VPN.
  • Change default passwords: cameras and DVRs left with default passwords are easy targets for botnets. Keep their firmware up to date too.
  • Be careful with UPnP: UPnP lets programs open ports without asking you, and malware can abuse it as well. Turn it off unless you need it.
  • Keep your rules tidy: delete rules you no longer use and, if your router supports it, only accept connections from specific IP addresses.