Port forwarding is a rule on your router that sends traffic arriving on a chosen port to a specific device inside your home network. It is how a website or game server at home becomes reachable from the internet, and every rule you add is also a door you have opened.
Why a home server can't be reached
Your router sits between two networks. On the outside it has one public IP address, given to it by your internet provider. On the inside, every device (laptop, phone, the old PC running your game server) gets a private IP address, usually handed out by the router itself through DHCP.
Private addresses come from ranges set aside for local networks: 10.0.0.0/8, 172.16.0.0/12 and 192.168.0.0/16. Thousands of homes use 192.168.1.20 at the same moment, so those addresses mean nothing on the public internet and are never routed across it.
To let all those devices share one public address, the router uses network address translation (NAT). When your laptop opens a web page, the router rewrites the outgoing packets so they appear to come from the public address, and notes the connection in a table. When the reply comes back, it looks up that entry and passes the reply to your laptop.
That table only fills when a device inside starts the conversation. A connection that starts outside, such as a friend trying to join your game server, arrives at the router with no matching entry. The router has no idea which device it is for, so it drops it. This is why someone on the internet can reach your router but not the server behind it.
What a forwarding rule says
A port forwarding rule fills that gap ahead of time. It tells the router: when new traffic arrives on this port, send it to this device. Most routers ask for four things:
- External port: the port on your public address that people connect to.
- Protocol: TCP, UDP or both. A web server uses TCP; many games and voice apps use UDP as well.
- Internal IP address: the device that should receive the traffic.
- Internal port: the port the service listens on, usually the same as the external one.
A port is a number from 0 to 65535 that says which program on a machine a connection is for. Some are well known: 80 for HTTP, 443 for HTTPS, 22 for SSH. Others are conventions a program picked, such as 25565, the default for a Minecraft Java Edition server.
Because the router chooses the destination by port, one public address can serve several machines. Each port gets its own rule and can point at a different device.
A worked example
Kitty's router has the public address 203.0.113.7. Inside the house, a small web server has the private address 192.168.1.20 and a Minecraft server runs on 192.168.1.30. The forwarding rules look like this:
| Outside port | Sent to | Service |
|---|---|---|
| 80 (TCP) | 192.168.1.20:80 | Website |
| 443 (TCP) | 192.168.1.20:443 | Website (HTTPS) |
| 25565 (TCP) | 192.168.1.30:25565 | Minecraft |
When a friend connects to 203.0.113.7:25565, the router finds the rule for 25565, rewrites the packet's destination to 192.168.1.30:25565 and passes it on. The game server answers, and on the way out the router rewrites the reply so it comes from the public address again. The friend never sees the private address.
A visitor to the website hits port 80 or 443 on the same public address and lands on a different machine. And when a scanner somewhere tries port 22, there is no rule, so the router drops it and nothing inside ever sees it.
Here is that whole exchange, packet by packet:
One public address, different ports, different servers
Step 1 of 9: A friend connects to Kitty's public address on port 25565.
Making it work in practice
The rule is the easy part. Most problems come from the network around it.
Give the server a fixed address
The rule points at an internal IP address, but DHCP can hand a device a different address, for example after it has been switched off for a while. The rule then sends traffic to the wrong device, or to nothing. Set a DHCP reservation for the server in the router's settings, so it always gets the same address.
Your public address can change
Most home connections get a public address that the provider can change from time to time. Friends who saved the old address can no longer connect. A dynamic DNS service fixes this by giving you a name that follows your address, updated by the router or a small program at home.
Your provider may not give you a public address at all
Some providers, mobile networks especially, put many customers behind one shared public address. This is carrier-grade NAT (CGNAT). Your router's WAN address is then not public at all, often sitting in the 100.64.0.0/10 range set aside for this, and a forwarding rule on your router can't help because the provider's NAT drops the traffic first. Compare the WAN address in your router's status page with what a 'what is my IP' site shows: if they differ, you are probably behind CGNAT. The fixes are asking the provider for a public address, using IPv6, or running a tunnel out to a server that has one.
Test from outside
Many routers can't loop a connection to their own public address back inside, a feature called NAT loopback or hairpinning. So a test from your own Wi-Fi can fail even when the rule works. Test from a phone on mobile data instead.
Every open port is an open door
A forwarding rule exposes that service to the whole internet, not only to the people you gave the address to. Automated scanners sweep the IPv4 address space all the time, so assume any open port will be found. Whatever listens on it will be probed by attackers as well as friends.
- Forward only what you need, and remove rules you no longer use. Each one adds to your attack surface.
- Never forward the router's own admin page, remote desktop (3389), file sharing (SMB on 445) or a database port. These are among the most attacked services.
- Keep the exposed software updated, and use strong, unique passwords or keys. A forwarded port leads straight to that program, with no other defence in front of it.
- Moving a service to an odd port number doesn't make it safe. It cuts down log noise from lazy scanners, but a full scan finds it anyway.
- Turn off UPnP if you don't need it. UPnP lets devices on your network open forwarding rules themselves. That is convenient for games consoles, but any compromised device can use it to open a door without asking you.
Many routers also have a 'DMZ host' setting that forwards every port to one device. It is far riskier than single rules, and it is not the same as a proper DMZ, which is a separate network segment.
When to use a VPN instead
Port forwarding fits a service meant for strangers: a public website, a game server open to anyone with the address. For things only you should reach, such as SSH into your home machine, a NAS or a camera feed, a VPN is the better choice. You forward a single port for the VPN (WireGuard uses one UDP port), or use a mesh VPN that usually needs none, and everything else stays private. Only someone with a VPN key can reach the services behind it.
Two neighbouring ideas are easy to mix up with this one. SSH port forwarding (ssh -L and ssh -R) tunnels a port through an SSH connection and has nothing to do with your router. With IPv6, devices usually get their own public addresses and no NAT is involved, so instead of forwarding you allow the port in the router's IPv6 firewall, which blocks unsolicited inbound traffic on most home routers.
Key takeaways
- Devices on a home network have private addresses, and the router's NAT drops connections that start outside.
- A port forwarding rule maps a port on the public address to a device and port inside.
- One public address can reach several servers, one port each.
- Reserve the server's internal address, and check you aren't behind carrier-grade NAT.
- Every forwarded port is an open door: forward only what you need, keep it patched, and use a VPN for private services.