Router Portal · Practical help for your router, Wi-Fi and local network
Pilot research guide

NAT Loopback Not Working: Local Access via a Public Name

NAT loopback or hairpin behavior lets a device inside the LAN reach a service through its public name. Not every router supports it.

Use safely: Follow these steps only for a router or network you own or are authorised to manage. Never send Router Portal a router password, Wi-Fi key, MAC address, serial number or private screenshot.
Evidence and scopeSOURCE-BACKED · CHECK DATE
Sources2 official references
ScopeModel/OS/network dependent
CredentialsNever universal
ReviewRecheck after UI changes
Quick answer: NAT loopback or hairpin behavior lets a device inside the LAN reach a service through its public name. Not every router supports it.

What this page covers

Compare local hostname, local address and public-name behavior without changing port rules first.

Step-by-step workflow

  1. Confirm the service works on its authorised local address.
  2. Check internal DNS or split-horizon options.
  3. Test the public name from an external authorised connection if appropriate.
  4. Use an internal DNS record or documented router feature when hairpin is absent.

Decision table

CheckWhat it tells youSafe next action
Local address worksService and LAN path are availableInspect DNS/hairpin behavior
Public name fails only insideHairpin may be unsupportedUse split DNS or local name
External access fails tooForwarding or upstream path is separateDiagnose WAN/CGNAT safely

Limits and verification

Hairpin failure is not proof that port forwarding is wrong. Keep public services protected and use VPN where appropriate.

Official sources

Related Router Portal guides

Router login troubleshooting · Router security guide

Editorial note: This pilot page is written for one distinct question. Firmware, operating-system menus, ISP policies and regional radio rules can change, so confirm the source and exact device before applying a setting.