Use safely: Follow these steps only for a router or network you own or are authorised to manage. Never send Router Portal a router password, Wi-Fi key, MAC address, serial number or private screenshot.
Evidence and scopeSOURCE-BACKED · CHECK DATE
Sources2 official references
ScopeModel/OS/network dependent
CredentialsNever universal
ReviewRecheck after UI changes
Quick answer: NAT loopback or hairpin behavior lets a device inside the LAN reach a service through its public name. Not every router supports it.
What this page covers
Compare local hostname, local address and public-name behavior without changing port rules first.
Step-by-step workflow
- Confirm the service works on its authorised local address.
- Check internal DNS or split-horizon options.
- Test the public name from an external authorised connection if appropriate.
- Use an internal DNS record or documented router feature when hairpin is absent.
Decision table
| Check | What it tells you | Safe next action |
|---|---|---|
| Local address works | Service and LAN path are available | Inspect DNS/hairpin behavior |
| Public name fails only inside | Hairpin may be unsupported | Use split DNS or local name |
| External access fails too | Forwarding or upstream path is separate | Diagnose WAN/CGNAT safely |
Limits and verification
Hairpin failure is not proof that port forwarding is wrong. Keep public services protected and use VPN where appropriate.
Official sources
- IETF RFC 7857 — Updates to NAT terminology (NAT terminology)
- Microsoft — Troubleshoot DNS server issues (DNS diagnosis)
Related Router Portal guides
Router login troubleshooting · Router security guide
Editorial note: This pilot page is written for one distinct question. Firmware, operating-system menus, ISP policies and regional radio rules can change, so confirm the source and exact device before applying a setting.