Advanced networking

How to port forward on a router (and when to use port triggering)

Forward only the required port to a trusted service, test externally and remove the rule when finished.

Safety boundary: Use these instructions only for a router or network you own or are authorised to manage. Never enter a router password, Wi-Fi password, SSID, serial number or private network data into Router Portal.
Security note: Port forwarding exposes a service to Internet traffic. Use the smallest rule, patch the service and delete it when no longer needed.

Before creating a rule

  • Follow the service documentation.
  • Confirm the service is listening.
  • Prefer DHCP reservation.
  • Have the gateway and login guide ready.

Rule fields

FieldMeaningCheck
NameIdentifies the ruleMake cleanup clear
External portPublic entryUse required port only
Internal portService destinationFollow vendor docs
Local IPTarget deviceReserve it
ProtocolTCP/UDPMatch service
Enable/saveActive stateDisable later

Forwarding versus triggering

Forwarding maps an always-available destination. Triggering creates a temporary mapping after outbound traffic. Neither is universally safer; use what the service supports.

Verify externally

Test while the service is running from outside the LAN. Local hairpin tests can mislead. Use the port checker when available.

Failure checklist

Check listener, host firewall, reserved IP, port mapping, protocol, double NAT, CGNAT, VPN, ISP filtering and IPv6. Do not jump to DMZ or reset.

Cleanup

Restrict source access when possible, monitor the service and remove the rule when finished.

Frequently asked questions

Does every app need forwarding?

No. Many apps use outbound connections or relays.

Why does LAN testing differ?

Hairpin NAT, CGNAT and firewall behaviour can differ externally.

Is DHCP reservation useful?

It keeps the device address stable without risky manual network edits.