Before creating a rule
- Follow the service documentation.
- Confirm the service is listening.
- Prefer DHCP reservation.
- Have the gateway and login guide ready.
Rule fields
| Field | Meaning | Check |
|---|---|---|
| Name | Identifies the rule | Make cleanup clear |
| External port | Public entry | Use required port only |
| Internal port | Service destination | Follow vendor docs |
| Local IP | Target device | Reserve it |
| Protocol | TCP/UDP | Match service |
| Enable/save | Active state | Disable later |
Forwarding versus triggering
Forwarding maps an always-available destination. Triggering creates a temporary mapping after outbound traffic. Neither is universally safer; use what the service supports.
Verify externally
Test while the service is running from outside the LAN. Local hairpin tests can mislead. Use the port checker when available.
Failure checklist
Check listener, host firewall, reserved IP, port mapping, protocol, double NAT, CGNAT, VPN, ISP filtering and IPv6. Do not jump to DMZ or reset.
Cleanup
Restrict source access when possible, monitor the service and remove the rule when finished.
Frequently asked questions
Does every app need forwarding?
No. Many apps use outbound connections or relays.
Why does LAN testing differ?
Hairpin NAT, CGNAT and firewall behaviour can differ externally.
Is DHCP reservation useful?
It keeps the device address stable without risky manual network edits.