GuideRespawn
Tutorials

How to Port Forward: A Beginner's Guide for Gamers

How to port forward for a game server: reserve a local IP, add the router rule, allow the server in Windows Firewall, then test from outside your network.

Photo of BrandonBrandon15 min read

Port forwarding comes down to one rule in your router that says "anything arriving on this port goes to that device." You give your PC or console a local IP that won't change, add the rule with the game's port and protocol, let the server through Windows Firewall, and then have someone outside your house try to join.

What a port forward is: one rule with three blanks

Whatever brand of router you're logged in to, it's asking for the same three things:

  • The device's local IP address, meaning the PC or console the traffic should land on.
  • The port number the game or server listens on.
  • The protocol: TCP, UDP or both.

You need a rule because your router's firewall blocks every connection attempt coming in from the internet by default. On top of that, all your devices share one public IP address, so when a friend's game knocks on that address, the router has no idea which device should answer.

Here's a made-up setup to carry through the rest of the steps. You're running a Palworld server on a PC at 192.168.0.50, your public address is 203.0.113.25, and Palworld uses UDP 8211. Your rule says "UDP 8211 goes to 192.168.0.50," and your friends join at 203.0.113.25:8211.

Do you need to port forward at all?

Maybe not, and it's worth a minute to check.

Anyone on the same home network as the server doesn't need a rule. They join with the server PC's local IP, so a roommate would type 192.168.0.50 and be in. Forwarding only matters for players elsewhere, who use your public IP.

A Valheim server started with -crossplay sends its data through a relay server and needs no port forwarding. With crossplay on, though, nobody joins by local IP, not even from the same house: players use the public IP and port, a join code or the server list.

An Xbox asks the router for UDP 3074 by itself through UPnP, so as long as your router has UPnP turned on, you may never have to touch the forwarding page. If you do end up adding rules for a console, they go in the router, not on the console. Xbox's own advice is not to combine port forwarding, UPnP and DMZ, so pick one method.

Give your PC or console a fixed local IP

Your router hands out local addresses automatically, and the same device can get a different one later. If your server PC is 192.168.0.50 today and 192.168.0.53 after a restart next month, the rule still points at .50 and your friends get nothing. The fix is a reservation, which tells the router to give that device the same address every time.

First, find the address the PC has now. On Windows 10 or 11, go to Start > Settings > Network & internet, then open Wi-Fi and your network, or Ethernet. It's next to IPv4 address. Or click Start, type cmd, press Enter and run:

ipconfig

That lists the IPv4 address, subnet mask and default gateway for each adapter. A reservation also needs the device's MAC address, which ipconfig /all shows, though some routers let you pick the device from a list instead.

Then reserve it:

  • TP-Link: Advanced > Network > DHCP Server > Address Reservation (on some models, Network > DHCP Server > Address Reservation). Click Add, enter the MAC address and IP, turn the entry's Status on, then Reboot. If the router is on its default 192.168.0.1, pick something between 192.168.0.2 and 192.168.0.254.
  • NETGEAR: ADVANCED > Setup > LAN Setup, then Add in the Address Reservation section. Type the IP and the MAC address (you can copy it from the Attached Devices page) and click Apply. The PC picks up the address the next time it contacts the router, so reboot it.
  • ASUS: Advanced Settings > LAN > DHCP Server. Set Enable Manual Assignment to Yes, pick the device from the list, enter an IP inside the DHCP pool, click +, then Apply. In the ASUS Router app it's Settings > LAN > IP Binding.
  • Linksys: Connectivity > Local Network tab > DHCP Reservations under DHCP Server. Select the device, click Add DHCP Reservation, then Save. The IP has to be inside the DHCP range.

For consoles, the router reservation is still the better route. If your router doesn't offer one, an Xbox can be set by hand under Profile & system > Settings > General > Network settings > Advanced settings > IP settings > Manual. On PS5 it's Settings > Network > Settings > Set Up Internet Connection, then Advanced Settings > IP address.

Find the port and protocol for your game or console

A port forwarding rule with its three blanks filled in: device local IP 192.168.0.50, port number 8211, protocol UDP.

These are the defaults from each game's or console's own maker.

Game or console Port Protocol Notes
Minecraft: Java Edition 25565 TCP Set by server-port=25565 in server.properties.
Valheim (Steam backend) 2456-2457 UDP The server uses the port set with -port (default -port 2456) plus the next one.
Palworld 8211 UDP Changed with the start argument -port=8211 (official server guide, version 1.0.4).
Project Zomboid (Build 42) 16261 and 16262 UDP Two separate rules. 16261 is the game port players type, 16262 is for direct connection.
Xbox network 88 (UDP), 3074 (UDP and TCP), 53 (UDP and TCP), 80 (TCP), 500 (UDP), 3544 (UDP), 4500 (UDP) Per port 9002 (UDP) only if remote play won't connect on Strict NAT. Some games need extra ports, listed by their developer.
PlayStation TCP 80, 443, 3478, 3479, 3480; UDP 3478, 3479, 49152-65535 TCP and UDP Remote Play uses UDP 8572.

Two things trip people up when they change a port. In Palworld, PublicPort doesn't change the port the server listens on. Only -port= does that, so the rule has to match the launch argument. In Minecraft, if you move off 25565, players have to add the new port after your address, like 203.0.113.25:25570.

For Valheim, if you start the server with a different -port, forward that number and the one after it.

How to port forward on your router

Every brand asks for an external port and an internal port. External is the one your friends' games hit from the internet, and internal is the one the server listens on at your PC. For a game server they're almost always the same number, so in the running example both are 8211.

A port can go to only one device. And if you see "port triggering" next to the forwarding option, leave it alone. It's a different feature, and it isn't the one a server waiting for incoming connections needs.

Log in at tplinkwifi.net or 192.168.0.1. TP-Link calls the feature Virtual Servers or Port Forwarding depending on the model, and there are three layouts:

  • TL-WR840N, TL-WR940N, Archer C20, C50: Forwarding > Virtual Servers > Add New. Fields are Service Port, Internal Port, IP Address, Protocol and Status (set to Enabled).
  • Archer A9, C7, AX10, AX6000: Advanced > NAT Forwarding > Virtual Servers > Add. Fields are Service Type, External Port, Internal Port, Internal IP and Protocol.
  • Archer A8, AX55, AX90, AX11000: Advanced > NAT Forwarding > Port Forwarding > Add. Fields are Service Name, Device IP Address (pick it from View Connected Devices), External Port, Internal Port and Protocol.

Once you're on the right page:

  1. Enter the port in the external (or service) port field, for example 8211.
  2. Enter the same number as the internal port. For a range written like 2456-2457, leave Internal Port empty.
  3. Enter the device's reserved IP, for example 192.168.0.50.
  4. Choose the protocol. If you're not sure, choose ALL.
  5. Make sure the entry is enabled and click Save.

TP-Link's own port forwarding setup guide has screenshots of each layout if yours looks different.

NETGEAR

  1. Go to www.routerlogin.net and log in. The user name is admin.
  2. Open ADVANCED > Advanced Setup > Port Forwarding/Port Triggering and keep Port Forwarding selected.
  3. Click Add Custom Service.
  4. Type a Service Name you'll recognize later, like "Palworld".
  5. Set Service Type to the protocol. If you're unsure, pick TCP/UDP.
  6. Fill in External Starting Port and External Ending Port. For a single port, both get the same number.
  7. Leave Use the same port range for Internal port ticked.
  8. Enter the PC's address in Internal IP address and click Apply.

NETGEAR walks through the same screen in its custom port forwarding service article.

ASUS

  1. Log in at www.asusrouter.com.
  2. Go to WAN > Virtual Server/Port Forwarding.
  3. Switch Enable Port Forwarding to ON. It's off by default, and it's easy to add a rule and never notice the master switch.
  4. Click Add profile.
  5. Fill in External Port. A range is written with a colon, like 300:500, and separate ports are written with commas, like 566, 789. Valheim's default pair would be 2456:2457.
  6. Leave Internal Port and Source IP blank unless you have a reason to change them.
  7. Enter the PC's address in Internal IP Address, pick the protocol the game needs and click OK.

There's more detail on the range syntax in the ASUS Virtual Server / Port Forwarding guide.

Linksys

  1. Log in at myrouter.local or 192.168.1.1.
  2. Go to Security > Apps and Gaming.
  3. For one port, open Single Port Forwarding and click Add a new Single Port Forwarding. For consecutive ports, use Port Range Forwarding instead, which has Start Port and End Port fields.
  4. Fill in Application name, External Port and Internal Port.
  5. Set Protocol. Linksys recommends leaving it on Both.
  6. Enter the last part of the PC's address in Device IP#.
  7. Tick Enabled, then click Save, Apply and Ok.

In the Linksys app, it's the menu > Advanced Settings > Port Settings > Single Port Forwarding > Add a rule. The web version is covered in the Linksys Smart WiFi port forwarding article.

Let the server through Windows Firewall

The router now passes traffic to your PC, but Windows blocks inbound connections by default too, so the server needs its own allow rule.

The first time you launch a server app, Windows shows a prompt asking whether to allow it. Say yes. Valheim's guide goes further and says to tick all the checkboxes in that pop-up.

If you clicked No or closed the prompt, that's very likely your problem. Windows responds by creating block rules, typically one for TCP and one for UDP, and block rules beat allow rules. The prompt won't come back until those are deleted. Type wf.msc into Start, open Inbound Rules, find the entries for your server app and remove the blocking ones.

From there you have two ways to let the server in.

Allow the app (the better choice). Open Windows Security > Firewall & network protection > Allow an app through firewall, click Change settings, and tick the server. If it isn't listed, use Allow another app and enter its path. Microsoft calls this the less risky option, because an allowed app opens its ports only when needed, while an opened port stays open until you close it.

Open a port. If you need a port rule instead:

  1. Type wf.msc into Start, or go to Firewall & network protection > Advanced settings.
  2. Click Inbound Rules, then New Rule... under Actions.
  3. On Rule Type, choose Port.
  4. On Protocol and Ports, pick TCP or UDP and type the local port, for example UDP 8211. The wizard makes you choose one protocol, so a game that needs both gets two rules.
  5. On Action, choose Allow the connection.
  6. On Profile, tick the network types the rule should apply to.
  7. Give it a name you'll recognize and finish.

That Profile page hides a catch. A rule only works on the network types you ticked, and Windows 11 sets a network to Public when you first connect to it. So a rule limited to Private does nothing if your home network is still marked Public. Check under Settings > Network & internet > your network > Network profile type.

Whichever route you take, don't turn the firewall off to "see if it helps." Microsoft is clear that doing so leaves the PC more vulnerable, and allowing the app gets you the same result. The full list of wizard pages is in Microsoft's documentation on configuring Windows Firewall rules.

Test the port from outside your network

A roommate indoors reaches the server by its local IP; the real test is a friend outside, coming in by WAN IP and port.

Two conditions make a test worth anything. The server has to be running, because a port with nothing listening behind it looks closed even when the rule is perfect. And the connection has to come from outside your home network, from a device that's on the internet but not on your own LAN.

The simplest real test is a friend. Have them connect to your WAN IP and port, in the running example 203.0.113.25:8211. Your WAN IP is on the router's status page.

If they can't get in, work through TP-Link's order of checks:

  1. Can a device on your own network reach the server at its local IP? If not, the problem is the server, not the router.
  2. Does the rule have the right internal IP, port and protocol? A reservation you set after the PC already had a different address is a classic cause.
  3. Is Windows Firewall blocking it? This and the next item are the two most common causes.
  4. Is the router's WAN IP a real public address? More on that below.
  5. Are the device's own IP settings correct?

Consoles have a built-in check. On Xbox, go to Profile & system > Settings > General > Network settings > Test NAT type, and you're aiming for Open. On PS5, it's Settings > Network > Connection Status > Test Internet Connection.

Project Zomboid gives you a helpful hint for free: it warns players when the server's port 16262 is closed, so if friends see that, your second rule is the one to look at.

When port forwarding can't work: double NAT and CG-NAT

A forward only works from the internet if your router's WAN IP is a public address. Here's how to check: note the WAN or Internet IP on the router's status page (on TP-Link it's WAN IP Address under Advanced > Status or Advanced > Network > Status), then look up your public IP on an IP-lookup website. If they match, you're fine. If they don't, something upstream is doing its own NAT and your rule never sees the traffic.

The WAN IP itself tells you which situation you're in:

  • A private address (10.0.0.0 to 10.255.255.255, 172.16.0.0 to 172.31.255.255, or 192.168.0.0 to 192.168.255.255) usually means double NAT. Your provider's gateway, the modem and router in one box, is doing NAT, and so is your own router behind it.
  • An address from 100.64.0.0 to 100.127.255.255 means carrier-grade NAT. It looks public, but it isn't. TP-Link says most 3G/4G/5G providers put customers on a private or CG-NAT address.

For double NAT, the first choice is putting the provider's gateway in bridge mode so your router gets the public address. If the gateway can't do that, run your own router in access point (AP) mode. It stops forwarding ports in that mode (NETGEAR greys the page out), so the rule goes on the gateway instead. If the first box is a separate router and not the provider's gateway, NETGEAR's first choice is to remove it. TP-Link also offers a workaround: open the same port on the upstream device too, pointing at your router.

For CG-NAT, nothing in your house will fix it. Ask your provider for a public IP address, or ask them to forward the port on their side. Xbox's blunt take is that if they can't give you one, you'll have to change ISPs.

Is port forwarding safe?

For a single game port pointing at a server with a password on it, the risk is manageable. It isn't zero, though, and the companies that make this hardware are upfront about why.

Linksys describes a forwarded port as "a point of entry." Automated bots can discover open ports, and devices with weak passwords or outdated software are especially vulnerable. Microsoft says opening a port "might create opportunities for hackers or malware." On the other side, TP-Link points out that forwarding keeps the rest of your network safe because other services stay invisible from the internet. You're opening one door you chose, not the whole house.

That's also why forwarding is the safest of the three ways to let traffic in. NETGEAR ranks them like this: port forwarding opens only the specific ports needed. UPnP is "not as secure as port forwarding," since a worm or malware can use it to open ports without asking, but it keeps more firewall protection than a DMZ. A DMZ "removes all of your router's firewall protection for a device." ASUS says of enabling DMZ: "We highly suggest not to do so." If you were tempted to throw your PC in the DMZ because the rule wasn't working, go back to the checks above instead.

The habits that matter:

  • Lock the server. Valheim has -password, Palworld has ServerPassword, Project Zomboid has Password= (plus Open=false for a whitelist), and Minecraft has the /whitelist command. An open port leading to a server that only lets your friends in is a much less interesting target.
  • Forward only what the game needs. One or two ports, not a huge range "to be safe."
  • Keep router firmware updated. TP-Link and ASUS both note that new firmware carries fixes for known security holes. Keep the server software current too.
  • Delete the rule when the server is retired. Linksys says a forward should never be "left open after it is needed." On NETGEAR, select the service on the Port Forwarding/Port Triggering page and click Delete Service. In the Linksys app, the rule's slider turns it off. If you made a Windows port rule, select it in Inbound Rules and choose Disable Rule.

FAQ

Why did my port forward stop working after a few weeks?

Usually one of two addresses changed. If you skipped the reservation, the server PC may have picked up a new local IP, so the rule now points at nothing. Or your provider gave your router a new WAN IP, and your friends are still typing the old one. Check both before you touch the rule itself.

Can two devices use the same port?

Not through one rule. A port can be forwarded to only one device. If two PCs on your network each need the same port, TP-Link's approach is two rules with different external ports, each pointing at a different device. For a second Xbox, there's Alternate port selection under Advanced settings in the console's network settings.

Will the address my friends use change?

It can. Your provider assigns the WAN IP dynamically, so it may be different after a router restart or just over time. If friends suddenly can't connect and nothing else changed, check the router's status page and send them the new address.

Should I pick TCP, UDP or both if the game doesn't say?

In the router, pick the combined option: ALL on TP-Link, TCP/UDP on NETGEAR, Both on Linksys. If the game does name a protocol, like UDP for Palworld and Valheim or TCP for Minecraft: Java Edition, use only that one. In Windows Firewall a port rule has to be either TCP or UDP, so either make two rules or allow the app instead.

Level complete

// Next level

Keep playing