Skip to content

Port forwarding, and why it keeps not working

Port forwarding tells your router where to send traffic nobody asked for. It's the classic fix for hosting a game, and here's every reason it quietly fails.

6 min read

Your router drops connections nobody inside asked for. (If that's news, start with NAT, it's a five-minute read.) A port forward is how you make an exception. You tell the router, ahead of time, where one specific kind of knock should go.

A port forward on a home router A friend connects to the router's public address on port 8211. The router has a rule sending 8211 to the game server's private address, so the connection reaches the server. Your friendjoins 203.0.113.7:8211Your routerpublic 203.0.113.7rule: 8211/udp → 192.168.1.30Game server192.168.1.30:821112

A port forward is a standing instruction: this port, that machine.

  1. 1Your friend's game connects to your public address on port 8211.
  2. 2The router checks its rules, finds one for 8211, and passes the connection to the server at 192.168.1.30.

Setting one up

Every router's menus are different, and every one of them hides this in a different place. The steps are the same everywhere though:

  1. Give the server a fixed local address. Look for DHCP reservation or static lease in the router. If you skip this, the server's address changes one day and your forward points at nothing.
  2. Find the ports your game uses, and whether they're TCP, UDP, or both. The game's server docs will say. A few common ones are in the table below.
  3. Log in to the router. Usually 192.168.1.1 or 192.168.0.1, or whatever's on the sticker.
  4. Add the rule. It might be called Port Forwarding, Virtual Server, NAT rules or Applications. Fill in the port, the protocol, and the server's local address.
  5. Test from outside. Phone on mobile data, Wi-Fi off. Testing from your own network is testing a different path and it'll lie to you.
Default server ports for some common games
GameDefault ports
Minecraft (Java)25565 TCP
Palworld8211 UDP
Valheim2456-2457 UDP
7 Days to Die26900 TCP, 26900-26903 UDP

Those are defaults. If you changed the port in the server's config, forward the one you changed it to.

Why it keeps not working

You did all of that and it still says can't connect. Go down this list, it's in rough order of how often each one is the culprit:

  1. Wrong protocol. Most games talk UDP. A TCP-only forward for a UDP game does exactly nothing.
  2. The server moved. No DHCP reservation, the PC rebooted, got a new local address, and the forward is pointing at an empty seat.
  3. Firewall on the server machine. Windows asks when a server first starts listening. If that prompt got dismissed, incoming connections are blocked on the PC itself, forward or no forward.
  4. You tested from inside. Lots of routers can't loop traffic back to themselves. It fails for you and works fine for everyone else.
  5. The server isn't listening where you think. Not running, crashed on startup, or set to a different port than the one you forwarded.
  6. There's another router in front of yours. Your forward is on the second front desk and the first one never heard about it. That's double NAT.
  7. Your ISP never gave you a public address. If your router's WAN address starts with 100.64 to 100.127, no forward on your router can ever work. That's CGNAT.
  8. Your ISP blocks the port. Rare for game ports, more common for things like 80 and 25. Worth knowing it exists.

What about UPnP?

UPnP lets a program ask your router to open a port for it, automatically. Some games use it, and when it works it's lovely. It's also switched off on a lot of routers, on purpose, because it lets any program on your network open ports, including ones you'd rather didn't. And like every other trick on this page, it can't get you past CGNAT.

Is it safe?

A port forward exposes one program, on one port, to the whole internet. That's fine for a game server you keep updated. A few rules keep it that way:

  • Forward only the ports the game actually needs.
  • Never forward an admin or RCON port. That's a remote control for your server, and it'll get found.
  • Keep the server software updated, and delete the forward when you stop hosting.

One more thing people don't think about: anyone who joins now knows your home IP address. Usually that's fine. If you're hosting for strangers, it's worth a thought.

Or skip all of this

Void Sluice gets players into a server behind any of these walls without you touching the router. Your server dials out, we hand you an address, your friends connect.

Keep reading