Short answer: port forwarding tells your router to send incoming connections on a particular port to one device on your network. You need it only when something outside your home has to start a connection in, such as a game server you host, a remote-access tool or some cameras. Open only the ports you need, and remove the rule when you’re done.

Why your router blocks incoming connections

Your devices use private addresses that aren’t reachable from the internet directly; ranges such as 192.168.0.0/16 and 10.0.0.0/8 are set aside for exactly that. Your router shares one public address between them using NAT. In traditional NAT, connections start from inside, and incoming ones are allowed only by exception, through fixed mappings. Port forwarding is that exception.

When you need it

  • Hosting a game server, a media server or a website at home.
  • Remote access to a computer or storage device, if the product doesn’t offer a cloud relay.
  • Some games and consoles, when they report a restricted NAT type.

Most everyday use, including browsing, streaming and most online games, works without it.

How to set it up

The address reservation matters because DHCP allocates reusable addresses, so a device can get a different one later. You’ll find these settings after you log in to your router.

Why it doesn’t work

  • Carrier-grade NAT (CGNAT). Some providers put customers behind their own NAT. The range 100.64.0.0/10 is set aside for the links between that equipment and your router. If your router’s internet (WAN) address starts with 100.64 to 100.127, or is any private address, a forward on your router alone can’t work. Ask your provider for a public address.
  • Double NAT. If your provider’s modem is also a router, you have two NATs in a row. TP-Link’s fix is to put the modem router in bridge mode. See double NAT explained.

Doing it safely

Every forwarded port is a door into your network, so open as few as possible, point them only at devices that get security updates, and never forward the router’s own admin page to the internet. Our router security checklist covers remote management and UPnP. If you’re forwarding ports to fix lag rather than connectivity, see how to reduce ping and lag instead.