Your IP address:
Provider:
...

What is NAT? Home routers and port forwarding

NAT, or Network Address Translation, changes packet addresses at a network boundary. In a home network, a router commonly lets several privately addressed IPv4 devices use one external IPv4 address. It often changes port numbers as well so that it can distinguish multiple simultaneous connections.

Following an outgoing request

Imagine a laptop at 192.168.1.20 opening a website through its router. The router records a mapping between the laptop’s internal address and port and the router’s external address and chosen port. The website sees the external address and replies to it. The router uses its mapping to direct the reply to the correct laptop, even if another phone contacted the same site at the same time. This is a simplified example of common address and port translation; exact behaviour depends on the router. RFC 3022 describes the basic NAT model.

Why an incoming connection may fail

An unsolicited request from outside has no matching entry created by an outgoing connection. To host a service, an administrator may configure a rule that forwards an external port to a local device and port. For example, external TCP port 8443 could point to a particular internal web application. The rule must specify the correct transport: TCP and UDP ports are separate. Before opening it, confirm that the service is maintained, authenticated and actually needs public reachability. An apparently open port does not prove that the application itself behaves correctly.

NAT is not a firewall policy

Translation describes how addresses are changed and replies are associated with connections. Firewall policy decides which traffic is allowed. A home router often combines both functions, which makes them easy to confuse. Do not rely on NAT as the sole security boundary: a forwarding rule, automatic mapping feature or configuration mistake can change exposure. Test the actual service after configuring it, not merely the port number. The 2ip port checker can provide an outside signal, but it cannot confirm that a service uses strong authentication.

Checking a failed forwarding rule

First check the server’s local address and whether it responds from the same LAN. Then verify the router’s port and transport rule and the server’s own firewall. Compare the router’s external address with the address observed by an Internet site. If another router or the provider’s carrier-grade NAT lies upstream, the home rule alone may not be enough. Do not switch off the entire firewall just to diagnose the problem; inspect the narrow rule and the application logs instead.