AT&T Port Forwarding: BGW320 and BGW210 Guide
Create and assign a NAT/Gaming service on an AT&T gateway, enter the right global and base host ports, and fix IP Passthrough or closed-port problems.
Quick Answer
While connected to the AT&T gateway, open http://192.168.1.254 and choose Firewall > NAT/Gaming. Enter the Device Access Code from the gateway label. Select an existing service or create Custom Services with a service name, Global Port Range, Base Host Port, and TCP, UDP, or TCP/UDP. Return to NAT/Gaming, choose the service and target under Needed by Device, then Add and Save.
Double NAT or no public IPv4? Compare VPN optionsPlan Your AT&T NAT/Gaming Service
Enter the service details to create a field-by-field reference. You still need to create the custom service in NAT/Gaming and assign it under Needed by Device.
Reference only: enter these values manually in the router or provider app. Copying them does not import or apply the settings.
AT&T Settings at a Glance
Use the values required by the application. A correct menu path cannot compensate for a wrong destination port or an offline service.
| Setting | Value | Why it matters |
|---|---|---|
| Gateway address | http://192.168.1.254 | Open this address while connected to the AT&T gateway. |
| Current menu | Firewall > NAT/Gaming | Older gateways may label the area Applications, Pinholes and DMZ. |
| Authentication | Device Access Code | Use the code printed on the gateway label, not the WiFi password. |
| Custom service | Global range + base host port + protocol | Assign the saved service to the correct Needed by Device entry. |
How to Port Forward on an AT&T Router
BGW320 and BGW210 gateways normally use Firewall > NAT/Gaming. Older gateways may call the equivalent area Applications, Pinholes and DMZ.
Open the AT&T gateway page
Connect to the AT&T gateway and browse to http://192.168.1.254. If it does not open, check the default gateway address in the device network settings and make sure you are not connected through a separate router.
Open Firewall and NAT/Gaming
Choose Firewall, then NAT/Gaming. Older models may use Applications, Pinholes and DMZ, but the goal is still to define a service and assign it to a destination device.
Enter the Device Access Code
Use the Device Access Code printed on the gateway label, not the WiFi password. If the access code was changed, use the current custom code.
Choose or create the service
Select a matching preset, or open Custom Services and enter a clear Service Name, Global Port Range, Base Host Port, and TCP, UDP, or TCP/UDP. Save the custom service.
Assign the service under Needed by Device
Return to the main NAT/Gaming screen, choose the saved service, select the computer, console, or server under Needed by Device, and click Add. Creating a service alone does not attach it to a device.
Save and test from an outside connection
Keep the destination application running, confirm local access, and test from cellular data or another network. Match the protocol and current public IPv4 address.
Test the Port Forward Correctly
Run these checks in order before editing the rule again.
Start the server, game, camera, or app first. A checker cannot find an open port when nothing is listening on the destination device.
Confirm the service works from another device on the home network before testing the internet path.
Test from cellular data or another outside connection. A same-Wi-Fi test can fail when the gateway does not support NAT loopback.
Match the protocol. Most browser-based port checkers test TCP and cannot prove that a UDP-only service is reachable.
AT&T Port Forwarding Not Working
Match the symptom first. Recreating the same rule will not fix a missing listener, wrong device, or upstream NAT layer.
| Symptom | Likely cause | What to do |
|---|---|---|
| 192.168.1.254 does not open | The device is on another router, using mobile data, or the gateway LAN address was changed. | Connect directly to the AT&T gateway and use the default gateway address shown by the device network settings. |
| The Device Access Code is rejected | The WiFi password was entered, the label code was mistyped, or a custom access code is active. | Use the Device Access Code from the gateway label and check capitalization. Use the current custom code if it was changed. |
| The service exists but is not assigned | Creating Custom Services does not automatically attach the rule to a destination. | Return to NAT/Gaming, select the service, choose the target under Needed by Device, and click Add. |
| The wrong internal port is reached | Base Host Port does not match the application's listening port. | Set Base Host Port to the first destination port. For a same-port mapping, match it to the start of Global Port Range. |
| A personal router is behind the gateway | Both devices are translating addresses. | Configure AT&T IP Passthrough for the personal router and keep the inbound rule on the device that owns the public-facing route. |
| The rule is correct but the port remains closed | The listener or firewall is blocking it, or another upstream NAT layer is present. | Verify local access first, then compare the gateway broadband IPv4 address with the public IPv4. |
BGW320, BGW210, Older Gateways, and IP Passthrough
BGW320 and BGW210 gateways normally use Firewall > NAT/Gaming. Older AT&T interfaces may use Applications, Pinholes and DMZ for the same job. When a personal router should manage the home network, use IP Passthrough so inbound traffic is not trapped behind two NAT layers. AT&T Fiber does not change the basic NAT/Gaming workflow.
When a VPN Is the Shorter Path
If you cannot control the active router, cannot obtain a public IPv4 address, or need an application-specific incoming port, a VPN with explicit port-forwarding support may be faster than changing the local gateway setup. It does not repair AT&T settings; the application must use the port assigned by the VPN.
A standard VPN connection without incoming port support will not make a server reachable. Check platform, region, and plan support before setup.
PureVPN
An option when you need an incoming port add-on. Confirm that the plan, server location, and device you use support port forwarding.
Check availabilityPrivate Internet Access
Provides an assigned incoming port in supported regions. Your application must listen on the port shown by the VPN client.
Check availabilityProton VPN
Supports port forwarding on eligible plans and platforms. Keep the VPN connected and use the assigned public port.
Check availabilityPort Forwarding Safety
- Forward only the port or narrow range documented by the application. Do not open a large range to make troubleshooting easier.
- Keep the destination operating system, application, and gateway firmware updated.
- Leave the device firewall enabled and add a narrow inbound rule for the same protocol and port.
- Remove rules you no longer use. Do not place a computer, NAS, or console in DMZ as a shortcut.
AT&T Port Forwarding FAQ
What address opens AT&T port forwarding settings?
Open http://192.168.1.254 while connected to the AT&T gateway, then choose Firewall > NAT/Gaming. The device default gateway setting reveals the current address if it was changed.
Is the Device Access Code the WiFi password?
No. Use the Device Access Code printed on the gateway label. It is separate from the WiFi network name and password.
How do I port forward on an AT&T BGW320 or BGW210?
Open 192.168.1.254, choose Firewall > NAT/Gaming, create or select a service, and assign it to the target under Needed by Device. Save the assignment before testing.
Why is AT&T port forwarding not working?
Common causes are a saved service that was never assigned, a wrong Base Host Port, an offline listener, a device firewall, Double NAT from a personal router, or an address mismatch upstream.
Do I need IP Passthrough with a personal router?
Usually yes when the personal router should be the primary router. IP Passthrough avoids keeping both the AT&T gateway and personal router as separate NAT layers.
Is AT&T Fiber port forwarding different?
The access technology is different, but BGW320 and BGW210 gateways still use the NAT/Gaming workflow. Your exact gateway model and whether a personal router is present matter more than Fiber versus DSL.
Official and Technical Sources
These sources document the provider controls, local firewall behavior, and the shared IPv4 range used when diagnosing CGNAT.