Moonlight Port Forwarding: Complete Rules, Sunshine Setup & Fixes
Configure Moonlight and Sunshine port forwarding to stream your PC games over the internet, troubleshoot failed remote connections, and bypass CGNAT.
Quick answer
To stream Moonlight or Sunshine outside your home Wi-Fi, forward TCP ports 47984, 47989, 48010 and UDP ports 47998, 47999, 48000, 48002, 48010 to your host PC’s static LAN IP. If external connections still fail due to ISP CGNAT or strict hotel/mobile firewalls, standard port forwarding will not work—use PureVPN (which supports multi-port forwarding across this exact port range) or Proton VPN to establish a reachable tunnel.
Moonlight & Sunshine Port Forwarding: Stream PC Games Anywhere
Nothing beats the buttery-smooth experience of streaming your gaming rig to a Steam Deck, laptop, or mobile screen at 4K 120 FPS inside your living room. But the moment you leave home and try streaming from a hotel, university dorm, or cellular connection, you hit a brick wall: “Moonlight/Sunshine works only at home – cannot connect remotely”.
Configuring moonlight port forwarding (and setting up sunshine port forwarding) lets you bypass local Wi-Fi limits and stream your host PC across the public internet. Whether you need the exact moonlight port forwarding rules, are troubleshooting why your port forward moonlight setup shows a moonlight port forwarding error, or are dealing with ISP carrier blocks, this guide gives you the verified roadmap.
Looking for alternative remote tools? Compare with our Parsec error 6023 fix or learn how to use Moonlight without port forwarding.
Moonlight & Sunshine Port Forwarding Rules: Complete Port Matrix
Unlike simple remote desktop protocols like RDP (which uses a single TCP port 3389), sunshine moonlight port forwarding uses multiple distinct channels to separate administrative handshake data from real-time low-latency audio/video feeds.
If even one UDP port is omitted or blocked, you will experience the classic symptom: your Moonlight client can wake up and pair with the host PC, but clicking a game crashes with an indefinite black screen or handshake timeout.
| Port Number | Protocol | Function in Streaming Pipeline | Required for Remote? |
|---|---|---|---|
| TCP 47984 | TCP | Sunshine Web UI, HTTPS management, & client pairing negotiation | Yes |
| TCP 47989 | TCP | HTTP fallback & host discovery protocol | Yes |
| TCP 48010 | TCP | RTSP control stream & session setup | Yes |
| UDP 47998 | UDP | RTSP video handshake & control channel | Mandatory |
| UDP 47999 | UDP | High-fidelity multichannel audio stream | Mandatory |
| UDP 48000 | UDP | Main high-bitrate video stream (NVENC / QuickSync / AMF) | Mandatory |
| UDP 48002 | UDP | Secondary / fallback video stream channel | Mandatory |
| UDP 48010 | UDP | Gamepad input, mouse movements, keyboard, and haptic rumble | Mandatory |
Note: If you use the legacy Nvidia GameStream service or third-party forks like apollo moonlight (port forwarding for apollo moonlight), the port numbers remain completely identical because Apollo and Sunshine both adhere to the GameStream protocol standard established in official Sunshine port documentation.
How to Configure Moonlight Port Forwarding in Your Router
Follow these sequential steps to establish clean, reliable moonlight streaming port forwarding:
Step 1: Set a Static Internal IP Address for Your Host PC
Before adding router rules, you must prevent your host PC’s local IP address from changing after reboots:
- Sign in to your router gateway (e.g.
192.168.1.1or192.168.0.1). - Navigate to DHCP Server → Address Reservation (or Static IP Lease).
- Locate your gaming PC’s MAC address and bind it to a fixed IPv4 (e.g.,
192.168.1.150).
Step 2: Add Router Port Forwarding Rules
Open your router’s Port Forwarding or Virtual Servers menu. Depending on whether your router allows port ranges or individual rules, configure the two consolidated mappings below:
Rule 1: TCP Handshake & Web Control
Name: Sunshine_TCP
Protocol: TCP
External Ports: 47984, 47989, 48010
Internal IP: 192.168.1.150
Internal Ports: 47984, 47989, 48010
Rule 2: UDP Media & Input Feed
Name: Sunshine_UDP
Protocol: UDP
External Ports: 47998-48002, 48010
Internal IP: 192.168.1.150
Internal Ports: 47998-48002, 48010
Many modern routers allow entering 47984-48010 with protocol set to TCP/UDP (Both) as a single rule. While convenient, creating separate TCP and UDP rules as shown above reduces exposure and avoids unnecessary open sockets. Review our TP-Link port forwarding guide for interface screenshots.
Step 3: Allow Sunshine Through Windows Defender Firewall
A correct router rule will still fail if the Windows host firewall drops incoming packets:
- Press Win + R, type
control firewall.cpl, and press Enter. - Click Allow an app or feature through Windows Defender Firewall.
- Find Sunshine (or click Allow another app and browse to
sunshine.exe). - Check both the Private and Public boxes, then confirm.
Moonlight Port Forwarding Not Working? Fixes for Remote Failure
If your remote device shows a moonlight port forwarding error or you cannot connect when testing outside your house, verify these four primary failure points:
1. Never Test Remote Connections While Connected to the Same Wi-Fi
Most consumer routers do not support NAT Loopback (NAT Hairpinning). If you enter your public WAN IP in the Moonlight client while your phone or laptop is still connected to home Wi-Fi, the router will drop the loopback request. Disconnect Wi-Fi and switch your client to cellular mobile data to perform a true external test.
2. Your ISP Public IP is Dynamic (Use a DDNS Hostname)
Residential ISPs regularly rotate your public IPv4 address. When it changes, Moonlight loses connectivity. Configure a free Dynamic DNS (DDNS) provider like DuckDNS or No-IP on your router, and enter the DDNS hostname (e.g. myhomepc.duckdns.org) inside the Moonlight client instead of a raw IP.
3. Check UPnP Conflicts (Sunshine Automatic Port Forwarding)
Sunshine includes an automatic UPnP forwarding module under Configuration → Network → Port Forwarding. If you configured manual router rules, disable Sunshine’s UPnP option to prevent stale leases from overwriting your manual rules. See our UPnP vs Port Forwarding breakdown.
How to do a Moonlight Check Port Forwarding test
Do not rely on web TCP port scanners to test video streaming ports: web checkers only test TCP (like 47984), while streaming video uses UDP (47998–48000). A port scanner will falsely report UDP as "closed/filtered" because UDP does not send SYN-ACK responses. The only reliable check is launching Moonlight over LTE/5G.
Moonlight Over VPN: The Solution for CGNAT & Strict Networks
What happens when you have configured your router and firewall with 100% precision, but Moonlight remote connection still completely fails?
As highlighted across r/MoonlightStreaming discussions, the culprit is almost universally Carrier-Grade NAT (CGNAT). If your ISP uses CGNAT (RFC 6598), your router WAN IP starts with 100.64.x.x. You share a single IPv4 address with thousands of other homes, meaning incoming internet packets have no route to reach your personal router.
Check whether you are affected with our guide to checking CGNAT and double NAT diagnostic.
Which VPN allows you to port forward all ports for Sunshine/Moonlight?
A frequent dilemma on Reddit is: “Which VPN will allow me to port forward all ports for Sunshine/Moonlight?”
Most standard VPNs fail here because they either offer zero port forwarding (like NordVPN or ExpressVPN) or only grant a single randomly assigned port (unusable for Moonlight’s complex multi-channel audio/video/control matrix). To stream Moonlight remotely over a VPN, you need a provider that supports forwarding specific port ranges or custom multiple ports.
This page contains affiliate links. If you sign up through them, NAT Checker may earn a commission at no extra cost to you.
PureVPN: Dedicated Port Forwarding Add-on for Multi-Port Streaming
Top Pick for Sunshine Multi-Port HostingPureVPN is one of the few commercial VPNs that provides an explicit Port Forwarding Add-on supporting up to 15 custom-selected ports. This allows you to forward the entire Moonlight and Sunshine spectrum—including TCP 47984, 47989, 48010 and the vital UDP 47998–48010 streaming ports—directly through your VPN endpoint.
- Open custom specific ports or port blocks rather than being locked to a single random port.
- Optional Dedicated IP add-on eliminates the need for dynamic DNS (DDNS) completely.
- Bypasses ISP CGNAT, double NAT, and restrictive university/hotel outbound blocks.
- Risk-free 31-day money-back guarantee allows testing your remote streaming setup without financial commitment.
Proton VPN: High-Speed WireGuard Tunneling for Private P2P
Best for Encrypted Low-Latency GamingProton VPN provides high-throughput 10 Gbps servers running custom WireGuard protocol optimizations. If you prefer tunneling your remote client through a secure, high-bandwidth connection without exposing your home IP to public scanning bots, Proton VPN’s paid tier provides ultra-stable performance and P2P routing.
- High-speed WireGuard protocol minimizes frame drops and audio latency during game streams.
- Built-in NAT traversal capability designed for peer-to-peer applications.
- Strict Swiss no-logs policy audited independently for complete privacy.
- 30-day money-back guarantee on all premium plans.
For an architectural comparison of VPN inbound capabilities, read our comprehensive VPN with port forwarding guide and Free VPN port forwarding report.
Moonlight Without Port Forwarding (Tailscale & ZeroTier)
If you are unable or unwilling to open public ports on your router, you can use moonlight without port forwarding via a virtual mesh overlay network.
Services like Tailscale (or ZeroTier) install a lightweight WireGuard agent on both your gaming PC and your remote client (Steam Deck, smartphone, or laptop). Both devices join an encrypted private virtual LAN, assigning each machine a static 100.x.y.z virtual address.
- Pros: Zero open router ports, maximum security against external scanners, functions seamlessly behind CGNAT.
- Cons: Cannot be installed directly on proprietary devices like a modded PS Vita or certain smart TVs without a secondary router gateway; if direct UDP hole-punching fails, traffic routes through relay servers (DERP) which introduces noticeable lag (50–150ms) and frame stutter.
For clients that support it, tailscale moonlight port forwarding elimination is a fantastic free alternative. For gaming consoles, smart TVs, or networks where DERP relay latency ruins streaming, a dedicated port-forwarding VPN like PureVPN remains superior.
Frequently Asked Questions: Moonlight & Sunshine Port Forwarding
What ports does Moonlight and Sunshine need for remote streaming?
Moonlight and Sunshine require TCP ports 47984, 47989, 48010 and UDP ports 47998, 47999, 48000, 48002, 48010. TCP handles web UI, pairing, and handshake negotiation, while UDP carries the high-speed video, audio, and controller input streams.
Is opening Moonlight ports to the public internet safe?
Moonlight requires PIN-based pairing and end-to-end encryption (TLS and AES) before accepting stream sessions. However, exposing the Sunshine web configuration UI (TCP 47984/47989) publicly means you must set a strong administrator password. Many users prefer tunneling over a secure VPN like PureVPN or Tailscale to avoid exposing open listening ports to bot scanners.
Why does Moonlight work on home Wi-Fi but fail remotely?
When Moonlight works locally but fails over external Wi-Fi or mobile data, the four most common culprits are: (1) ISP uses CGNAT preventing inbound traffic, (2) the host LAN IP changed, (3) client cellular network filters high UDP ports, or (4) your public IP changed and DDNS was not configured.
Can you port forward Moonlight behind CGNAT?
No. If your ISP assigns a CGNAT WAN address (100.64.0.0/10), your personal router does not hold a public IPv4, making router port forwarding completely ineffective. You must either request a public IP from your ISP, use an IPv6 direct connection if available, or route traffic through a multi-port forwarding VPN.
Which VPN allows port forwarding all ports for Sunshine/Moonlight?
Because Moonlight requires multiple TCP and UDP ports (47984–48010), standard single-port VPNs fall short. PureVPN with its Port Forwarding Add-on allows configuring multiple custom ports or a port range, making it ideal for Sunshine remote hosting. Proton VPN is another excellent alternative for encrypted P2P tunneling.
Can I use Moonlight without port forwarding?
Yes. ZeroTier and Tailscale create a private peer-to-peer virtual LAN between your client and host without opening any ports on your router. However, in regions where mesh relay servers are blocked, or on restricted networks, a VPN with dedicated port forwarding provides greater reliability.