Guide
16 min readAug 06, 2026

TP-Link Port Forwarding: Build the Right Archer, Deco or Omada Rule

Choose your TP-Link interface, generate the exact TCP or UDP rule, compare the router WAN address with your public IPv4, and find the layer that keeps a port closed.

Quick Answer

On a current Archer router, open Advanced > NAT Forwarding > Port Forwarding or Virtual Servers. Older routers use Forwarding > Virtual Servers, while Deco uses More > Advanced > NAT Forwarding > Port Forwarding in the app. Reserve the device's local IP, enter the required TCP or UDP ports, then test from mobile data while the service is running. If CGNAT or an upstream router you cannot control blocks inbound traffic and the ISP cannot provide a public IPv4 address, another TP-Link rule will not solve the problem. An inbound-capable VPN can carry an assigned port through an app-managed tunnel, giving one or several services a reachable port with little setup; a small public server provides a fixed public entry point, more ports and more control when you can manage Linux and a reverse tunnel.

Interactive setup

Build your TP-Link port forwarding rule

Choose the interface you see, enter the values required by your app, and compare the router WAN address with the public IPv4 observed from this browser. The tool creates a reference rule; it does not sign in to or change your router.

Protocol

Rule to enter

Menu path
Advanced > NAT Forwarding > Port Forwarding
Rule name
Home server
External Port
25565
Device IP Address
192.168.0.50
Internal Port
25565
Protocol
TCP

Use only the ports documented by your application. The generated rule does not prove the port is open; the service and device firewall must also accept the connection.

Enter the TP-Link WAN IPv4 address

Find it on the router Internet or Status page. The comparison tells you whether the TP-Link device is the first router facing the internet.

Next: Run the public-path check, then enter the WAN address shown by TP-Link.

The observed UDP mapping belongs to this diagnostic session. It is not the application port you entered above and is not an open-port test.

Choose the menu that matches your TP-Link device

TP-Link has used several names for the same permanent inbound mapping. Choose by the interface in front of you, not only by the model printed on the router.

Omada Controller 5.x commonly uses Settings > Transmission > NAT > Port Forwarding. Current Controller 6.x documentation uses Network Config. Standalone gateway labels can differ, so confirm the hardware version in the official manual if neither path appears.

Before you add the rule

Start the service locally

Connect to the service from another device on the same home network. If local access fails, the router rule cannot fix it.

Confirm the exact port and protocol

Use the application vendor documentation. TCP and UDP are different paths even when they use the same number.

Keep the destination IP stable

Create a DHCP address reservation so the device does not receive a different local IPv4 after a restart.

Find the real internet router

If TP-Link is only an access point or extender, add the rule on the modem-router or gateway that owns the WAN connection.

How to set up TP-Link port forwarding

1

Reserve the destination device address

Open the TP-Link client or DHCP list, find the device by name and MAC address, and reserve its current local IPv4. Reconnect the device if the router asks you to apply the reservation.

2

Open the matching Port Forwarding page

Use the interface selector above. On Archer this may be Port Forwarding or Virtual Servers; on Deco it is in the app; on Omada it is in the NAT section.

3

Create a narrow rule

Enter a clear name, the external port, the destination device, the internal port and the exact protocol. For one port, enter the same number in start and end fields.

4

Save and confirm the rule is enabled

Some older interfaces have a separate Enabled or Status switch. Do not use DMZ just to solve a one-port problem.

5

Allow the service on the destination device

Permit the app or its internal port in Windows Firewall, the Linux firewall, the NAS firewall or the device security settings.

6

Test from outside your Wi-Fi

Leave the service running, turn off Wi-Fi on a phone, and connect through mobile data or another internet connection.

Test the port without getting a false result

1. Test the local service first

Use the destination device local IP and port from another device on the same LAN. A local failure points to the service or device firewall.

2. Keep the application listening

A TCP checker sees an open port only when an application is actively accepting connections on that port.

3. Move outside the home network

Testing the public address from the same Wi-Fi may fail when the router does not support NAT loopback. Use mobile data.

4. Test UDP with the real application

UDP has no TCP-style handshake. A generic scanner may receive no reply even when the rule is correct, so use an outside game client, VPN client or application-specific test.

Need a second reading of your NAT behavior and public IPv4? Run the main NAT test before changing more router settings.

Check NAT type and public IPv4

Rule saved, but the port is still closed

Stop at the first failed check. Changing several layers at once makes the real cause harder to find.

1

Does the service work on the local network?

If no: Start the service, confirm its listening port, and fix the destination device firewall.

2

Does the rule point to the current device IP and exact TCP/UDP protocol?

If no: Correct the rule and add a DHCP reservation.

3

Is the TP-Link WAN address private, such as 192.168.x.x or 10.x.x.x?

If yes: There is another router upstream. Bridge it, use AP mode, or forward through both routers.

4

Is the WAN address between 100.64.0.0 and 100.127.255.255?

If yes: The ISP is using CGNAT. A normal TP-Link rule cannot receive the unsolicited internet connection.

5

Does the public address work from mobile data but not from home Wi-Fi?

If yes: The router probably lacks NAT loopback. The outside path is working; use the local address while at home.

IPv6 uses a firewall rule, not the same IPv4 port mapping

If the service has a public IPv6 address, there is normally no private-to-public IPv4 translation to configure. Allow only the required protocol and destination port in the router and device IPv6 firewalls, then test the IPv6 address from another network. Do not disable the entire firewall.

Only after the upstream path is confirmed blocked

When the TP-Link rule cannot receive the connection

The Quick Answer above defines when this alternative path applies. A port-forwarding VPN is the simpler choice when the target app can run on the VPN-connected device and accept the provider's port. A public server gives you a fixed public entry point, more ports and more control, but requires basic Linux, firewall and reverse-tunnel administration.

Affiliate disclosure: We may earn a commission when you purchase through links in this section, at no extra cost to you.

Simpler app-based options

The existing problem is that the ISP-side NAT never sends the connection to TP-Link. These services terminate the inbound connection on their network and carry it through the VPN tunnel, giving the application a reachable port without changing the ISP gateway.

Best for exactly 1 port

Proton VPN

The quickest fit when one application can use the port assigned by the VPN app.

  • All Proton VPN apps are open source and independently audited
  • Five consecutive annual third-party no-logs audits published through 2026
  • Official port-forwarding support on paid Windows, macOS and Linux apps
  • 30-day refund policy for eligible paid-plan purchases
Use for 2–10 chosen ports

PureVPN

The fit when several services must keep their documented port numbers.

  • 3M+ users and 17 years in cybersecurity according to PureVPN
  • Fourth consecutive independent no-log policy assessment
  • ISO 27001-certified information security management program
  • 31-day money-back guarantee for eligible new purchases

Advanced fixed public entry points

A small VPS can run FRP or another authenticated reverse tunnel. The home device makes the outbound tunnel, while remote users connect to the server's stable public address. This replaces a dynamic VPN port with an endpoint and firewall you control.

Read the official FRP documentation
First server choice
New users get $300

Vultr

A general-purpose public server for a fixed FRP endpoint and custom TCP or UDP rules.

  • Operating since 2014 with more than a decade in cloud infrastructure
  • 33 cloud data center regions across six continents as of 2026
  • Official API, CLI and Terraform tooling for repeatable management
  • New-user $300 reward shown through the current referral offer
Asia-route alternative

DMIT

A public VM alternative when routes toward users in Asia are the main consideration.

  • Purpose-built routes toward China Telecom, China Unicom and China Mobile
  • Locations include Los Angeles, San Jose, Hong Kong and Tokyo
  • Listed VM plans include public IPv4 and an IPv6 /64
  • Documented 3-day full-refund window for eligible new VM orders

Promotional credits, refund eligibility, supported VPN locations and port availability can change. The linked official pages and checkout terms are the source of truth at purchase time.

Keep the forwarded service safe

  • Forward only the exact port and protocol the application needs.
  • Update the router firmware, operating system and exposed service.
  • Use strong authentication and remove default accounts.
  • Avoid exposing router, NAS or remote-desktop admin panels directly.
  • Restrict source IP addresses when the same trusted users connect.
  • Delete the rule when the service is no longer needed.

TP-Link port forwarding questions

Authoritative sources

Menu paths and troubleshooting checks were verified against current TP-Link and Omada documentation. Address classifications come from the IETF, and port names come from IANA.

Technical details and commercial evidence last verified August 6, 2026.

Share this article