Warframe Strict NAT Detected? Fix the Connection
Warframe strict NAT detected means your network is restricting peer connections, which can disrupt squad invites, matchmaking and voice chat.
Start where the connection breaks
Use the route that matches what you have already tried. Change one setting at a time and record the game’s result before continuing.
Different setup? Go to PS5 / Xbox, two PCs at home, hotspot / shared internet, VPN, or check our Destiny 2 strict NAT guide.
Fix UPnP before adding manual rules
Open Analyze Network in Warframe’s in-game settings. Save the full warning, including any UDP port numbers and local IP address it displays. Restart the game and your home router once if you have not already done so, then check whether the warning returns. After any change, if it clears, go to squad verification.
On Windows, open Windows Security → Firewall & network protection → Allow an app through firewall. Allow the installed Warframe app on the network profile shown as active. If you use a separate security app, check its exception there instead. Keep the firewall enabled, as recommended in the basic troubleshooting guide.
“Please ensure your firewall permits UDP ports 4950 and 4955”
If you use port-specific firewall rules, allow the UDP pair shown by your game. A TCP rule with the same numbers does not allow UDP. The warning can also remain when the firewall is correct but the router has no working mapping; check UPnP next.
Once the app exception is correct, VPN users can continue with VPN settings. For a home connection, UPnP and NAT-PMP let the game request router port mappings automatically. Choose the case below that matches your warning, or check existing manual rules.
No UPnP or NAT-PMP detected
- On PC, open Options → System, enable UPnP and/or NAT-PMP, then confirm.
- Sign in to your router’s app or admin page and enable the corresponding feature. Use the access instructions on its label or in its manual; router menus vary.
- Restart Warframe and rerun its network analysis. If the warning clears, test squad invites before changing anything else.
If the router does not support UPnP or NAT-PMP, use the manual steps below. If you cannot access its settings, use the network-operator request. Official UPnP instructions.
UPnP malfunctioning, even though it is enabled
In the router’s port-mapping list, check whether Warframe’s ports point to an old device address or another PC. Correct only the conflicting entries you recognize. Also check the manufacturer’s firmware updates, as Warframe recommends. If the warning remains, use manual forwarding below.
Warframe port forwarding: match both UDP ports
The “Please forward UDP ports” message gives you the pair and destination IP to use. Warframe ports 4950 and 4955 are the usual pair, but the numbers shown in your game take priority. They are two separate ports, not a request to open every port between them. Check the official port guidance.
If two PCs play on this connection, choose a different pair for each PC first. If one PC reports “ports in use,” resolve that conflict before forwarding.
Sign in to your router and find Port Forwarding, sometimes called Virtual Server or NAT/Gaming. Use its manual for access instructions; our TP-Link guide shows an example. Update existing rules for this pair rather than adding duplicates.
- Keep the device’s local address stable. Find the gaming device in the router’s connected-device list and reserve its current IPv4 under DHCP / Address Reservation. This keeps its LAN IP—the address inside your home network—from changing. Use that reserved address in the rules.
- Add two UDP rules. For each port, use the same external and internal number, with your gaming device’s reserved IP as the destination.
- Use one mapping method. Warframe’s manual setup instructions call for disabling router UPnP and, on PC, in-game UPnP/NAT-PMP. A router-wide change also affects automatic mappings used by other devices.
- Save the rules and restart Warframe. Use the checks below to verify the result. If you later change the in-game pair, update both router rules too.
Example only: gaming device 192.168.1.50, pair 4950 / 4955
UDP 4950 → 192.168.1.50:4950
UDP 4955 → 192.168.1.50:4955These rules cover the pair identified by the Strict NAT warning. For additional Steam or console service ports, consult Warframe’s platform-specific port list.
Test in Warframe, then test with a squad
- Run Analyze Network in the game’s settings. Record whether Strict NAT remains and any other message.
- Try invites in both directions. Join a friend, then have them join you. Load into a mission together and check voice chat if you use it.
- If an invite fails, try another friend. This helps distinguish one player’s connection problem from failures across several squads.
- Once it works, restart and repeat. With multiple home devices, test simultaneously. With a VPN, repeat after reconnecting.
- Warning gone and invites work: save the settings and stop.
- Strict NAT remains: on a home connection, check CGNAT or a second router. On a VPN, check the VPN route. If you have already checked that route, send the results for support.
- Warning gone but invites fail: if only one friend fails, ask them to check their connection. If several fail, report a matchmaking issue instead of adding more port rules.
Can I use a website to test these UDP ports?
A TCP port checker cannot validate UDP rules. A UDP scanner can return “open|filtered” without a reply, as Nmap explains. NAT Checker’s browser result also does not test Warframe’s ports. Use the in-game analysis and squad checks above.
Warframe port forwarding not working? Check upstream
Your provider may share one public internet address among several customers. This is carrier-grade NAT (CGNAT), and your router cannot control its incoming mappings. A second router in your home can create a similar obstacle. If you use shared internet and cannot access its main router, skip to what to ask the network operator.
Otherwise, open your router’s internet-status page and find its WAN IPv4—the address on the provider-facing side, not your gaming device’s local address. Compare it with the public IPv4 of your home connection using our CGNAT check instructions. Make this comparison outside the VPN route.
- WAN is 100.64.0.0–100.127.255.255
- This is shared address space used for CGNAT. Ask your ISP whether it can supply a public IPv4 with incoming UDP access.
- WAN is 10.x, 172.16–31.x or 192.168.x
- Another private router sits upstream. If you control it, configure both forwarding hops or use its supported bridge mode. Otherwise, contact the network operator.
- WAN matches the home public IPv4
- If the device address, UDP pair and firewall checks above are already correct, ask the ISP whether incoming UDP is filtered. If it confirms no filtering, use the support instructions.
- The addresses differ, but neither range fits
- Ask the ISP to explain the mismatch before changing more rules. A mismatch alone does not identify which device or service is translating the address.
If you find two routers, our double NAT guide explains the next steps. The shared-address range above comes from RFC 6598.
What to ask your ISP or network operator
“Warframe reports Strict NAT. Is my connection behind CGNAT? Can you allow incoming UDP traffic for the two ports shown by the game, or provide a public IPv4 so I can forward them on my router?” A dynamic public IPv4 can work; a static address is not inherently required.
If the ISP supplies a public IPv4 or you remove a second router, check the rules on the router now handling your connection, then retest. If inbound access is unavailable, consider the VPN route; if you cannot change routes, you will need the operator’s help to remove this restriction.
Give each PC its own UDP pair
Two PCs cannot share the same fixed incoming port mapping to different LAN addresses. On the second PC, go to Options → System → Network Ports [UDP] and select another available pair, such as 4960 / 4965. Leave the first on 4950 / 4955 if that is its current setting.
If using manual forwarding, update each PC’s rules to match its new pair before testing. If using UPnP, let the game request the new mappings. Restart both games and test with both running. Official multiple-device guidance.
Only one PC, but “ports in use”?
Another program may already own the pair. Close it if you can identify it; otherwise, choose another pair under Options → System → Network Ports [UDP]. Update any manual rules, restart Warframe and test again. Official port-conflict help.
Warframe strict NAT on PS5 or Xbox
Sign in to your router’s app or admin page, enable UPnP if supported, then restart Warframe and run Analyze Network in the game’s settings. The in-game UPnP toggles used on PC will not appear on a console.
If the warning remains, follow the manual forwarding steps using the console’s LAN IP and the UDP pair in Warframe’s warning. Check the official list for your platform for any additional service ports. If you already tried those rules, go to the CGNAT and double NAT checks.
After each change, verify inside Warframe. A PlayStation NAT Type 2 or Xbox Moderate label is a separate result; it does not establish that Warframe’s squad connections work.
For wider platform connection problems, use the PlayStation NAT guide or Xbox NAT guide. For two consoles, check each device’s available network settings and mappings rather than forwarding the same external pair to both.
Can a VPN fix Warframe strict NAT?
Already using a VPN? Compare the game with it disconnected, if that is acceptable for your setup. If it works only without the VPN, use that connection or adjust the VPN’s NAT settings below. If both routes fail, complete the app firewall check if you have not already done so. Home-router rules cannot open ports at the VPN’s exit.
Considering a VPN because of CGNAT? First ask your ISP about inbound access. If that is unavailable, a less restrictive VPN NAT mode or explicit forwarding of Warframe’s UDP pair may help. Check whether your existing plan supports either option before buying another subscription.
On PS5 or Xbox, the console’s traffic must pass through a supported VPN router or shared VPN connection. Running a VPN on a nearby PC is not enough, so confirm support for your setup before choosing a plan.
This page contains affiliate links. If you sign up through them, NAT Checker may earn a commission at no extra cost to you.
Proton VPN: try Moderate NAT on a paid plan
On Windows, go to Settings → Connection → Advanced settings → NAT type → Moderate, then apply and retest. Other apps have their own controls in Proton’s Moderate NAT instructions. This feature requires a paid plan and cannot run alongside port forwarding.
Proton’s standard port-forwarding feature assigns a random active port, so it cannot simply replace Warframe’s selected UDP pair. For this approach, leave forwarding off and test Moderate NAT using the game’s result.
Check Proton VPN paid plansPureVPN: selected ports with the forwarding add-on
If you need explicit mappings, confirm support for both Warframe UDP ports on your operating system, VPN protocol and chosen location before purchasing. With the add-on active, select the game’s pair, connect to a PF-supported location and rerun Warframe’s analysis. Follow the PureVPN setup instructions.
Check PureVPN + port forwardingWhichever route you use, test invites and mission stability, including after a VPN reconnect. A VPN can add latency, so keep it only if the connection works better for you. See our VPN port-forwarding comparison for more setup details.
Still failing after the route checks?
If the failure occurs only on a VPN, send its support team the location, protocol, NAT mode or forwarded pair, and the game’s result. If it also occurs without the VPN, send Warframe Support the warning, platform, UDP pair, router model and which friends or missions fail.
On PC, reproduce the failure, run Analyze Network, then use launcher gear → Get Logs. Attach the logs and your completed checklist to the private ticket. This gives support the results of the checks you have already done.
Warframe strict NAT FAQ
Can I still play Warframe with strict NAT?
You may still be able to log in or join some squads, but connections to other players can be less reliable. Test invites and missions with more than one friend. A working chat window or one successful mission does not show that every peer can reach you.
Is the Warframe strict NAT warning a bug?
The warning alone cannot identify a game bug. Check whether a VPN, router update, changed LAN IP or second gaming device coincided with the problem. If it persists after controlled checks, send the network-analysis message and your results to Warframe Support instead of repeatedly resetting the router.