Updated: October 2026
Someone needs to reach a device on the office network from outside, and the fastest answer on every forum is "just forward the port." It works, and it also leaves a door open that the whole internet can knock on. Here's what port forwarding does, where it causes trouble, and what to use instead when the device belongs to a business.
What Is Port Forwarding?
Port forwarding is a router rule that sends traffic arriving at your public internet address on one port to a specific device and port inside your network. Without the rule, the router drops that traffic, because it doesn't know which internal device it's meant for.
Think of the router as a building's front desk. The building has one street address, your public IP. Inside are dozens of offices, your laptops, printers and servers, each with a private address the street never sees. A port number is like an apartment number on the envelope. Port forwarding is the note at the front desk that says "anything for apartment 8443 goes straight up to the server in room 50."
How Port Forwarding Works
Take one worked example. The office has the public address 203.0.113.10, and a web app runs on a server at 192.168.1.50, port 443. The router gets a rule: traffic to 203.0.113.10 on port 8443 goes to 192.168.1.50 on port 443.
Someone outside types the public address and port. The router sees the request, checks its forwarding table, rewrites the destination to the internal server, and passes it through. Replies go back the same way. The person outside never learns the internal address.
The rule exists because of network address translation (NAT). NAT lets many private devices share one public address for outbound traffic, which is why your laptop can browse the web without its own public IP. Inbound traffic is the problem NAT can't solve on its own. When a connection starts from outside, the router needs a rule to know where to send it, and a port forward is that rule.
What People Use It For
At home, port forwarding lets people host game servers, reach a NAS or security camera from their phone, or run a small web app. In a business, the list looks similar with higher stakes: camera systems, file servers, a line-of-business app, and above all Remote Desktop on port 3389.
It often arrives as a request from a vendor. The camera installer, the phone system provider or the software company asks IT to "forward port X to this box" so their support team can connect. The request is reasonable. The way it gets done is where the risk lives.
Is Port Forwarding Safe?
A forwarded port is open to every address on the internet, not just the person you had in mind. Automated scanners sweep the whole internet around the clock, so an open port gets found whether or not anyone announces it. Whatever service sits behind it then has to survive every password guess and every exploit thrown at it.
The numbers show where that goes. In Sophos's 2025 Active Adversary Report, based on more than 400 incident cases from 2024, attackers got in by exploiting external remote services in 56% of cases, usually with valid credentials. Remote Desktop was involved in 84% of those cases.
There's good news in the 2026 edition, which covers 661 cases. External use of RDP showed up in 10% of cases, and Sophos saw exposed RDP systems roughly halve compared with the year before. Closing forwarded RDP ports is working where teams do it.
This r/msp story shows how fast it goes wrong. A client insisted on having 3389 forwarded to his PC instead of using a VPN, and the next morning the machine was encrypted.
So the short answer depends on what's behind the port. A game server at home is a small risk. A Windows server, a NAS or a camera system with a default password on a business network is an invitation, and our guide to ransomware attacks shows what usually follows.
UPnP: Port Forwarding Nobody Approved
Some ports get opened without anyone touching the router. Universal Plug and Play (UPnP) lets devices on the network ask the router to create forwarding rules for themselves. Game consoles use it, and so do some cameras, printers and smart TVs.
That's convenient at home and a blind spot at work. A device can open an inbound path, and nobody gets a ticket about it. On a business router, switch UPnP off and create any rule you need by hand, so every open port has a person who asked for it.
Safer Ways to Give Remote Access
The goal is the same in each case: get the right person to the right device without leaving it reachable by everyone else. Here are the common options, from most exposed to least.
A port forward with an IP allowlist narrows who can connect, but it only works when the remote person has a fixed address. A VPN with multi-factor authentication puts a login in front of the whole network, so nothing behind it is visible until someone proves who they are. Identity-aware access, often sold as zero trust network access (ZTNA), goes further and grants access to one app at a time instead of the whole network.
The strongest pattern has nothing listening at all. Outbound tunnel connectors and agent-based remote access tools make the connection from inside the network out to a broker, so there's no inbound port to find. Our guide to remote access software compares the agent-based tools.
Teams that want to self-host can look at MeshCentral, an open-source option that runs on your own server.
This r/ITManagers thread asks exactly this: staff need Remote Desktop to an office server from their own machines, with no ports opened. The replies cover RD Gateway, a VPN on managed devices, Microsoft's Global Secure Access, Tailscale and Apache Guacamole.
SpaceRex walks through what port forwarding exposes and what to check before you open anything, with examples from NAS setups.
How to Check What's Open Right Now
Start with the router or firewall. Export the port forwarding table and the UPnP mapping list, if the device keeps one. Every line is a door, so every line needs an owner.
Then look from the outside, the way an attacker would. Run a port scan against your public IP from a machine outside the network, or look the address up in a search engine for internet-exposed devices such as Shodan. Anything answering that you didn't expect goes to the top of the list.
Keep a short register for every rule that survives:
| Rule | Who asked for it | Why | Review date |
|---|---|---|---|
| 443 to the web app server | Operations lead | Customer portal | Every quarter |
| 3389 to the accounts PC | Nobody remembers | Unknown | Close it today |
The second row is the one to hunt for. A "temporary" rule with no owner has usually outlived the reason it was created. Our post on RMM security covers the same discipline for the tools techs use to reach machines every day.
Close the Doors You Don't Need
Port forwarding is a useful tool with a simple rule attached: every open port is reachable by everyone. Keep the ones with an owner and a reason, replace the rest with a VPN, identity-aware access or an outbound connector, and switch UPnP off on business routers.
If a port you find has already been used against you, our guide to incident management covers what to do in the first hours.
Content Marketing Lead
Ohayo! I run content, SEO, social, and community at Flamingo. Before IT, I worked as a correspondent for Ukraine's Public Broadcasting Company and have a Master's in journalism.
