Flamingo Raises $4.5M Seed Round

Skip to content

Updated: October 2026

Someone needs to reach a device on the office network from outside, and the fastest answer on every forum is "just forward the port." It works, and it also leaves a door open that the whole internet can knock on. Here's what port forwarding does, where it causes trouble, and what to use instead when the device belongs to a business.

What Is Port Forwarding?

Port forwarding is a router rule that sends traffic arriving at your public internet address on one port to a specific device and port inside your network. Without the rule, the router drops that traffic, because it doesn't know which internal device it's meant for.

Think of the router as a building's front desk. The building has one street address, your public IP. Inside are dozens of offices, your laptops, printers and servers, each with a private address the street never sees. A port number is like an apartment number on the envelope. Port forwarding is the note at the front desk that says "anything for apartment 8443 goes straight up to the server in room 50."

How Port Forwarding Works

Take one worked example. The office has the public address 203.0.113.10, and a web app runs on a server at 192.168.1.50, port 443. The router gets a rule: traffic to 203.0.113.10 on port 8443 goes to 192.168.1.50 on port 443.

Someone outside types the public address and port. The router sees the request, checks its forwarding table, rewrites the destination to the internal server, and passes it through. Replies go back the same way. The person outside never learns the internal address.

The rule exists because of network address translation (NAT). NAT lets many private devices share one public address for outbound traffic, which is why your laptop can browse the web without its own public IP. Inbound traffic is the problem NAT can't solve on its own. When a connection starts from outside, the router needs a rule to know where to send it, and a port forward is that rule.

What People Use It For

At home, port forwarding lets people host game servers, reach a NAS or security camera from their phone, or run a small web app. In a business, the list looks similar with higher stakes: camera systems, file servers, a line-of-business app, and above all Remote Desktop on port 3389.

It often arrives as a request from a vendor. The camera installer, the phone system provider or the software company asks IT to "forward port X to this box" so their support team can connect. The request is reasonable. The way it gets done is where the risk lives.

Is Port Forwarding Safe?

A forwarded port is open to every address on the internet, not just the person you had in mind. Automated scanners sweep the whole internet around the clock, so an open port gets found whether or not anyone announces it. Whatever service sits behind it then has to survive every password guess and every exploit thrown at it.

The numbers show where that goes. In Sophos's 2025 Active Adversary Report, based on more than 400 incident cases from 2024, attackers got in by exploiting external remote services in 56% of cases, usually with valid credentials. Remote Desktop was involved in 84% of those cases.

There's good news in the 2026 edition, which covers 661 cases. External use of RDP showed up in 10% of cases, and Sophos saw exposed RDP systems roughly halve compared with the year before. Closing forwarded RDP ports is working where teams do it.

This r/msp story shows how fast it goes wrong. A client insisted on having 3389 forwarded to his PC instead of using a VPN, and the next morning the machine was encrypted.

So the short answer depends on what's behind the port. A game server at home is a small risk. A Windows server, a NAS or a camera system with a default password on a business network is an invitation, and our guide to ransomware attacks shows what usually follows.

UPnP: Port Forwarding Nobody Approved

Some ports get opened without anyone touching the router. Universal Plug and Play (UPnP) lets devices on the network ask the router to create forwarding rules for themselves. Game consoles use it, and so do some cameras, printers and smart TVs.

That's convenient at home and a blind spot at work. A device can open an inbound path, and nobody gets a ticket about it. On a business router, switch UPnP off and create any rule you need by hand, so every open port has a person who asked for it.

Safer Ways to Give Remote Access

The goal is the same in each case: get the right person to the right device without leaving it reachable by everyone else. Here are the common options, from most exposed to least.

A port forward with an IP allowlist narrows who can connect, but it only works when the remote person has a fixed address. A VPN with multi-factor authentication puts a login in front of the whole network, so nothing behind it is visible until someone proves who they are. Identity-aware access, often sold as zero trust network access (ZTNA), goes further and grants access to one app at a time instead of the whole network.

The strongest pattern has nothing listening at all. Outbound tunnel connectors and agent-based remote access tools make the connection from inside the network out to a broker, so there's no inbound port to find. Our guide to remote access software compares the agent-based tools.

Teams that want to self-host can look at MeshCentral, an open-source option that runs on your own server.

This r/ITManagers thread asks exactly this: staff need Remote Desktop to an office server from their own machines, with no ports opened. The replies cover RD Gateway, a VPN on managed devices, Microsoft's Global Secure Access, Tailscale and Apache Guacamole.

SpaceRex walks through what port forwarding exposes and what to check before you open anything, with examples from NAS setups.

How to Check What's Open Right Now

Start with the router or firewall. Export the port forwarding table and the UPnP mapping list, if the device keeps one. Every line is a door, so every line needs an owner.

Then look from the outside, the way an attacker would. Run a port scan against your public IP from a machine outside the network, or look the address up in a search engine for internet-exposed devices such as Shodan. Anything answering that you didn't expect goes to the top of the list.

Keep a short register for every rule that survives:

RuleWho asked for itWhyReview date
443 to the web app serverOperations leadCustomer portalEvery quarter
3389 to the accounts PCNobody remembersUnknownClose it today

The second row is the one to hunt for. A "temporary" rule with no owner has usually outlived the reason it was created. Our post on RMM security covers the same discipline for the tools techs use to reach machines every day.

Close the Doors You Don't Need

Port forwarding is a useful tool with a simple rule attached: every open port is reachable by everyone. Keep the ones with an owner and a reason, replace the rest with a VPN, identity-aware access or an outbound connector, and switch UPnP off on business routers.

If a port you find has already been used against you, our guide to incident management covers what to do in the first hours.

Kristina Shkriabina

Content Marketing Lead

Ohayo! I run content, SEO, social, and community at Flamingo. Before IT, I worked as a correspondent for Ukraine's Public Broadcasting Company and have a Master's in journalism.

Related Content

Blog Posts

Product Releases

Podcasts

Webinars

Case Studies

Events

Onboarding Guides

Frequently Asked Questions

Port Forwarding

No. Port forwarding opens one port on the router to everyone on the internet and sends that traffic to one device. A VPN puts a login in front of the whole network, so nothing inside is reachable until the user authenticates, ideally with multi-factor authentication.
Only keep port forwarding rules you can name an owner and a reason for. On a business network, remove unexplained rules, replace remote access forwards such as RDP with a VPN or an outbound connector, and turn UPnP off so devices can't add rules on their own.
It can help at home: forwarding the ports a game or console needs can fix strict NAT types and hosting problems. The risk is lower on a home gaming setup than on a business network, but it still exposes that device, so keep it updated and forward only the ports the game documents.
UPnP (Universal Plug and Play) lets devices ask the router to open ports for themselves without anyone approving it. On business routers it's safer to turn UPnP off and create any forwarding rule by hand, so every open port has an owner.

MSP AI Agents

On a five-person desk, reported deployments show $78,000 to $130,000 in annual direct labor savings, roughly 30% fewer escalations, and 15% to 20% better SLA compliance. Broader MSP adoption data adds ticket handling time cut by 45% and five to 12 points of margin, all from reclaimed capacity rather than headcount cuts.
Yes. In production MSP shops today, 10% to 25% of tickets close before a human opens them. Thread alone has processed 173 million tickets across 750-plus MSP partners at 96% triage accuracy, handing back 490,000-plus technician hours. Agents own the low-risk, high-volume work (password resets, MFA enrollment, known installs, onboarding and offboarding) and flag anything that touches production data or needs judgment for a human to take.

About OpenFrame

OpenFrame isn't built to plug into your stack. It replaces it. Instead of duct-taping a dozen tools together (RMM, MDM, SIEM, patching, remote access, each its own login and bill), we bundle it into one unified platform: RMM, MDM, monitoring, automation, remote access, patch management, security monitoring, and ticketing, plus built-in AI copilots. So "does it integrate with X?" usually means: you won't need X anymore.
Most platforms give you one piece and expect you to bolt the rest on. OpenFrame unifies the whole stack in one place, with AI copilots built in. Fewer logins, fewer bills, less duct tape.
In the cloud, on US soil. Your data stays stateside.
Both. It's built for MSPs and MSSPs alike.