Port forwarding lets people on the internet reach a device connected to your dedicated WireGuard® server. Use it to host a game server, a website or remote desktop access, even if your home connection can't accept incoming connections.
How port forwarding works
When someone connects to your server's public IP on the external port you choose, the server sends that traffic down the tunnel to your device's internal IP on the internal port you choose.
For example, if your server's IP is 203.0.113.10 and your device's internal IP is 10.66.66.2, a forward from external port 25565 to internal port 25565 means anyone connecting to 203.0.113.10:25565 reaches port 25565 on your device.
- Your home IP stays private. People connect to your server, not your router.
- It works behind CGNAT and on mobile networks, because your device connects out to the server.
- Your service sees incoming connections as coming from the server's own internal address (the
.1address in your subnet), not the visitor's real IP.
Before you start
- Create a WireGuard user for the device first. Port forwards always belong to a user. See Creating and Managing WireGuard Users.
- The device must be connected to the server for the forward to work.
- The service on the device must be running and listening on the internal port.
Add a port forward
- In the portal sidebar, click WireGuard, then Manage Server.
- Find the user for the device and click Ports.
- Fill in the form:
- Ext. port: the port people connect to on your server's IP.
- Int. port: the port your service listens on. It's often the same as the external port, but doesn't have to be.
- Protocol: TCP, UDP or Both.
- Click Add Forward.
The forward works straight away and stays in place when the server restarts. Each forward appears under the user as server-ip:external to device-ip:internal with its protocol.
Each forward covers one port. If your service needs several ports, add a forward for each one.
Choosing the protocol
| Service | Protocol |
|---|---|
| Minecraft (Java Edition) | TCP |
| Minecraft (Bedrock Edition) | UDP |
| Valheim, ARK and most Steam game servers | UDP |
| Websites (HTTP and HTTPS) | TCP |
| SSH and Remote Desktop | TCP |
| Mumble | Both |
If you're not sure, choose Both, or check your software's documentation for the ports and protocols it uses.
Ports you can't forward
- 22: used to manage the server
- 51820, and your server's WireGuard port if it's different (shown under Server Info › WireGuard Port)
- 56561: reserved for internal management
The form reminds you which ports are blocked. If you try one, you'll see a message saying the port is reserved.
Port 25 (email) is also blocked on our servers to prevent spam, so you can't run a public mail server on it.
Port conflicts
Each external port and protocol can only be forwarded once per server. If it's already in use, you'll see a message such as "Port 8080/tcp is not available. Please choose another." A port forwarded as Both can't also be forwarded as TCP or UDP on its own.
Internal ports can repeat across devices, because each device has its own internal IP. For example, two devices can both run a web server on port 80 if you forward different external ports to them.
Remove a port forward
Click Ports on the user, then Remove next to the forward and confirm. It stops working straight away. Removing a user also removes all of its port forwards.
Common examples
Minecraft server (Java Edition)
- Ext. port
25565, Int. port25565, TCP - Players connect to
your-server-ip:25565
Web server
- Two forwards:
80to80and443to443, TCP - Point your domain's A record at your server's IP
Remote Desktop (RDP)
- Ext. port: a less obvious port such as
53389, Int. port3389, TCP - Connect to
your-server-ip:53389, and use a strong password
Plex media server
- Ext. port
32400, Int. port32400, TCP
Testing your forward
Test from a device that isn't connected to your WireGuard server, such as a phone on mobile data. Testing from the same device, or another device on the same server, may not work even when the forward is set up correctly.
FAQs
Do port forwards survive a server restart?
Yes. Forwards are saved on the server and restored when it starts.
Is there a limit on how many forwards I can have?
No. Add as many as you need. If you add a lot quickly, the portal may ask you to wait a minute.
Can I forward one external port to two devices?
No. Each external port points to one device. Use a different external port for each device.
Does the device need to send all its traffic through the VPN?
No. Replies to forwarded connections go back through the tunnel automatically. You can set AllowedIPs to your server's subnet only and port forwards still work. See Understanding Your WireGuard Configuration File.
Can I manage forwards with the API?
Yes. See API: Port Forwarding.
Still stuck? Open a support ticket and tell us your device, app version and what you've tried.