Setting Up Port Forwarding

Updated 4 Oct 2026 4 min read

Port forwarding lets people on the internet reach a device connected to your dedicated WireGuard® server. Use it to host a game server, a website or remote desktop access, even if your home connection can't accept incoming connections.

How port forwarding works

When someone connects to your server's public IP on the external port you choose, the server sends that traffic down the tunnel to your device's internal IP on the internal port you choose.

For example, if your server's IP is 203.0.113.10 and your device's internal IP is 10.66.66.2, a forward from external port 25565 to internal port 25565 means anyone connecting to 203.0.113.10:25565 reaches port 25565 on your device.

  • Your home IP stays private. People connect to your server, not your router.
  • It works behind CGNAT and on mobile networks, because your device connects out to the server.
  • Your service sees incoming connections as coming from the server's own internal address (the .1 address in your subnet), not the visitor's real IP.

Before you start

  • Create a WireGuard user for the device first. Port forwards always belong to a user. See Creating and Managing WireGuard Users.
  • The device must be connected to the server for the forward to work.
  • The service on the device must be running and listening on the internal port.

Add a port forward

  1. In the portal sidebar, click WireGuard, then Manage Server.
  2. Find the user for the device and click Ports.
  3. Fill in the form:
    • Ext. port: the port people connect to on your server's IP.
    • Int. port: the port your service listens on. It's often the same as the external port, but doesn't have to be.
    • Protocol: TCP, UDP or Both.
  4. Click Add Forward.

The forward works straight away and stays in place when the server restarts. Each forward appears under the user as server-ip:external to device-ip:internal with its protocol.

Each forward covers one port. If your service needs several ports, add a forward for each one.

Choosing the protocol

ServiceProtocol
Minecraft (Java Edition)TCP
Minecraft (Bedrock Edition)UDP
Valheim, ARK and most Steam game serversUDP
Websites (HTTP and HTTPS)TCP
SSH and Remote DesktopTCP
MumbleBoth

If you're not sure, choose Both, or check your software's documentation for the ports and protocols it uses.

Ports you can't forward

  • 22: used to manage the server
  • 51820, and your server's WireGuard port if it's different (shown under Server Info › WireGuard Port)
  • 56561: reserved for internal management

The form reminds you which ports are blocked. If you try one, you'll see a message saying the port is reserved.

Port 25 (email) is also blocked on our servers to prevent spam, so you can't run a public mail server on it.

Port conflicts

Each external port and protocol can only be forwarded once per server. If it's already in use, you'll see a message such as "Port 8080/tcp is not available. Please choose another." A port forwarded as Both can't also be forwarded as TCP or UDP on its own.

Internal ports can repeat across devices, because each device has its own internal IP. For example, two devices can both run a web server on port 80 if you forward different external ports to them.

Remove a port forward

Click Ports on the user, then Remove next to the forward and confirm. It stops working straight away. Removing a user also removes all of its port forwards.

Common examples

Minecraft server (Java Edition)

  • Ext. port 25565, Int. port 25565, TCP
  • Players connect to your-server-ip:25565

Web server

  • Two forwards: 80 to 80 and 443 to 443, TCP
  • Point your domain's A record at your server's IP

Remote Desktop (RDP)

  • Ext. port: a less obvious port such as 53389, Int. port 3389, TCP
  • Connect to your-server-ip:53389, and use a strong password

Plex media server

  • Ext. port 32400, Int. port 32400, TCP

Testing your forward

Test from a device that isn't connected to your WireGuard server, such as a phone on mobile data. Testing from the same device, or another device on the same server, may not work even when the forward is set up correctly.

FAQs

Do port forwards survive a server restart?

Yes. Forwards are saved on the server and restored when it starts.

Is there a limit on how many forwards I can have?

No. Add as many as you need. If you add a lot quickly, the portal may ask you to wait a minute.

Can I forward one external port to two devices?

No. Each external port points to one device. Use a different external port for each device.

Does the device need to send all its traffic through the VPN?

No. Replies to forwarded connections go back through the tunnel automatically. You can set AllowedIPs to your server's subnet only and port forwards still work. See Understanding Your WireGuard Configuration File.

Can I manage forwards with the API?

Yes. See API: Port Forwarding.

Still stuck? Open a support ticket and tell us your device, app version and what you've tried.

Something out of date or unclear? Let us know.

Stay Ahead of Online Threats

Get VPN tips, security insights, and exclusive offers delivered straight to your inbox. No spam — just the essentials.

Unsubscribe at any time. We respect your privacy.

PremierVPN Support