πŸ”§ FreeFlow Relay β€” Router Port Forwarding Guide

Find your router below and follow the steps to open port 8443 (TCP + UDP).

Quick start: Your relay needs TCP & UDP port 8443 forwarded to your computer.
  1. Enable UPnP on your router β€” easiest, fully automatic.
  2. No UPnP? Manually forward port 8443 (TCP+UDP) to your local IP.
  3. On CGNAT? No forwarding works β€” ask ISP for public IP or use a VPS.
TP-Link
Archer series, Deco mesh Β· 192.168.0.1 or tplinkwifi.net
β–Ά

UPnP (automatic)

  1. Log in at 192.168.0.1 (admin / admin).
  2. Advanced β†’ NAT Forwarding β†’ UPnP.
  3. Toggle Enable UPnP ON β†’ Save.

Manual port forwarding

  1. Advanced β†’ NAT Forwarding β†’ Port Forwarding.
  2. Click Add.
  3. Name: freeflow-relay, External Port: 8443, Internal Port: 8443, Protocol: TCP/UDP.
  4. Internal IP: your computer's local IP β†’ Save.

Newer TP-Link models: you set your own password on first login. Deco mesh is managed via the Deco app β€” UPnP is on by default.

Asus
RT-AX, RT-AC, ROG Rapture Β· 192.168.1.1
β–Ά

UPnP

  1. Log in at 192.168.1.1 (admin / admin).
  2. WAN β†’ Internet Connection tab.
  3. Enable UPnP β†’ set to Yes β†’ Apply.

Manual port forwarding

  1. WAN β†’ Virtual Server / Port Forwarding.
  2. Enable Port Forwarding.
  3. Profile: freeflow-relay, Port range: 8443, Local IP: your computer, Protocol: Both.
  4. Add β†’ Apply.

Firmware: Asuswrt-Merlin has the same menu paths.

Netgear
Nighthawk (R-series), Orbi mesh Β· 192.168.1.1 or routerlogin.net
β–Ά

UPnP

  1. Log in (admin / password).
  2. ADVANCED β†’ Advanced Setup β†’ UPnP.
  3. Check Turn UPnP On β†’ Apply.

Manual port forwarding

  1. ADVANCED β†’ Advanced Setup β†’ Port Forwarding / Port Triggering.
  2. Add Custom Service.
  3. Service name: freeflow-relay, Service type: TCP/UDP, External/Local port: 8443, Local IP: your computer.
  4. Add β†’ Apply.
Linksys
Velop mesh, WRT, EA series Β· 192.168.1.1
β–Ά

UPnP

  1. Log in (admin / admin).
  2. Connectivity β†’ Port Forwarding (or Smart Wi-Fi Tools β†’ UPnP on older models).
  3. Check UPnP Enabled β†’ OK / Apply.

Manual port forwarding

  1. Connectivity β†’ Port Forwarding (or Security β†’ Applications and Gaming).
  2. Add.
  3. Application: freeflow-relay, External/Local port: 8443, Protocol: Both, Device: your computer.
  4. OK.
D-Link
DIR, EXO, Covr mesh Β· 192.168.0.1
β–Ά

UPnP

  1. Log in (admin, blank password or admin).
  2. Advanced β†’ Advanced Network β†’ UPnP.
  3. Check Enable UPnP β†’ Save Settings.

Manual port forwarding

  1. Advanced β†’ Port Forwarding (or Firewall β†’ Port Forwarding).
  2. Add.
  3. Name: freeflow-relay, External/Internal port: 8443, Protocol: Both, Local IP: your computer.
  4. Save.
Fritz!Box (AVM)
All models Β· fritz.box or 192.168.178.1
β–Ά

UPnP (Portfreigabe)

  1. Open fritz.box. Enter your PIN/password.
  2. Internet β†’ Permit Access β†’ Port Sharing tab.
  3. Check Allow device to share ports automatically β†’ Apply.

Manual port forwarding

  1. Internet β†’ Permit Access β†’ Port Sharing tab.
  2. Add Port Sharing.
  3. Select "Other application", name: freeflow-relay, Protocol: TCP, External/Internal port: 8443, select your computer.
  4. OK. Repeat for UDP (second rule). Apply.

German firmware: "Portfreigabe" = Port Sharing.

Huawei
B-series (4G/5G), AX-series WiFi 6 Β· 192.168.3.1
β–Ά

UPnP

  1. Log in (admin / admin, or check sticker).
  2. More Functions β†’ Network Settings β†’ UPnP.
  3. Toggle UPnP ON β†’ Save.

Manual port forwarding

  1. More Functions β†’ Network Settings β†’ Port Mapping.
  2. Add.
  3. Name: freeflow-relay, Protocol: TCP+UDP, External/Internal port: 8443, Local IP: your computer.
  4. Save.
ZTE
ZXHN series, MC-series 4G/5G Β· 192.168.1.1
β–Ά

UPnP

  1. Log in (admin / admin, or check sticker).
  2. Application β†’ UPnP.
  3. Enable UPnP β†’ Save.

Manual port forwarding

  1. Application β†’ NAT β†’ Port Forwarding (or Virtual Server).
  2. Add New.
  3. Name: freeflow-relay, External/Internal port: 8443, Protocol: ALL, Local IP: your computer.
  4. Save.
Tenda
AC, AX, Nova mesh Β· 192.168.0.1 or tendawifi.com
β–Ά

UPnP

  1. Log in (admin, blank or user-set).
  2. Advanced β†’ UPnP Settings.
  3. Toggle UPnP ON β†’ OK.

Manual port forwarding

  1. Advanced β†’ Virtual Server (or Port Forwarding).
  2. Add.
  3. Name: freeflow-relay, Port: 8443, Protocol: ALL, Local IP: your computer.
  4. OK.
Xiaomi
Mi Router series Β· 192.168.31.1 or miwifi.com
β–Ά

UPnP

  1. Log in (admin / admin).
  2. Advanced β†’ UPnP Settings.
  3. Toggle UPnP ON β†’ Save.

Manual port forwarding

  1. Advanced β†’ Port Forwarding.
  2. Add.
  3. Name: freeflow-relay, Protocol: TCP+UDP, Port: 8443, Local IP: your computer.
  4. Save.

Also manageable via the Mi Home app on Android/iOS.

Google Nest WiFi / Google WiFi
Managed via Google Home app Β· 192.168.86.1
β–Ά

No web admin interface. Use the Google Home app on your phone.

  1. Open the Google Home app.
  2. Tap Wi-Fi β†’ Settings β†’ Advanced networking.
  3. Tap Port management β†’ Add port management.
  4. Name: freeflow-relay, Protocol: TCP and UDP, Port: 8443, Device: your relay computer.
  5. Tap Save.

No UPnP toggle β€” port forwarding is manual-only via the app.

Amazon eero
Managed via eero app Β· 192.168.4.1
β–Ά

No web admin interface. Use the eero app.

  1. Open the eero app.
  2. Settings (gear icon) β†’ Network Settings β†’ Port Forwarding.
  3. Add Port Forwarding.
  4. Name: freeflow-relay, Protocol: TCP + UDP, Port: 8443, Device: your relay computer.
  5. Tap Add.
Apple AirPort / Time Capsule
NAT-PMP by default Β· 10.0.1.1
β–Ά

Apple AirPort uses NAT-PMP by default β€” the FreeFlow relay auto-detects it, no config needed.

Manual port mapping (if needed)

  1. Open AirPort Utility on macOS (or iOS).
  2. Select your AirPort β†’ Edit β†’ Port Settings tab.
  3. Click +.
  4. Description: freeflow-relay, Public/Private port: 8443, Protocol: TCP/UDP (two entries), Private IP: your computer.
  5. Done β†’ Update.

NAT-PMP is enabled by default on all AirPort models.

Ubiquiti UniFi
UniFi Network Controller Β· 192.168.1.1:8443
β–Ά

UniFi does not have UPnP on most firmware β€” use manual port forwarding.

  1. Log in to the UniFi Network Controller or app.
  2. Settings β†’ Routing & Firewall β†’ Port Forwarding.
  3. Add Rule.
  4. Name: freeflow-relay, Protocol: TCP + UDP, WAN port: 8443, LAN port: 8443, LAN IP: your computer.
  5. Save.
OpenWrt
LuCI web UI Β· 192.168.1.1
β–Ά

UPnP / NAT-PMP / PCP

  1. Log in to LuCI (root, your password).
  2. Services β†’ UPnP & NAT-PMP.
  3. Check Enable UPnP and Enable NAT-PMP.
  4. Save & Apply.

Manual port forwarding

  1. Network β†’ Firewall β†’ Port Forwards.
  2. Add.
  3. Name: freeflow-relay, Protocol: TCP+UDP, External port: 8443, Internal IP: your computer, Internal port: 8443.
  4. Save & Apply.

Via SSH (no LuCI): opkg install luci-app-upnp miniupnpd && /etc/init.d/miniupnpd enable && /etc/init.d/miniupnpd start

pfSense
HTTPS web UI Β· 192.168.1.1
β–Ά

UPnP / NAT-PMP / PCP

  1. Log in (admin / pfsense).
  2. Services β†’ UPnP & NAT-PMP.
  3. Check Enable UPnP. Set Network(s) to your LAN subnet (e.g. 192.168.1.0/24).
  4. Save β†’ restart the service.

Manual port forwarding

  1. Firewall β†’ NAT β†’ Port Forward tab.
  2. Add.
  3. Interface: WAN, Protocol: TCP/UDP, Destination port: 8443, Redirect target IP: your computer, Redirect target port: 8443.
  4. Description: freeflow-relay. Save β†’ Apply Changes.
OPNsense
HTTPS web UI Β· 192.168.1.1
β–Ά

UPnP / NAT-PMP

  1. Log in (root / opnsense).
  2. Services β†’ Os-UPnP.
  3. Check Enable UPnP/NAT-PMP. Set Allowed networks to your LAN.
  4. Save β†’ Apply.

Manual port forwarding

  1. Firewall β†’ NAT β†’ Port Forward.
  2. Click +.
  3. Interface: WAN, Protocol: TCP/UDP, Destination port: 8443, Redirect IP: your computer, Redirect port: 8443.
  4. Save β†’ Apply.
MikroTik
WinBox app Β· 192.168.88.1
β–Ά

UPnP

  1. Log in (admin, blank password) or via WinBox.
  2. IP β†’ UPnP.
  3. In Interfaces tab, click +. Add your WAN as "external" and LAN as "internal".
  4. Enable: check Show Dummy Rule and Allow Disable/Enable. Apply β†’ OK.

Manual port forwarding (dst-nat)

  1. IP β†’ Firewall β†’ NAT tab. Click +.
  2. Chain: dstnat, Protocol: tcp, Dst. Port: 8443, Action: dst-nat, To Addresses: your computer's IP, To Ports: 8443. Apply.
  3. Add a second rule for UDP (change Protocol to udp).
Belkin
All models Β· 192.168.2.1
β–Ά

UPnP

  1. Log in (no password by default).
  2. Firewall β†’ UPnP Settings.
  3. Check Allow UPnP Port Mapping β†’ Apply Settings.

Manual port forwarding

  1. Firewall β†’ Virtual Servers (or Port Forwarding).
  2. Add.
  3. Name: freeflow-relay, Protocol: TCP+UDP, Inbound/Outbound port: 8443, IP: your computer.
  4. Apply Settings.
ISP Gateways (Arris, Technicolor, Sagemcom)
ISP-supplied Β· various IPs
β–Ά

Arris/SBG: 192.168.0.1 (admin/password) β†’ Gateway β†’ Port Forwarding β†’ Add rule for port 8443, protocol Both.

Technicolor: 192.168.1.254 (admin/admin) β†’ Advanced β†’ NAT/Gaming β†’ Add Port Mapping for 8443.

Sagemcom: 192.168.1.1 (admin/admin) β†’ Advanced Settings β†’ Port Forwarding β†’ Add rule for 8443.

Locked by ISP? Contact your ISP to enable port forwarding, or put the gateway in bridge mode and use your own router behind it.

βœ… Verify Your Port Is Open

Method 1: Visit canyouseeme.org and check port 8443.

Method 2: Use your phone on mobile data (not WiFi) and try to connect. Or ask someone outside your network.

Method 3: Check the relay log for:

Relay is LIVE β€” accepting connections
  Public:    203.0.113.7:8443  [UPnP mapped β†’ 203.0.113.7:8443]

UPnP mapped NAT-PMP/PCP mapped Direct (public IP / VPS) = good βœ“
Warning about forwarding = not reachable βœ—

Important: Testing from inside your own WiFi/LAN usually fails even when forwarding is correct. Most routers don't support NAT hairpinning. Always test from outside your network.

πŸ”§ Troubleshooting

SymptomCauseFix
Can't access router adminWrong IPCheck default gateway with ipconfig
Default password failsChangedFactory reset (hold reset 10s)
UPnP on but unreachableCGNATCompare router WAN IP vs public IP
Port checker says closedNot forwarded / firewallAdd both TCP and UDP rules for 8443
Only TCP works, QUIC failsMissing UDP ruleAdd a UDP rule for port 8443
Relay works then stopsDHCP changed your IPSet a static IP or DHCP reservation

⚠️ CGNAT β€” When Nothing Works

If your ISP uses Carrier-Grade NAT, no port forwarding will work. Your router's WAN IP is a private address shared with many customers.

Signs of CGNAT:
  • Router WAN IP starts with 100.64.–100.127. (RFC 6598).
  • Router WAN IP β‰  your public IP from whatismyip.com.
  • UPnP "succeeds" but port checkers say closed.
Solutions:
  1. Ask your ISP for a public/static IP (sometimes free).
  2. Run on a VPS β€” any server with a public IP ($3–5/month).
  3. Bridge mode β€” put ISP gateway in bridge mode, use your own router. Only works if ISP assigns a public IP.
Deprecation: Reverse tunnel for CGNAT relays was deprecated 2026-06-23. The [nat] tunnel_fallback and tunnel_relay settings are no longer functional.

πŸ“Œ Set a Static IP

Port forwarding requires your computer's local IP to stay the same.