Port forwarding is a useful feature for businesses and IT professionals needing external access to specific devices or applications within their private network. As your ISP, we can configure port forwarding on your managed router upon request. However, it's important to understand the risks, follow best practices, and explore alternative solutions before proceeding.

While we ensure secure configurations on the router, it is your responsibility to monitor and maintain the security of the devices behind it.

What Is Port Forwarding?

Port forwarding allows external devices to connect to specific internal devices or services within your network. For example, port forwarding is often used to access:

  • Web servers
  • CCTV systems
  • Remote desktops
  • IoT devices

When we configure port forwarding, specific traffic is redirected from the router’s public IP address and port to an internal device on your private network. While effective, this process can expose your network to risks if not carefully managed.

Risks of Port Forwarding

  1. Increased Exposure to Cyber Threats:
    • Open ports can become targets for hackers, who often scan networks to find vulnerabilities.
    • Misconfigured or outdated devices behind forwarded ports are particularly susceptible to exploitation.
  2. Unauthorised Access:
    • Forwarded ports may allow unauthorised users to access sensitive systems if access controls aren’t strictly enforced.
  3. Data Breaches:
    • Attackers can use open ports to infiltrate your network and access confidential data.
    • Unencrypted traffic passing through forwarded ports is vulnerable to interception.
  4. Denial-of-Service (DoS) Attacks:
    • Open ports can be overwhelmed with malicious traffic, causing service interruptions.
  5. Internal Network Compromise:
    • Once a port is breached, attackers can use the compromised device as a gateway to access other systems on your network.

Best Practices for Secure Port Forwarding

To minimise risks, we recommend the following best practices:

  1. Only Open Necessary Ports:
    • Request port forwarding only for essential services or applications.
    • Inform us immediately if a forwarded port is no longer needed so it can be closed.
  2. Restrict Access with ACLs (Access Control Lists):
    • Provide a list of trusted source IPs to limit who can access the forwarded port.
    • Avoid allowing unrestricted access from "any" IP address.
  3. Secure Internal Devices:
    • Use strong, unique passwords and enable two-factor authentication for devices behind forwarded ports.
    • Ensure devices and applications are regularly updated with the latest security patches.
  4. Monitor Device Activity:
    • Regularly check logs and activity on the devices receiving traffic through forwarded ports.
    • Use endpoint security tools to detect unauthorised access or suspicious behaviour.
  5. Use Encrypted Protocols:
    • Always use secure protocols like HTTPS or SSH for services behind forwarded ports to protect data in transit.

Alternatives to Port Forwarding

In many cases, alternative solutions can provide a more secure way to access internal resources without the risks associated with port forwarding:

  1. Virtual Private Network (VPN):
    • VPNs create a secure, encrypted tunnel to your private network, eliminating the need for open ports.
    • Only authorised users with VPN credentials can access internal devices.
  2. Reverse Proxy:
    • A reverse proxy (e.g., Nginx, HAProxy) manages incoming traffic securely and routes it to the appropriate internal resource.
    • This method adds layers of security, including authentication and traffic filtering.
  3. Cloud-Based Remote Access Solutions:
    • Platforms like ZeroTier or JumpCloud provide secure access to internal systems without opening ports.
    • These solutions often include built-in monitoring and access controls.
  4. Zero Trust Network Access (ZTNA):
    • ZTNA enforces access policies, allowing users and devices to connect only to authorised applications or systems.
    • This approach reduces the attack surface by limiting what external users can see and access.
  5. Dynamic DNS with Remote Tools:
    • Combine Dynamic DNS services with secure tools like SSH (used via VPN) to access resources without permanent open ports.

Our Role vs. Your Responsibility

  • Our Role as Your ISP:
    • We configure port forwarding securely on your managed router based on your request.
    • We apply access control and test the setup to minimise risks.
  • Your Responsibility as the Device Owner:
    • Monitor and maintain the security of devices and applications behind forwarded ports.
    • Regularly audit and update these systems to reduce vulnerabilities.
    • Respond to unauthorised access attempts promptly to protect your network.

Requesting Port Forwarding

To request port forwarding, please provide the following details:

Date (dd/mm/yyyy) 

Technical Contact Person

Contact Email

Contact Phone

Service ID

Service Address 

Reason for Request   (Brief explanation of why port forwarding is required)                 

PORT FORWARD REQUEST(S)

Rule NamePublic IP / Device IdentifierAllowed Source IP (ACL)Destination IP (Internal Host)Protocol (TCP/UDP)

Port(s)

(Forwarded)

      
      
      
      
      
      
      

TERMS & CONDITIONS

  1. You acknowledge that opening ports may increase your exposure to potential security threats. It is your responsibility to ensure all internal systems are suitably protected with up-to-date security measures.
  2. By requesting port forwarding, you confirm that you are authorised to request and approve changes to the network infrastructure on behalf of your or the organisation.
  3. The service provider shall not be liable for any loss, damage, or expense caused by unauthorised access or misuse of forwarded ports. You agree to indemnify and hold the service provider harmless from any claims arising out of or related to the use of these forwarded ports.
  4. While every effort is made to avoid disruption, maintenance or unforeseen events may require temporary downtime.
  5. The service provider reserves the right to disable port forwarding if these terms and conditions are breached, or if it is necessary to protect network security.
  6. The service provider may update these terms at any time. Continued use of port forwarding after any updates constitutes acceptance of the revised terms.