Guide

BT Smart Hub port forwarding and dynamic DNS

BT home broadband normally gives you a public IPv4 address, so port forwarding works – once you find the right page in Hub Manager and give your server a fixed address. Here is the whole process, plus what to do about dynamic DNS, which the hub only supports for a short list of providers.

Updated · Checked against BT Smart Hub 2 and Smart Hub 3 help guides and BT Community threads, September 2026 · 6 min read

Hub Manager
192.168.1.254
Password
Admin password on the back of the hub
Menu
Advanced settings → Firewall
Built‑in DDNS
Fixed provider list only

Before you start

  • Check your connection type. BT home broadband traditionally uses public, dynamic IPv4 addresses. Confirm it for your line with the CGNAT check: the hub’s broadband IPv4 address (Hub Manager’s status pages) should match what ip.uk.app shows.
  • Is the BT hub your only router? If you have a mesh system or your own router behind it, read double NAT first, or your forward will stop at the second router.
  • Know the port. For a web app behind a reverse proxy that is TCP 443 (and 80 for some certificate methods). For WireGuard it is UDP 51820; for Plex TCP 32400.

1. Open Hub Manager

  1. On a device connected to the hub, go to http://192.168.1.254.
  2. Click Advanced settings. You will be asked for the hub’s admin password: it is printed on the back of the hub (or on the pull‑out card), unless you changed it.

2. Give your server a fixed address

A port forward points at one LAN address. If your server gets a different address after a restart, the forward silently stops working. Before creating the rule, make the hub always give the server the same address: find the server in Hub Manager’s list of connected devices, open it, and choose the option to always use this IP address. (Alternatively, set a static address on the server itself, outside the hub’s DHCP range.)

3. Create the port forwarding rule

In Advanced settings → Firewall, open the port forwarding section. On the Smart Hub 2 and Smart Hub 3 the steps are:

  1. Choose Create a new port forwarding rule.
  2. Rule name: something recognisable, such as HTTPS proxy.
  3. Select device: pick your server from the list.
  4. External and internal ports: for a single port, enter the same number (for example 443) in both the start and end boxes.
  5. Protocol: TCP for web apps, UDP for WireGuard, TCP/UDP only if the app needs both.
  6. Press the + (add) button, add any further ports, then Save.

Menus look different?

BT has shipped several Hub Manager designs. On some firmware you first add a “game or application” with its ports and protocol, then assign it to a device. The information you enter is the same: a name, the port or range, the protocol and the target device.

Watch out

An external port can only go to one device – that is true of every router. If you need two servers on the same service, give the second a different external port (for example 8443 → 443) and use that port from outside. On the BT Business Smart Hub 3, early firmware also refused two rules with the same internal port; BT fixed that in v1.14, so let the hub update if you hit it.

4. Dynamic DNS: use another device

BT hubs have a dynamic DNS page (Advanced settings → Broadband → Dynamic DNS on the Smart Hub 2), but it only offers a fixed list of providers such as DynDNS, No‑IP and ChangeIP. There is no field for a custom update address, so it can’t update a uk.app name – or most others.

Run the updater on something that is always on instead:

  • a Linux box, Raspberry Pi or container – the five‑line cron job in the start guide;
  • Home Assistant, with a RESTful command and an automation;
  • a Synology NAS, using its custom DDNS provider option.

All of them need a DDNS token from the uk.app dashboard and update a name such as home.yourname.uk.app. Because BT addresses tend to stay the same for long periods, many people forget the updater exists – until a line fault or hub replacement changes the address. Set it up anyway.

5. Using your own router instead

The home Smart Hubs don’t have a simple modem or bridge mode. If you want your own router or mesh system as the only router:

  • Full fibre (FTTP): your line ends in an Openreach fibre box (the ONT) with its own network socket. Connect your router’s WAN port to it and set the WAN to PPPoE. BT’s commonly used login is username bthomehub@btbroadband.com with any password; check BT’s current guidance if it doesn’t connect.
  • Part fibre (FTTC): the line comes in on the phone socket, so your router needs a built‑in VDSL modem, or you need a separate VDSL modem in front of it.
  • Check your phone service first: BT Digital Voice handsets plug into the Smart Hub, so replacing it can affect calls.

If you keep the Smart Hub in front of your own router, forward the port on the hub to your router, and again on your router to the server – see double NAT.

IPv6

BT supplies IPv6 on most home lines. IPv6 connections don’t use port forwarding; instead the hub’s firewall has to allow them to reach the device, and the hub handles IPv4 and IPv6 rules separately. Unless you specifically want IPv6 visitors, you can ignore it – but don’t publish an AAAA record for a service that the IPv6 firewall blocks, or visitors with IPv6 will fail to connect.

6. Check it from outside

  1. Does the name point home? Look up home.yourname.uk.app with the DNS lookup and compare the A record with the address on ip.uk.app. After a change, the propagation checker shows which resolvers still have the old one.
  2. Is the port open from the internet? Run the open port checker against port 443. “Open” means your router forwards it and something answers. “Closed” or “timed out” means the forward, the device’s own firewall or CGNAT is in the way.
  3. Is the certificate right? The SSL checker shows whether the certificate covers the exact name, who issued it and when it expires.
  4. Test from outside for real. Turn Wi‑Fi off on your phone and open the address over mobile data. Testing from inside your own network can give misleading results.

If the port still shows as closed

  • Nothing is listening – the port checker reports “closed” if the forward works but the server isn’t running on that port. Test the server from another device at home first.
  • The server’s own firewall – Windows Defender Firewall, ufw or a NAS firewall can block the port even when the hub forwards it. A BT Community thread in the sources was solved exactly this way.
  • Wrong device – the server’s address changed and the rule still points at the old one. Recheck step 2.
  • Double NAT or CGNAT – see double NAT and CGNAT.
  • Testing from home – use mobile data; some hubs don’t loop traffic for the public address back inside.

A name for your next idea

Give your website, home server or next project a memorable address: yourname.uk.app. Choose your name and check availability before registering.

Find your name

Questions people ask

What is the default BT Smart Hub admin password?

It is unique to each hub and printed on the back of the hub or its pull‑out card, labelled as the admin password. If you changed it and forgot, a factory reset restores the printed one.

Does BT block any incoming ports?

BT doesn’t publish a list of blocked incoming ports for home broadband, and common ports such as 443 and 80 work for most people. If one specific port never works while others do, try a different external port.

Can I get a static IP from BT?

Static IP addresses are offered on BT Business broadband. Home customers normally have a dynamic address that changes rarely, which dynamic DNS handles.

Does UPnP work on BT hubs?

Yes, BT hubs support UPnP, which apps such as games consoles and Plex use to open ports automatically. For a server you rely on, a manual rule is more predictable.

Sources and further reading

We check each guide against the vendor’s own documentation and support forums. If something has changed on your firmware, tell us.

Partners