Check two things first
- Does your TP‑Link have a public WAN address? TP‑Link’s own help says port forwarding only works when the router’s WAN IP is public. On an Archer, look at the status page; in the Deco app, More → Internet Connection → IPv4. Compare with ip.uk.app.
- If the WAN address starts with 192.168, 10 or 172.16–31, the TP‑Link sits behind another router – usually the ISP hub. That’s double NAT. If it’s in 100.64–100.127, it’s CGNAT, common on TP‑Link kit supplied by full‑fibre providers.
Archer routers (web interface)
1. Reserve an address for the server
Sign in at http://tplinkwifi.net (or the router’s LAN address, often 192.168.0.1 or 192.168.1.1). Go to Advanced → Network → DHCP Server and add an entry under Address Reservation for your server, so its address never changes.
2. Add the port forward
- Go to Advanced → NAT Forwarding → Port Forwarding. Older firmware calls this page Virtual Servers.
- Click Add. Enter a Service Name (or pick one from the list), the Device IP Address (choose from connected devices or type it), the External Port and Internal Port (usually the same, for example 443) and the Protocol (TCP, UDP or All).
- Tick Enable This Entry and save.
To reach two servers on the same port, give each a different external port and the same internal port, as TP‑Link’s FAQ describes.
Deco mesh (app)
- In the Deco app, go to More → Advanced → NAT Forwarding → Port Forwarding and tap + (or Add Port Forwarding Rule).
- Choose a Service Type, or Custom and enter a service name.
- Pick the Internal IP from the list of devices. The Deco can’t take a typed address: the server must be connected to the Deco network and have an address before it appears.
- Enter the External Port. Leave Internal Port blank to use the same number. Save.
Deco behind an ISP hub
A Deco plugged into a BT, Sky or Virgin Media hub runs in router mode by default, giving you double NAT. Either put the Deco into access‑point mode (More → Advanced → Operation Mode) and forward on the ISP hub, or put the ISP hub into modem mode where possible and forward on the Deco. See double NAT.
Dynamic DNS: two ways to use your own name
TP‑Link’s DDNS page (Advanced → Network → Dynamic DNS on Archers; More → Advanced → DDNS on Deco) supports a fixed set of providers – TP‑Link’s own tplinkdns.com service and, on many models, No‑IP and DynDNS. There is no custom option, so it can’t update a uk.app name directly. You have two good options:
Option A: point your name at the TP‑Link DDNS name
Turn on TP‑Link DDNS and register a hostname such as yourhome.tplinkdns.com. Then, in the uk.app DNS settings, add a CNAME record home → yourhome.tplinkdns.com. The router keeps the TP‑Link name up to date, and your own name simply follows it. Nothing else to run. Certificates for home.yourname.uk.app still work, because they are issued for your name, not TP‑Link’s.
Option B: run an updater elsewhere
Use a uk.app DDNS token with an updater on another always‑on device – the cron job in the start guide, Home Assistant or a Synology NAS. This avoids depending on a second provider.
Tip
Behind double NAT, TP‑Link DDNS may publish the router’s private WAN address, and the updater on another device will publish the right one. TP‑Link’s DDNS troubleshooting page explains how to spot this.
Built‑in VPN server
Many recent Archer models include a VPN server, with WireGuard on newer firmware alongside OpenVPN (Advanced → VPN Server → WireGuard). Deco has a WireGuard server on supported models too. If yours has WireGuard, it is an easy way to follow our VPN approach without a separate machine – the router generates the client configuration for you. Avoid PPTP, which is no longer considered secure.
Check it from outside
- Does the name point home? Look up
home.yourname.uk.appwith the DNS lookup and compare the A record with the address on ip.uk.app. After a change, the propagation checker shows which resolvers still have the old one. - Is the port open from the internet? Run the open port checker against port 443. “Open” means your router forwards it and something answers. “Closed” or “timed out” means the forward, the device’s own firewall or CGNAT is in the way.
- Is the certificate right? The SSL checker shows whether the certificate covers the exact name, who issued it and when it expires.
- Test from outside for real. Turn Wi‑Fi off on your phone and open the address over mobile data. Testing from inside your own network can give misleading results.
If the port stays closed
- The WAN address isn’t public – see the first section.
- The server’s own firewall blocks the port, or nothing is listening on it.
- The rule isn’t enabled, or points at an old address – set up the reservation first.
- You are testing from inside your own network; use mobile data.