Guide

TP‑Link port forwarding on Archer routers and Deco mesh

TP‑Link makes both the routers many people buy to replace an ISP hub and the Archer and Deco kit that several UK full‑fibre providers supply. Port forwarding is straightforward on both. The traps are double NAT behind an ISP hub, CGNAT on some fibre providers, and a DDNS menu that only knows a few providers.

Updated · Checked against TP-Link support FAQs 1379, 1797 and 3649, September 2026 · 4 min read

Archer web UI
tplinkwifi.net or the router’s LAN IP
Archer menu
Advanced → NAT Forwarding → Port Forwarding
Deco menu
App: More → Advanced → NAT Forwarding
Built‑in DDNS
TP‑Link, No‑IP, DynDNS only

Check two things first

  1. Does your TP‑Link have a public WAN address? TP‑Link’s own help says port forwarding only works when the router’s WAN IP is public. On an Archer, look at the status page; in the Deco app, More → Internet Connection → IPv4. Compare with ip.uk.app.
  2. If the WAN address starts with 192.168, 10 or 172.16–31, the TP‑Link sits behind another router – usually the ISP hub. That’s double NAT. If it’s in 100.64–100.127, it’s CGNAT, common on TP‑Link kit supplied by full‑fibre providers.

Archer routers (web interface)

1. Reserve an address for the server

Sign in at http://tplinkwifi.net (or the router’s LAN address, often 192.168.0.1 or 192.168.1.1). Go to Advanced → Network → DHCP Server and add an entry under Address Reservation for your server, so its address never changes.

2. Add the port forward

  1. Go to Advanced → NAT Forwarding → Port Forwarding. Older firmware calls this page Virtual Servers.
  2. Click Add. Enter a Service Name (or pick one from the list), the Device IP Address (choose from connected devices or type it), the External Port and Internal Port (usually the same, for example 443) and the Protocol (TCP, UDP or All).
  3. Tick Enable This Entry and save.

To reach two servers on the same port, give each a different external port and the same internal port, as TP‑Link’s FAQ describes.

Deco mesh (app)

  1. In the Deco app, go to More → Advanced → NAT Forwarding → Port Forwarding and tap + (or Add Port Forwarding Rule).
  2. Choose a Service Type, or Custom and enter a service name.
  3. Pick the Internal IP from the list of devices. The Deco can’t take a typed address: the server must be connected to the Deco network and have an address before it appears.
  4. Enter the External Port. Leave Internal Port blank to use the same number. Save.

Deco behind an ISP hub

A Deco plugged into a BT, Sky or Virgin Media hub runs in router mode by default, giving you double NAT. Either put the Deco into access‑point mode (More → Advanced → Operation Mode) and forward on the ISP hub, or put the ISP hub into modem mode where possible and forward on the Deco. See double NAT.

Dynamic DNS: two ways to use your own name

TP‑Link’s DDNS page (Advanced → Network → Dynamic DNS on Archers; More → Advanced → DDNS on Deco) supports a fixed set of providers – TP‑Link’s own tplinkdns.com service and, on many models, No‑IP and DynDNS. There is no custom option, so it can’t update a uk.app name directly. You have two good options:

Option A: point your name at the TP‑Link DDNS name

Turn on TP‑Link DDNS and register a hostname such as yourhome.tplinkdns.com. Then, in the uk.app DNS settings, add a CNAME record home → yourhome.tplinkdns.com. The router keeps the TP‑Link name up to date, and your own name simply follows it. Nothing else to run. Certificates for home.yourname.uk.app still work, because they are issued for your name, not TP‑Link’s.

Option B: run an updater elsewhere

Use a uk.app DDNS token with an updater on another always‑on device – the cron job in the start guide, Home Assistant or a Synology NAS. This avoids depending on a second provider.

Tip

Behind double NAT, TP‑Link DDNS may publish the router’s private WAN address, and the updater on another device will publish the right one. TP‑Link’s DDNS troubleshooting page explains how to spot this.

Built‑in VPN server

Many recent Archer models include a VPN server, with WireGuard on newer firmware alongside OpenVPN (Advanced → VPN Server → WireGuard). Deco has a WireGuard server on supported models too. If yours has WireGuard, it is an easy way to follow our VPN approach without a separate machine – the router generates the client configuration for you. Avoid PPTP, which is no longer considered secure.

Check it from outside

  1. Does the name point home? Look up home.yourname.uk.app with the DNS lookup and compare the A record with the address on ip.uk.app. After a change, the propagation checker shows which resolvers still have the old one.
  2. Is the port open from the internet? Run the open port checker against port 443. “Open” means your router forwards it and something answers. “Closed” or “timed out” means the forward, the device’s own firewall or CGNAT is in the way.
  3. Is the certificate right? The SSL checker shows whether the certificate covers the exact name, who issued it and when it expires.
  4. Test from outside for real. Turn Wi‑Fi off on your phone and open the address over mobile data. Testing from inside your own network can give misleading results.

If the port stays closed

  • The WAN address isn’t public – see the first section.
  • The server’s own firewall blocks the port, or nothing is listening on it.
  • The rule isn’t enabled, or points at an old address – set up the reservation first.
  • You are testing from inside your own network; use mobile data.

A name for your next idea

Give your website, home server or next project a memorable address: yourname.uk.app. Choose your name and check availability before registering.

Find your name

Questions people ask

What’s the difference between Port Forwarding and Virtual Servers?

They are the same feature. Newer TP‑Link firmware calls it Port Forwarding under NAT Forwarding; older firmware calls it Virtual Servers.

Can I use a custom DDNS provider on TP-Link?

Not in the stock firmware; the list is fixed. Use a CNAME to the TP‑Link DDNS name, or run an updater on another device.

My fibre provider supplied the TP-Link. Can I change its settings?

Usually yes – providers normally give you the admin password or it is printed on the router. Some lock the WAN settings. If the WAN address is in the 100.64.0.0/10 range, ask the provider for a public IP; see the CGNAT guide.

Sources and further reading

We check each guide against the vendor’s own documentation and support forums. If something has changed on your firmware, tell us.

Partners