Which hub do you have?
- Hub 5 – the current hub on Virgin’s cable (DOCSIS) network. The steps below are for it.
- Hub 5x – supplied on Virgin’s full‑fibre (XGS‑PON) lines. Port forwarding is similar, but modem mode isn’t available at the time of writing.
- Hub 3 and Hub 4 – older models with a similar layout; menu names differ slightly.
Check that you have a public address: the hub’s status page shows its IPv4 address, which should match ip.uk.app. The CGNAT check compares them for you.
1. Sign in to the hub
Go to http://192.168.0.1 from a device connected to the hub. The page asks only for a password: it is printed on the card on the back of the hub, unless you changed it.
2. Reserve an address for your server
In Advanced settings → DHCP, find Reserved IP addresses and add a rule with your server’s MAC address (format 01:23:45:67:89:AB) and the IP address it should always get. Without this, the server can get a new address after a restart and your forward will point at nothing.
3. Add the port forward
- Go to Advanced settings → Security → Port forwarding.
- Add a rule: Local IP address (the reserved address), Local port range and External port range (for one port, the same number in start and end – for example
443–443), and Protocol (TCP for web apps, UDP for WireGuard). - Make sure the rule is enabled, and apply.
Restart after saving
Several people on the Virgin Media Community have found that a new rule appeared in the list but didn’t take effect until the hub was restarted. If a correctly entered rule shows as closed in the port checker, restart the hub before changing anything else.
You can’t forward the same external port to two devices. If you need a second server on the same service, use a different external port for it.
DMZ – only for your own router
Advanced settings → Security → DMZ sends every unrequested incoming connection to one address. Use it only to point at your own router in a double NAT set‑up, never at a PC or server.
4. Modem mode: use your own router
Many people with a mesh system or a better router switch the Hub 5 into modem mode. The hub then just passes the connection through, your router gets the public IP address, and you set port forwards and dynamic DNS there.
- Connect an Ethernet cable from one of the Hub 5’s Ethernet ports to your router’s WAN or Internet port.
- In the hub’s settings, find Modem mode, enable it and apply. The hub restarts; wait until its light is steady.
- Set your router’s WAN to obtain an address automatically (DHCP). If it doesn’t get one, try the hub’s other Ethernet ports – people report that not every port carries the connection in modem mode.
- To reach the hub later (to switch modem mode off), go to
http://192.168.100.1.
Note
In modem mode the hub no longer provides Wi‑Fi or a firewall. Your own router’s firewall now protects your network, so make sure it is on. Restart the hub before your router if the router doesn’t pick up an address.
5. Dynamic DNS
The Virgin Media hub has no dynamic DNS feature. Virgin addresses are dynamic but tend to stay the same for long periods – which is exactly why an updater is easy to forget until the day it changes. Run one on:
- your own router in modem mode, if it supports custom providers (see OpenWrt);
- a Synology NAS or Home Assistant;
- any Linux machine with the cron job in the start guide.
With a uk.app name, create a DDNS token in the dashboard and keep home.yourname.uk.app updated; point other names at it with CNAME records.
IPv6
Virgin Media has been enabling IPv6 on Hub 5 connections. If your devices have global IPv6 addresses, they may be reachable over IPv6 depending on the hub’s IPv6 firewall settings, which are separate from IPv4 port forwarding. Check those settings, and only publish an AAAA record for a service you have deliberately allowed through.
6. Check it from outside
- Does the name point home? Look up
home.yourname.uk.appwith the DNS lookup and compare the A record with the address on ip.uk.app. After a change, the propagation checker shows which resolvers still have the old one. - Is the port open from the internet? Run the open port checker against port 443. “Open” means your router forwards it and something answers. “Closed” or “timed out” means the forward, the device’s own firewall or CGNAT is in the way.
- Is the certificate right? The SSL checker shows whether the certificate covers the exact name, who issued it and when it expires.
- Test from outside for real. Turn Wi‑Fi off on your phone and open the address over mobile data. Testing from inside your own network can give misleading results.