Port forwarding on a TP-Link router

Archer series through the web interface, and Deco mesh through its app.

This opens a door into your own network and you are responsible for what

comes through it. Read the warnings first if you have not.

Log in

Default address is http://tplinkwifi.net, or 192.168.0.1 or 192.168.1.1 depending on model. Deco uses 192.168.68.1. If none work, read the default gateway from a client: Windows calls it Default Gateway, macOS and iOS call it Router, Android calls it Gateway.

Older models ship with admin / admin. Newer ones have no default and make you create a password at setup. There is no recovery on most models: either use Password Recovery if you set it up, or hold Reset for about 10 seconds with the router powered on, which wipes wifi settings, internet settings and any forwarding rules you already had.

Give the board a fixed address

Go to Advanced > Network > DHCP Server > Address Reservation, click Add, enter the board's MAC address and the address you want, then enable the entry. The address must be inside the router's own range. Some models want a reboot.

Add the rule

The menu depends on which interface generation your model runs, so check the screen rather than the model number.

For a board on the middle interface: External Port 6400, Internal Port 6400, Internal IP the address you reserved, Protocol TCP, then Save.

The same page also holds Port Triggering, DMZ and UPnP. Virtual Servers wins over all three when rules overlap. Do not use DMZ.

The Tether app

TP-Link's port forwarding documentation covers the web interface only. Tether keeps its settings under Tools, and some recent models expose forwarding there, but there is no official page naming that path. Treat it as model-dependent and use the web interface if you cannot find it.

Deco mesh

Documented, and different: Deco app > More > Advanced > NAT Forwarding > Port Forwarding, then the + icon. Fields are Service Type (or Custom plus a Service Name), Internal IP, External Port, Internal Port. Leave Internal Port blank and it matches the external one.

Deco will not accept a typed address: the board must already be connected and holding a lease so you can pick it from the list. Some models cap out at 64 rules.

When it does not work

Sources