PORT_FORWARDING_TESTER

> Diagnostic tool for verifying external connectivity.
> Supports standard services and custom TCP ports.

TCP_CONNECTION_PROBE
Test outbound connectivity to your services.
Minecraft::25565HTTP::80HTTPS::443SSH::22Plex::32400FTP::21
BATCH_OPERATION
Scan common vulnerability points simultaneously.
_
Technical Deep Dive

How TCP Port Scanning & Port Forwarding Work

A TCP port is a communication endpoint for network applications. When hosting services behind a home router, NAT gateway, or cloud firewall (AWS Security Groups, Cloudflare, GCP), port forwarding maps incoming public traffic to your local server's private IP.

01

1. TCP SYN Handshake Probe

Our external scanning probe transmits a TCP SYN packet to your target IP/hostname and designated port, waiting for a SYN-ACK response.

Client (SYN) -> Target (SYN-ACK) -> Client (ACK)
02

2. State & Timeout Evaluation

If the socket connects within timeout thresholds, the port is OPEN. If an RST packet is returned, the port is CLOSED (host up, no service listening). If dropped silently, it is FILTERED (firewall drop).

Status: OPEN | CLOSED | TIMEOUT
03

3. Service Banner Identification

For known protocols (SSH, HTTP, SMTP), the scanner checks protocol conformance to verify that the application layer is responding normally.

SSH-2.0-OpenSSH_9.6p1 Ubuntu

Common Port Forwarding & Firewall Issues

Double NAT (CGNAT / ISP Carrier Grade NAT)

ISP Routing

If your WAN IP in your router settings does not match your public IP (often starting with 100.64.x.x), your ISP uses CGNAT, blocking direct incoming port forwards without a VPN/tunnel.

Local Host Firewall (Windows Defender / UFW / iptables)

OS Firewall

Even if your router forwards port 25565 or 22, the local operating system firewall on the server machine must explicitly allow inbound connections on that port.

Cloud Security Group Restrictions

Cloud Config

On AWS EC2, DigitalOcean, or Azure VMs, inbound rules in the cloud dashboard must permit traffic from 0.0.0.0/0 on the specified port range.

Binding to localhost (127.0.0.1) vs 0.0.0.0

App Binding

If your daemon binds to 127.0.0.1 instead of 0.0.0.0, it will only accept connections from the local machine and will refuse all external forwarded requests.

Frequently Asked Questions

Everything you need to know about Open Port Checker and network reliability best practices.

Why does my port show closed when my server is running?

Common reasons include: the server application is bound to 127.0.0.1 rather than 0.0.0.0, the router port forwarding rule points to the wrong local IP address, or your ISP blocks incoming ports (e.g. port 80/25).

What are the most commonly forwarded ports?

Common ports include 22 (SSH), 80 (HTTP), 443 (HTTPS), 25565 (Minecraft Java), 19132 (Minecraft Bedrock), 32400 (Plex Media Server), 8080 (Web Dev), and 3389 (Remote Desktop RDP).

Is scanning open ports safe?

Yes. Our port checker executes a non-intrusive standard TCP connection attempt to verify external reachability. It does not perform invasive vulnerability probing.

How can I continuously monitor my custom TCP or UDP ports?

SteadyStack provides automated TCP and HTTP port monitoring from multiple geographic regions every 60 seconds, immediately notifying your team if a port stops responding.

Continuous Edge Verification

Automate Your Monitoring 24/7 with SteadyStack

Don't wait for manual tests. SteadyStack pings your endpoints from global edge locations every 60 seconds with quorum consensus to eliminate false alarms.

Start Free Monitoring