How to See and Remove UPnP Port Forwards from Your iPhone

By Paul Snyman · Published · 7 min read

Short version. When UPnP is on, any device on your network can ask your router to open a port from the internet to itself, and the router keeps a table of what it agreed to. On an iPhone joined to your own Wi-Fi, PingKit's Router mode reads that table with Guardian, names what each port is usually for, marks the services that are not usually opened to the internet, and removes an entry after you confirm. Some routers refuse removal from an app, a device can ask again, and a rule you typed into the router yourself may not be listed, so the router's own admin page stays the final word.

What a UPnP Port Forward Is

Your router lets connections out to the internet freely and turns unrequested connections from the internet away. A port forward is an exception: a rule that sends traffic arriving on one port of your public address to one device at home. You can type one into the router's admin page yourself, or, if UPnP is switched on, a device can ask the router for one and the router adds it without asking you.

That second route is why UPnP exists. A game console needs other players to reach it, a NAS wants to be reachable when you are away, a media server wants to stream to your phone on the train. Each asks the router for the port it needs and it works without anyone opening a settings page. The price is that the list of what your network exposes grows by itself, and nobody looks at it.

Why the Table Is Worth Reading

PingKit's Security Scan reports UPnP Enabled when your router answers UPnP discovery. That tells you the door can open. It does not tell you what has come through it. The table does: every forward the router agreed to, which device it points at, and usually the name the device gave when it asked.

Reading it answers the questions that matter. Is anything pointed at a device you replaced last year? Did a camera or a recorder open its own path in? Is a computer offering remote desktop to the whole internet because some app asked for it once? Those are the forwards worth removing, and you only find them by looking.

Reading the Table on Your iPhone

  1. Join your own Wi-Fi. Router mode talks to the router of the network your iPhone is on, and nothing else.
  2. Open PingKit, go to the Tools tab and tap Router, in the Network group.
  3. After a few seconds of asking the router, the section called What the internet can reach lists every forward. The table is part of PingKit Guardian; without it the section is locked, and the free status view above it is unchanged.

Each entry has two lines. The first names the port, the protocol and what the port is usually for, such as Port 32400 (TCP): a Plex media server. The second says where the traffic goes and who asked for it, such as To 192.168.1.20 port 32400, asked for by "Plex Media Server". When PingKit does not recognise a port, it shows the number and protocol only, and the device's own description is the best clue.

Router mode in PingKit for iPhone: the router's make and model, its internet connection, public address and line rate, and the ports it forwards from the internet to devices at home.
Each forward: the port, what it is usually for, the device it reaches and the name that device gave when it asked. The bin removes one.
UsuallyPortTypical owner
Xbox online play3074An Xbox
Game and voice chat3478Consoles and calling apps
A Plex media server32400The computer or NAS running Plex
A Minecraft server25565Someone's Java Edition server
A VPN1194 or 51820OpenVPN or WireGuard at home
A NAS's web page5000 or 5001A NAS offering remote access

The Entries Marked "Worth a Look"

Seven services get an orange note in Router mode, because they are rarely meant to be reachable by anyone on the internet: file transfer (FTP, 21), remote login (SSH, 22), remote login without encryption (Telnet, 23), file sharing (445), a camera or video stream (554), remote desktop (3389) and screen sharing (5900).

The note is a prompt, not a verdict. If you run an SSH server at home on purpose and keep it patched, its forward is exactly right. What deserves action is the forward nobody remembers asking for: a remote desktop port opened by a program you have since uninstalled, a camera that opened 554 to itself so its app could stream, a file share someone exposed while testing. Is your security camera reachable from the internet? covers the camera case step by step.

Removing a Forward

Tap the bin beside the entry. PingKit asks you to confirm and says what will happen: the device at that address stops being reachable from the internet on that port, and it can ask your router again if it needs to. Confirm, and PingKit asks the router to delete the entry, then reads the whole table again, so what you see afterwards is what the router actually holds.

Two things can happen that are not PingKit's to decide:

What the Table Cannot Show You

Router mode reads what your router publishes over UPnP, and that is not always everything:

When the Router's Own Page Is the Better Answer

For a complete audit, open the admin page. Router mode's status view has a link to it, and it is usually the gateway address PingKit shows, such as 192.168.1.1. That page lists the forwards you set by hand next to the UPnP ones, lets you switch UPnP off altogether or, on some routers, per device, and holds the DMZ and IPv6 settings. What the iPhone adds is speed and plain language: a thirty-second look from the sofa at what the internet can reach, with the entries that deserve attention already marked.

With Guardian, the network report also carries a Port Forwarding section from Router mode's last reading, dated, which is a simple way to keep a record of what was open and when.

Frequently Asked Questions

How do I see UPnP port forwards on my router?

Open your router's admin page and look for a UPnP or port forwarding section. From an iPhone joined to your own Wi-Fi, PingKit's Router mode reads the same UPnP table with Guardian and lists each forward with the device it points at and what the port is usually for.

Can I remove a UPnP port forward from my iPhone?

Often. In Router mode, tap the bin beside the entry and confirm, and PingKit asks the router to delete it and re-reads the table. Many routers only allow changes in their own settings, or only let the device that asked for a forward remove it, and PingKit tells you when the router refuses. A device with UPnP on can ask for the forward again, so switch UPnP off on the device or the router to stop it.

Why does Router mode not show a port forward I set up myself?

Router mode reads the table your router publishes over UPnP. On many routers a rule typed into the admin page by hand is kept separately and is not part of that table, so the router's own port forwarding page is the complete list.

Is it safe to leave UPnP on?

It depends on what is on your network. UPnP lets any device on it open ports without asking you, which is convenient for consoles and media servers and risky for anything poorly maintained. Reading the table from time to time, and removing what you do not recognise, is the middle ground. What Is UPnP and Should You Turn It Off? goes through the trade-off.

Is the port forwarding table free in PingKit?

No, it is part of PingKit Guardian, $2.99 a month or $24.99 a year with a 1-week free trial. Router mode's status view, with the internet link, public address and line rate, is free.

Read your own router from your iPhone.

Router mode's status view is free. Guardian adds the port forwarding table, $2.99 a month or $24.99 a year with a 1-week free trial.

Download PingKit for iPhone

Get the free PingKit Agent for Mac

Related Articles