Port Forward

Port Forward

🚨 CRITICAL SECURITY WARNING

⚠️ Uplevel Strongly Advises: Do Not Use Port Forwarding

Keep your ports closed and connect to your internal network through a secure Client VPN tunnel instead.


✅ The Secure Way: Use Client VPN

Client VPN gives you secure, encrypted access to your LAN without exposing anything to the internet.
It keeps your systems protected behind the firewall where they belong.

Setup Guides:


❌ Why Port Forwarding is a Bad Idea

Instant Exposure:

  • The moment you open a port, your service is indexed by scanners like Shodan.io—often within hours.

  • Your public IP:port combination becomes a permanent target for automated attacks.

  • You’re effectively removing your firewall’s protection and relying entirely on the app’s own security.

Real-World Risk:

  • Firewall Threat Analysis can only block some HTTP or HTTPS threats—it doesn’t cover all protocols or new exploits.

  • Any new vulnerability (a “zero-day”) in that exposed service can be exploited instantly.

  • You’re betting your network’s safety on the software developer keeping up with global attackers.


⚠️ If You Absolutely Must Use Port Forwarding

Proceed with extreme caution and follow these steps:

Required Protections:

  1. In the Portal > Firewall > port forwarding settings, choose “Accept traffic exclusively from certain sources.”

  2. Add only the specific IP addresses that truly need access.

  3. Review and update this list often.

  4. Monitor system logs regularly for suspicious activity.

  5. Apply software updates immediately when available.

Know the Limits:

  • IP restrictions do not protect you from attacks if one of those allowed systems is compromised.

  • Threat Analysis provides only basic HTTP protection.

  • Any flaw in the exposed software gives attackers a direct entry point into your network.


🔒 The Bottom Line

Once you open a port, it will be attacked—constantly.
No matter how careful you are, eventually a vulnerability will appear, and it will be exploited.

Using a Client VPN eliminates that exposure completely.
Your services stay hidden from the internet, yet fully accessible to you and your team through a secure, authenticated connection.


    • Related Articles

    • Port Color Legend

      All Uplevel Hardware is outfitted with 1Gbps Auto-Negotiating Ports. When a connection is negotiated there are three (3x) negotiation possibilities. 1000BASE-T (1Gbps) Color Green in the Portal 100BASE-T (100Mbps) Color Blue in the Portal 10BASE-T ...
    • WAN Mapping - Multiple Static IPs

      Introduction This article describes the configuration, and mapping usage, when multiple Static IPs are added to the Primary or AUX WAN Ports. WAN Static IP Capabilities: Up to 4 Static IPs may be configured for each of the WAN Ports. Each Static IP ...
    • High Gain Wifi Antenna for Outdoor APs - 3rd Party

      When having to cover long distances with our Outdoor Access Points, we recommend using the Ubiquit airMax high gain antennas. They connect right up and have extended our APs range to over 600ft - ...
    • WAN Static IP Configuration Guide Prerequisites

      WAN Static IP Configuration Guide Prerequisites Administrative access to Uplevel portal ISP-provided static IP configuration parameters Network downtime maintenance window scheduled Setting Static IP From The Uplevel Portal Login to your Portal and ...
    • Uplevel SNMP - OIDs

      General System ============== System Description .1.3.6.1.2.1.1.1.0 = STRING: Uplevel Systems UG-101 Gateway System Uptime .1.3.6.1.2.1.1.3.0 = Timeticks: (193583855) 22 days, 9:43:58.55 System Name .1.3.6.1.2.1.1.5.0 = STRING: gateway System Date ...