11 ms·
How to Set Up a Router's Port Forwarding for a Nintendo Switch Console
- Terry_Roll 5y agoI cant believe a company this size could suggest such a thing, so has anyone tried doing this and then monitored what happens? Is the Switch able to do other stuff which is not reported or mentioned anywhere?
- dm319 5y agoDarn, I hope this isn't the solution to the problem I have where my switch won't join other worlds on minecraft.
- smcleod 5y agoPlayStation is pretty bad too, they want 80, 443 (and 1935, 3074, 3478-3479), if you don't you can get all sorts of really annoying problems joining games, delays joining voice chats etc....
- sneak 5y agoCox (US residential ISP) recently started blocking all port 80 inbound to residential IPs.
- KronisLV 5y agoDon't most ISPs already use NAT and therefore disallow all inbound traffic to devices behind it? I personally had to use WireGuard to work around it for some of my homelab servers that i wanted to publish: https://blog.kronis.dev/tutorials/how-to-publicly-access-your-homelab-behind-nat https://blog.kronis.dev/tutorials/how-to-publicly-access-you...
- smcleod 5y agoSome use CGNAT, but you can disable it if you need to run servers.
- IntelMiner 5y agoYou can disable it IF the ISP has an opt-out
- smcleod 5y agoSorry yes that is what I should have said
- sneak 5y agoI don't know about "most", but in the US, the residential broadband I've seen has public IPs. LTE/5G mobile networks do not.
- smcleod 5y agoThat's common in Australia and New Zealand along with some other potentially high risk ports, usually you can opt out of it in your settings.
- 3np 5y agoWTF are they strictly needing 80/443 for? Are those TCP?
- yrro 5y agoThey aren't. They need _outbound_ access to TCP ports 80/443, and Sony are too cheap to hire people who actually know what they're talking about to write support articles.
- fuzzy2 5y agoYeah except of course they do not actually need most of these. It’s all BS and it’s my favorite pet peeve with port forwarding guides. For whatever reason they almost always put all ports for both incoming and outgoing traffic in a list and call it a day.
- ZiiS 5y agoIf they need all your incoming traffic they should probably have called it a "router" not a "switch".
- hamasho 5y agoI'm sure "Nintendo Router" would be much more terrible product...
- toyg 5y agoAmong other problems, it would be pronounced differently in different countries...
- theginger 5y agoNintendo Firewall sounds good though.
- leshenka 5y agoSomething straight out of bowser's castle
- trembonator 5y ago
- gorpomon 5y agoA joke that could really only happen here, I happily give my upvote.
- cookiengineer 5y agoBa dum tzz... sigh take my upvote.
- sdiupIGPWEfh 5y agoI am ashamed that this has never occurred to me and shocked that I have never heard it elsewhere. Brilliant. Apparently, the "Nintendo WiFi Network Adapter" was once a thing in Japan, and it did have a router mode. https://www.wired.com/2008/09/nintendo-announ-2/ https://www.wired.com/2008/09/nintendo-announ-2/ https://www.famitsu.com/game/news/1217892_1124.html https://www.famitsu.com/game/news/1217892_1124.html https://kotaku.com/nintendo-announces-wii-ds-wifi-router-bwah-5046565 https://kotaku.com/nintendo-announces-wii-ds-wifi-router-bwa...
- ginko 5y agoWhat is this needed for? I never set up any port forwarding and don't remember having any issues with network connectivity. But then again I don't play that much online.
- smcl 5y agoI came to ask the same thing - I haven't picked up my Switch in a couple of months but I never touched my router settings for this and it was always working fine. Maybe it's just something from a recent Switch firmware update? Or perhaps just for online play in specific games.
- tootie 5y agoTypically you'd do this for enabling peer-to-peer connections. I run some Minecraft servers in my house this way. I have no idea what kind of peer-to-peer gaming Switch enables. Social gaming is done over the internet with a cloud subscription that costs like $20/year.
- smcl 5y agoYeah this is what I thought, I remember fiddling around with this to make Soulseek (or something) work on my old Linksys WRT54G back when I was at university. I wonder what Switch services/games work this way
- stevenwoo 5y agoI dunno if this had anything to do with it but there is peer to peer online gaming with Divinity Original Sin 2, and I tried grouping up with many folks I friended online and not in the same time zone and it never worked for us. Borderlands also appears to use peer to peer connections.
- goldcd 5y agoIt's pretty good advice, if you're Nintendo and spending a fortune trying to provide support advice to people with crappy router config/connections. Yes it's entirely likely to cause other problems - but probably going to get that switch working. Other problems will go to other vendors - and if their advice stops your switch from working, that's on them.
- spockz 5y agoSo… what if you have two switches?
- foxtrottbravo 5y agoYou obviously need a separate ISP package for every Switch you own
- spockz 5y agoAt that point it would be easier if it just came with its own 5g modem and ipv6 support.
- notum 5y agoExactly. Just like on the Apple's website: "If someone starts shooting at your iPhone: guard it with your body. Layers of tissue and fat should prevent the bullets from scratching iPhone's screen." Perfect business sense.
- hamasho 5y agoI guess they don't like it. If the device is not broken, but the user is dead, they have fewer consumers and more good devices in the secondhand market, no profit. But if the user survives and the device is broken, he or she continues to buy Apple products, at least the next one immediately, profit!
- andi999 5y agoIs this on their website, or is it a joke. Seriously, I cant tell anymore.
- rawling 5y agohttps://news.ycombinator.com/item?id=29903365 https://news.ycombinator.com/item?id=29903365
- mysterydip 5y agoWhat if I have two switches?
- julius_deane 5y agoon the first switch you redirect all ports to the second one I will not elaborate
- fuzzy2 5y agoYou’ll have to switch between them
- goodlinks 5y agoset up rules in your firewall for the correct NAT type either for your whole network or just those devices - unless something has changed recently.
- peppermint_tea 5y ago
- foxtrottbravo 5y agoLet's make it constructive then and talk about something that grinds my gears. Throwing all ports in the direction of a single host has nothing to to with a DMZ. I know consumer router manufacturers like to call it that but it isn't. It's an Exposed Host setup. A DMZ is a multi-tiered firewall approach where you have a Firewall between the internet and your DMZ and another one between your DMZ and your LAN
- IntelMiner 5y agoPlease don't use slurs to indicate points :(
- 46424ea63d4c 5y agoJust a quick advice, as I struggled with this as my daughter complained that she could not join network games in Animal Crossing because she had only “NAT Type D”. Forwarding all these ports was the recommended solution in Nintendo’s docs. However, it did nothing to resolve this problem. What helped was to ensure not to modify source ports in the NAT setup (“static-port” in pf).
- goodlinks 5y agoWhen i use routers provided by my ISP the switches always just work. when i was running pfsense (i need to set it up again soon :) ).. I just had to set a rule for them to always get the same IP and the correct NAT type and it worked perfectly. It does make me wonder if all ISP provided routers are pretty insecure in some way?
- vorticalbox 5y agodoes anyone know why? I don't have this set up on my network haven't had any issues.
- goodlinks 5y agoI have only seen this issue when running pfsense. and then to fix it i set up rules for the switch to ahve the type of NAT it wants. When i use a router from my ISP it always just works.
- vorticalbox 5y agomakes sense but what happens if you have multi switch's? do routers support forwarding to multiple hosts?
- goodlinks 5y agoI know very little about networking, but i know that my kids can play multiplayer at the smae time together that wont work until i set up thier NAT correctly. My naivity says that its either NAT handles it or the swithces are choosing random ports (or maybe negotiating through plug and play).
- MauranKilom 5y agoThis whole article is... optimistic. > 4. Enter the IP address you found on the network device, but add 20 to the last section of digits, and then select OK. > As an example, if your computer's IP address displays as 192.168.2.5, enter 192.168.2.25 on the Nintendo Switch. Hope you don't have more than 20 devices on your network (after your PC), and that they're not configured to be close to 255 there...
- toyg 5y agoTbf, this is the fault of network people, not the poor support guys left holding the bag of shit. The whole stack is still dangerous and obscure, 25 years after the internet went mainstream. UPnP was an effort at simplifying the situation and seems to have failed, so now we're back trying to teach IT toddlers to spell "characteristic" when they don't even know the ABC (nor do they care about it). It's inevitable that shortcuts will be taken.
- willis936 5y agoIt also assumes that your DHCP range is the top half of the last byte. That's a de facto convention in consumer routers, but not codified anywhere and the kind of thing that could change and probably isn't even correct for some routers shipping today.
- yardstick 5y agoDefinitely not codified anywhere, and not in any of the routers I’ve used (to be fair they are more prosumer). The main dhcp server used in most routers, dnsmasq, also assigns IPs using a MAC algorithm by default for consistent IP addressing of devices in a LAN. You would need to explicitly configure it for sequential first come first serve.
- thrdbndndn 5y agoJust curious, what if you have another layer of NAT, or your router is out of your control (and no UPnP)? You just can't play networked games with Switch, or what?
- rehamelbasha 5y agoAs a network engineer, this made me audibly sigh. Solid advice, redirect all incoming UDP traffic to your Switch, and your Switch alone...
- siva7 5y agoCan you explain the consequences to the plebs? :)
- iqanq 5y agoNone. Unwanted traffic will simply be discarded.
- toyg 5y agoFrom the little I understand of networking, this might mean that other machines on the network will never get that traffic (unless the Switch routes it and those machines use it as gateway, which is unlikely).
- cube00 5y agoI think we can safely assume something that needs 20k odd ports forwarded to it won't be doing anything like re-routing and acting as a secondary gateway on the network. It doesn't strike me that a lot of thought went into how a Switch would be used behind a firewall during the design if you need that many ports.
- misnome 5y agoApparently you only _need_ to forward 45000~65535: https://www.reddit.com/r/NintendoSwitch/comments/6qjhjy/i_have_figured_out_the_actual_range_of_ports_to/ https://www.reddit.com/r/NintendoSwitch/comments/6qjhjy/i_ha... I went through this when setting up the switch to talk to someone behind heavy NAT over the holidays. 45000+ worked for me. ....which makes this even more ridiculous if it never uses them.
- the_mitsuhiko 5y agoThat makes it worse. That means this is not actually a mistake in the documentation. JFC. Does it not support UPnP?
- loup-vaillant 5y agoProbably because of this: https://duckduckgo.com/?t=ffab&q=UPnP https://duckduckgo.com/?t=ffab&q=UPnP Among the 4 first links, 3 explicitly tell me that UPnP is dangerous.
- yardstick 5y agoCame here to say this. UPnP is a security vulnerability, not a feature.
- solarkraft 5y agoWorse than forwarding all ports?
- yardstick 5y agoNeither is an acceptable solution. Although I will say that if you are forwarding all ports, at least it’s to a device you know about. Not some random IoT or PC software or whatever opening up ports without your knowledge.
- the_mitsuhiko 5y ago
- thanatos519 5y agoWhat, they can't use UPnP like a good citizen?
- deleted 5y ago[deleted]
- OldTimeCoffee 5y agoBecause UPnP is disabled by default on a lot of routers.
- deleted 5y ago[deleted]
- yrro 5y agoMaybe if the network administrator has disabled UPnP that is a hint that they don't want to allow random devices to expose themselves to the entire internet?!
- GekkePrutser 5y agoI don't think upnp is used a lot anymore as it's also really handy for malware makers
- 1_player 5y agoWhat? It's used by tons of legitimate applications as well. Not only malware benefits from being able to accept connections from the Internet. Games, torrents and other p2p services, etc.
- GekkePrutser 5y agoI play a lot of games and I've never had any issues not having UPnP. They got used to working around it. Probably with centralised servers. I never liked the P2P model anyway, dedicated servers are more fun because you can influence the gamemode, add mods etc. For torrents I don't know... If I were to torrent I would not do it without VPN anyhow.
- mschuster91 5y agoMy s/o and her sister (CS student) regularly play Animal Crossing over the Internet. I (and the SIL) wanted to curse Nintendo to hell and back for requiring users to essentially put their Switches available to the wide Internet (meaning, as long as the Switch is powered on, any RCE exploit on the Switch turns it into a full, unrestricted gateway into my home network!) simply because Nintendo doesn't want to follow basic Internet standards like UPnP or, heaven forbid, provide STUN/TURN proxies paid for by the Nintendo Online subscription. Hell it took years for them to implement Bluetooth audio on the Switch, and that's output-only, no microphone. What stuff is their software division smoking?
- echelon 5y agoNintendo, despite making some of the first attempts at networked play in the late 80's and 90's, does not really understand the internet. https://en.wikipedia.org/wiki/Family_Computer_Network_System https://en.wikipedia.org/wiki/Family_Computer_Network_System (1988) https://en.wikipedia.org/wiki/Satellaview https://en.wikipedia.org/wiki/Satellaview (1995) https://en.wikipedia.org/wiki/64DD https://en.wikipedia.org/wiki/64DD (1999) They don't understand a lot of things, even some of which they've lucked into, like the competitive Smash scene. Or fan remakes and tributes (of which Sega notoriously doesn't send their lawyers after). But they still make some incredibly compelling games.
- djtango 5y agoYes networking is def not a core competency. Strange though, the senior people are super technical (I recall the stories of Iwata writing compression algos in Pokemon) Maybe the DNA of the company is just too focused on games specifically
- smaudet 5y agoThis is just an aside, but this might explain why their (online) shop sucks so hard (and no browser on what amounts to a phone without a SIM card?)... It's not just that the UX is a bit clunky, it's that it's a veritable morass of junk, a lot of which is regurgitated ports of PC titles... They didn't understand how online shops work, to be fair all titles still at least play, but there is not as high quality control as I would have expected. I say this as, Nintendo has a reputation and clout as a games developer (honestly none of their consoles have ever been great - they have mishaps in the software world but it is rarer), looking at their store you see a suspicious similarity to steam with sales - in fact as far as software goes a humble bundle subscription is probably a better value proposition. It's just not the rich and high quality, unique catalog people have come to associate with them. Maybe it was always like that regarding 3rd party games, but it just underlines how much they don't understand the internet...
- _trampeltier 5y agoYou allways have to, why? And I was so close to buy a Switch. But no .. never gona happen to may home Network.
- hwers 5y agoWhat's the reason not to open all ports btw? Outing myself as naive by asking
- 3np 5y agoIt’s about redirecting. Following these instructions means that the Switch, and only the Switch, can receive UDP on behalf of the other network. Which will break a lot of things. Supposedly this also means that more than one Switch on the same network is a no-go.
- foxtrottbravo 5y agoIn a normal NATed setup your ports are closed from the outside until a client from inside your network Starts sending packets to the outside. The Router will keep track of network package going through to the Internet and store it in a table. in case there is an answer from outside of your network the router will look up whether a client started this conversation (there is a corresponding entry in his table) and will forward the incoming packet to the client that started the conversation. What nintendo is asking you to allow here is to allow any outside packet coming in over UDP to get to the switch whether it first asked for it or not. This means in practice you won't be able to run any other service which needs an UDP port fowarded in your network. It also means anyone can talk directly to your switch on any port they like whether you want to or not. And it means, that should something ever take/get the same IP as the switch it will be exposed to the Internet directly
- grayfaced 5y agoIt's not a firewall acl, it's a port forwarding rule. In a NAT, UDP connections you initiate will be added to NAT table temporarily to handle replies. Nintendo's port range covers all the ephemeral ports that OS will naturally give to UDP connections. So your computer may attempt to start a UDP communication but the reply traffic will be forwarded to your switch instead of using NAT table. So nothing else can use UDP properly. That DNS request to port 53 has a source port of 42981 (for example), and the switch gets the reply. I'm not sure if most routers prioritize port forwarding rules or NAT tables. That's really up to implementation.
- icf80 5y agodoesn't ipv6 fixes those issue?
- foxfluff 5y agoIt will, I guess. In the same sense that fusion power will fix our energy issues.
- fulafel 5y agoDo you mean the need to configure your CPE to allow incoming traffic to specific devices? Not really, with v6 you have to put in allow-rules too if you have the normal default-deny firewall rules in the CPE. It could be automatic with UPnP, but it could be automatic with v4 + NAT too. The article doesn't say if the Switch supports that.
- zibzab 5y agoThat's not portforwarding, that's moving to the DMZ...