How can a device behind a NAT create its own port-forwarding mapping with UPnP IGD, NAT-PMP or PCP, and how do the three differ?
answer
- the host asks the gateway
- leases versus forever
- UDP 5351 to the default gateway
- version 0 vs version 2
- who picks the external port
basics
~20 sThe host asks the gateway directly. UPnP IGD is a UPnP Forum protocol using XML over HTTP; NAT-PMP (RFC 6886) is a small leased UDP protocol; PCP (RFC 6887), its Standards Track successor, adds IPv6, firewalls and carrier-grade NAT.
solid answer
~40 sAll three let an application open an inbound mapping only while it needs one and learn the external endpoint it got; none tells peers where to connect. UPnP IGD comes from the UPnP Forum, not the IETF: SSDP discovery, then XML requests over HTTP; in IGD 1.0 the client names a port and hears yes or no, and clients usually ask for unlimited leases. NAT-PMP (RFC 6886, Informational) sends small UDP requests to port 5351 of the default gateway: opcodes 1 and 2 map UDP and TCP, the gateway assigns another port if the suggested one is taken, and the recommended lease is 7200 seconds, renewed halfway. PCP (RFC 6887, Standards Track) keeps those ports with version 2 and adds `MAP`/`PEER`, IPv6, firewalls, carrier-grade NAT, nonces and options like `THIRD_PARTY` and `FILTER`.
code
pseudocode · 12 linesgw = default_gateway_ipv4()
want = 8443
loop:
send_udp(gw, 5351, vers=0, op=2, internal=443,
suggested=want, lifetime=7200)
r = await_reply(from=gw, first_wait_ms=250) # wait doubles on retry
if r.result != 0:
log("mapping refused", r.result)
stop
advertise(external_address(gw), r.mapped_port) # may differ from want
want = r.mapped_port # renewals suggest the granted port
sleep(r.lifetime / 2) # renew halfway to expirygo deeper
Recall that some applications ask the router to open a port for them, and name UPnP IGD, NAT-PMP and PCP as the protocols that do it.
Explain request, granted port, lifetime and renewal, and what changed from NAT-PMP's version 0 to PCP's version 2.
Judge which protocol to rely on given what gateways support, how mappings are lost on reboot, and why leases and source-address binding matter for safety.
Weigh application-requested mappings against relays or IPv6 as the product's inbound strategy, including how much you depend on home and ISP gateways.
## Why devices ask for their own mappings A static rule needs someone to configure it and stays open until someone removes it. Applications that want to receive connections, such as a game hosting a match, a peer-to-peer client, a call or a home camera, need a mapping only while they run, and they need to learn which external address and port they got so they can tell peers. Three protocols let a host ask the NAT directly. None of them tells peers where to connect: the PCP specification says it "does not provide this rendezvous function", so the application publishes the endpoint itself, through its own matchmaking server, a SIP proxy or DNS. ## UPnP Internet Gateway Device UPnP IGD comes from the **UPnP Forum**, not the IETF. A host discovers the gateway with SSDP multicast, then sends XML control requests over HTTP on a TCP connection. It was designed as a general gateway-administration protocol, and that shows in its port-mapping behaviour: - In IGD 1.0 the client names the external port it wants and the answer is yes or no (RFC 6269); a client that hears no guesses the next port. IGD 2.0 lets the gateway allocate any available port. - RFC 6886 (section 9.4) reports that some IGD gateways answer a request for a port already in use by silently overwriting the old mapping, so two clients take the port from each other indefinitely. - A lease duration exists, but RFC 6886 observes that clients in practice ask for 0, meaning no expiry, so mappings outlive the applications that made them. ## NAT-PMP (RFC 6886) NAT-PMP served for almost a decade before RFC 6886 documented it in 2013 as an **Informational** RFC, already superseded by PCP. It is deliberately small and IPv4-only: 1. The client sends a UDP request to **port 5351 of its default gateway**, with version 0. 2. Opcode 0 asks for the external IPv4 address; opcode 1 maps a UDP port and opcode 2 a TCP port. The response opcode is 128 plus the request's. 3. A mapping request carries the internal port, a **suggested** external port and a requested lifetime. If the suggested port is taken, the gateway MUST return another available port if it can. 4. The **recommended lifetime is 7200 seconds** (two hours). The client renews halfway to expiry, and a requested lifetime of 0 deletes the mapping. 5. The gateway announces restarts and address changes to `224.0.0.1` port 5350, so clients can recreate mappings a reboot lost. Two rules carry its security: the mapping's internal address MUST be the request's **source address**, and the gateway MUST NOT accept requests on its external interface. ## PCP (RFC 6887) The **Port Control Protocol** is the Standards Track successor. It keeps UDP ports 5350 and 5351 and a compatible header with **version 2**, so a server can tell the two protocols apart from the first byte. RFC 6886 lists what it adds: IPv6, management of outbound mappings and firewall rules, compatibility with large NATs that hold a pool of external addresses, error lifetimes, and an extension mechanism. - **Opcodes:** `ANNOUNCE` (0), `MAP` (1) for inbound mappings, and `PEER` (2) to create or learn about an outbound mapping. - **Scope:** NAT44, NAT64 and firewalls, where the mapping is the identity function and only filtering changes; residential NATs and carrier-grade NATs alike. - **Server:** a configured one if there is one, otherwise the default router. - **Response:** the assigned external address and port; an IPv4 address is carried as an IPv4-mapped IPv6 address. - **Mapping nonce:** a random value that ties a mapping to its creator and is repeated in renewals. - **Options:** `THIRD_PARTY` maps for another host and only on a fully trusted network; `PREFER_FAILURE` fails rather than assign a different port, for interworking with UPnP IGD 1.0 semantics; `FILTER` admits only named remote peers. - **Renewal:** at a random point between 1/2 and 5/8 of the lifetime. ## Side by side | | UPnP IGD | NAT-PMP | PCP | |---|---|---|---| | Published by | UPnP Forum | IETF, Informational | IETF, Standards Track | | Messages | SSDP discovery, XML over HTTP | UDP to gateway port 5351 | UDP to server port 5351 | | Port already taken | yes or no in 1.0; some gateways overwrite | gateway assigns another | server assigns another unless `PREFER_FAILURE` | | Lifetime | often unlimited in practice | leased, 7200 s recommended | leased and renewed | | Mapping for another host | the request names an internal host | forbidden | only with `THIRD_PARTY` | ## What a client loop looks like The code example shows a NAT-PMP client that maps internal TCP 443, accepts whatever external port the gateway grants, and renews halfway through the lease, suggesting the granted port so a rebooted gateway can restore it.
- Why does a NAT-PMP or PCP renewal suggest the external port the gateway granted rather than the one the client first wanted?Small gateways often keep mappings only in memory, so a reboot loses them. If the renewal suggests the port that was actually granted, a freshly restarted gateway sees an ordinary request for a port it is willing to hand out and recreates the same mapping, keeping the endpoint the client already advertised to peers.
- How does a client know whether its gateway speaks PCP or only NAT-PMP?Both use UDP port 5351 and put the version in the first byte: 0 for NAT-PMP, 2 for PCP. A client should send PCP first; a NAT-PMP-only gateway answers with an Unsupported Version result, and the client retries at once in NAT-PMP format. RFC 6886 says the client should not remember that result permanently, because gateway firmware gets updated.
saying these in an interview costs you the question
- UPnP IGD is an IETF standard for port mapping.
- NAT-PMP mappings stay open until the client deletes them.
- PCP tells remote peers which external port to connect to.
- A NAT-PMP host can create a mapping for another device on the LAN.
- PCP and NAT-PMP use different UDP ports, so they cannot coexist.