AnonymFlow
securite-reseauINFO

VPN Port Forwarding: What It Does, and Why Providers Keep Removing It (2026)

Port forwarding opens a way in from the internet to a machine behind the VPN. What it actually enables, why torrent clients ask for it, and why serious no-log providers switch it off rather than fix it.

By Eric Gerard · Editor · AnonymFlow3 min readPhoto: Pexels

A VPN normally works one way round: you open connections outwards, and answers come back down the tunnel you opened. Nothing on the internet can start a conversation with you. That is a large part of why a VPN feels safe.

Port forwarding is the exception you ask for. It tells the provider to accept incoming connections on a chosen port at its server, and hand them to your machine through the tunnel. It punches a way in.

What it actually enables

BitTorrent connectability. Without an open port your client can only reach outwards, to peers that accept incoming connections. You still download, but you are invisible to a large share of the swarm and your upload suffers. With a forwarded port, other peers can reach you. That is why the question usually shows up in a qBittorrent or Deluge context.

Reaching something you host. A game server, a self-hosted service, an SSH port - anything that has to be dialled into rather than out of. Behind the VPN with no forwarded port, nobody outside gets to it.

Both are legitimate, and both need the same thing: an open door.

Why the door is being bricked up

This is the part most articles skip, and it matters more than any setup guide.

Mullvad removed port forwarding entirely. The announcement came on 29 May 2023, and existing forwarded ports were deleted on 1 July 2023. The stated reason was abuse: forwarded ports were used to host undesirable content and malicious services from Mullvad's own servers. The consequences the company listed are concrete - law enforcement making contact, IP addresses blacklisted, hosting providers cancelling service. That last one hits every user of the affected servers, not just the abuser.

CEO Jan Jonsson stated the structural problem plainly: "Since Mullvad is taking a great deal of effort into keeping users private, and not logging traffic, we can not block bad users or identify bad users, so we become a safe haven for bad stuff."

Read that twice, because it is the whole argument. A provider that genuinely does not log cannot identify who is abusing a forwarded port. It cannot ban the individual, because it does not know who the individual is. Its only lever is to close the feature for everyone.

The removal is therefore neither laziness nor cost-cutting. It is what happens when a no-log policy meets a feature that invites abuse. A provider that could police forwarded ports precisely would be a provider that knows far more about you than you want.

What that changes when you choose

Treat "port forwarding available" as a real differentiator, and ask what it costs. A provider offering it either absorbs the abuse burden or keeps enough information to manage it. Which of the two is worth knowing before you pay.

Do not assume a pricing page is current. This is exactly the kind of feature withdrawn quietly, and comparison tables are rarely updated. Check the provider's own status page or changelog rather than a third-party table - including ours.

A forwarded port is a permanent inbound opening. Whatever listens on it is exposed to the internet through the VPN, with the provider's IP in front. Reasonable for a hardened service, a poor idea for something set up in five minutes and forgotten.

If you cannot get one

For torrenting, a client without an open port still works - slower, with less of the swarm reachable. A degradation, not a failure, and acceptable for most people.

For hosting something reachable, the honest answer is that a commercial VPN is the wrong tool. A cheap VPS with its own public IP does the job properly, and the VPN stays for the traffic that should go out through it.

A weathered brick facade with one wooden door still usable and two neighbouring openings bricked up, a blue plate numbered 36 above them
A weathered brick facade with one wooden door still usable and two neighbouring openings bricked up, a blue plate numbered 36 above them
One door still opens; the two beside it have been bricked up. That is roughly what happened to port forwarding across the VPN industry - not broken, deliberately closed.

Editorial pick
4.6 / 5

Secure your connection with NordVPN

Threat Protection blocks trackers & malware · kill switch · 30-day money-back

Deloitte audit 202430-day guarantee14M+ users
See the offer
Everything you need to know.

Frequently asked questions

What is port forwarding on a VPN?

It tells your VPN provider to accept incoming connections on a specific port at its server and pass them through the tunnel to your machine. Normally a VPN only carries connections you start outwards; a forwarded port creates a way in from the internet. It is used mainly for BitTorrent connectability and for reaching a service you host behind the VPN.

Why did Mullvad remove port forwarding?

Mullvad announced the removal on 29 May 2023 and deleted existing forwarded ports on 1 July 2023. The stated cause was abuse: forwarded ports were used to host undesirable content and malicious services from its servers, leading to law enforcement contact, blacklisted IP addresses and hosting providers cancelling service. Because the company does not log traffic, it could not identify or block those responsible, so it closed the feature for everyone.

Do I need port forwarding to torrent?

No, but it changes your results. Without an open port your client only connects to peers that accept incoming connections, so part of the swarm is unreachable and your upload rate suffers. Downloads still work. It is a degradation rather than a blocker, and acceptable for most users.

Is port forwarding through a VPN safe?

It is a permanent inbound opening to whatever listens on that port, presented to the internet behind the provider's IP address. That is reasonable for a service you have hardened and keep updated, and a poor idea for something configured quickly and forgotten. The risk lies in the exposed service, not the tunnel.

What should I use if my provider dropped it?

If the goal is hosting something reachable from outside, a commercial VPN is the wrong tool - a cheap VPS with its own public IP does it properly. If the goal is torrent connectability, accept the reduced performance, or pick a provider that still offers forwarding while understanding what that implies about how it handles abuse.