

#UPNP OR NAT PMP ON NETGEAR ROUTER SOFTWARE#
Some systems may also have security software present that only allows select applications to communicate with the Internet. In other cases such as Linux iptables we leave this to the user since there are too many variations and we do not want to accidentally corrupt user settings by trying to modify them manually.
#UPNP OR NAT PMP ON NETGEAR ROUTER WINDOWS#
In some cases (such as the Windows built-in firewall) ZeroTier does this automatically if installed with one of our installation packages. If your computer has a local firewall, allow traffic to and from UDP port 9993. Let ZeroTier and UPnP, NAT-PMP, and IPv6 handle it automatically. To talk with them directly, you need to be able send to any port. That means your peers could be listening on any port. A random, high numbered port for use with UPnP/NAT-PMP mappings.A random, high numbered port derived from your ZeroTier address.What ports does ZeroTier use? It listens on three 3 UDP ports: Some switches might allow finer grained control, and on these it would be sufficient to allow local UDP traffic to/from 9993 (or in general). Switches and wireless access points should allow direct local traffic between local devices.Place no more than about 16,000 devices behind each NAT-managed external IP address to ensure that each device can map a sufficient number of ports.NATs should have a port mapping or connection timeout no shorter than 60 seconds.Multiple layers of NAT introduce connection instability due to chaotic interactions between states and behaviors at different levels. No more than one layer of NAT should be present between ZeroTier endpoints and the Internet.Symmetric NAT is extremely hostile to peer to peer traffic and will degrade VoIP, video chat, games, WebRTC, and many other protocols as well as ZeroTier. Use "full cone" or "port restricted cone" NAT. If present it should be implemented without NAT (NAT is wholly unnecessary with IPv6 and only adds complexity) and with a stateful firewall that permits bidirectional UDP conversations. IPv6 is recommended and can greatly improve direct connection reliability if supported on both ends of a direct link.


But "some level of connectivity" does not mean "optimal connectivity." This page details the physical network configuration that we recommend for best results. We provide multiple layers of fallback so that some level of connectivity can be achieved through even the most restrictive or broken physical networks. ZeroTier is designed to work in as many environments as possible.
