Universal Plug'n'Play (NAT-PMP and UPnP)

Universal Plug'n'Play (UPnP) is a technology introduced by Microsoft that allows for easy configuration of port forwarding. Nowadays it is used by many network clients which rely on it to get proper access to the Internet. UPnP is also used by some game consoles, such as the Xbox 360 and the Playstation 3.

NAT Port Mapping Protocol (NAT-PMP) is a technology similar to UPnP that originates from Apple. Unlike UPnP, it is currently an IETF standard, and a number of OS X, iOS, Linux and Windows applications support it. NAT-PMP is basically a simple and sane replacement of UPnP for automating the process of creating port mappings in NAT.

Note: AstLinux 1.0.4 or later is required

Note: AstLinux 1.2.3 or later is required for 'Port Control Protocol' NAT-PMP/PCP support.

Either NAT-PMP or UPnP (or both) may be enabled in AstLinux via the Network tab:

Network tab option

By default both NAT-PMP and UPnP are disabled, and that is the suggested setting for most users.

But, since you are reading this, there are situations where dynamically creating port mappings in NAT is necessary. If so, first try enabling NAT-PMP only and see if your network clients or devices support it.

If it turns out enabling NAT-PMP only does not support your clients, then as last resort enable both NAT-PMP & UPnP so your clients can choose which method of Universal Plug'n'Play is desired.

Note that at least one of the Interfaces: needs to be checked for Universal Plug'n'Play to be enabled.

Any changes to the Universal Plug'n'Play options may be applied by selecting Restart Univ. Plug'n'Play and clicking the Reboot/Restart button.

The Status tab will show a Universal Plug'n'Play (NAT-PMP and UPnP) Leases: section if it is active, and display any active leases.

Security considerations

The topic of Universal Plug'n'Play is not complete without discussing security. Neither NAT-PMP nor UPnP provides any authentication mechanisms, so by default any network application within the selected interface's network may dynamically define NAT EXT→LAN firewall rules. Technically, a worm or malware program could use this function to compromise security.

Within AstLinux there are a few power user features to help minimize the security risks.