Screens Connect normally configures your router automatically. If your router doesn't support automatic port mapping, has UPnP/NAT-PMP disabled, or automatic configuration isn't working, you can configure your router manually instead.
Manual configuration requires you to:
- Make sure your PC keeps the same local IP address.
- Configure your router to forward an incoming port to your PC.
- Tell Screens Connect which public port you configured.
Looking for an easier alternative?
Screens also natively supports Tailscale, which doesn't require port forwarding or manual router configuration.
If your Internet connection uses Carrier-Grade NAT (CGNAT), manual port forwarding may not be possible. In that case, Tailscale is generally the better option.
Before proceeding, make sure a compatible VNC server is installed and properly configured on your PC:
Prepare Your Windows PC for Screens
Using Port Forwarding
Step 1: Give Your PC a Stable Local IP Address
Your router needs to know which computer should receive incoming Screens connections.
Normally, your router automatically assigns your PC a local IP address such as:
192.168.1.25
or:
10.0.0.25
That address may change over time. If it changes, a port forwarding rule pointing to the old address will stop working.
For this reason, your PC needs a stable local IP address.
Recommended: Reserve the Address on Your Router
If your router supports DHCP reservations, reserved IP addresses, or static leases, we recommend using that feature.
A DHCP reservation tells your router to always assign the same local IP address to your PC. This is generally easier and avoids accidentally choosing an address already being used by another device.
The exact procedure varies by router. Check your router manufacturer's or Internet provider's documentation for terms such as:
- DHCP Reservation
- Reserved IP
- Address Reservation
- Static Lease
Some routers, including Xfinity gateways, manage the destination device directly when creating a port forwarding rule and may not require you to manually assign an address in Windows.
If your router handles this automatically, you can continue to Step 2.
Alternatively: Configure a Static Address in Windows
If your router doesn't provide a way to reserve an address, you can configure a static IP address directly in Windows.
Microsoft provides instructions here:
Change TCP/IP Settings in Windows
Under Change TCP/IP Settings, follow Microsoft's instructions to change IP assignment from Automatic (DHCP) to Manual, then configure IPv4.
How Do I Know Which IP Address to Use?
The address must belong to the same local network as your router and must not already be used by another device.
For example, if your PC currently has:
192.168.1.25
an appropriate address might look like:
192.168.1.200
However, don't simply copy this example. Networks use different address ranges, and choosing an address already assigned to another device can cause network problems.
If you're unsure which address to use, we recommend using your router's DHCP reservation feature instead or consulting the documentation for your router or Internet provider.
Step 2: Configure Port Forwarding on Your Router
Next, configure your router to send incoming Screens connections to your PC.
Router interfaces vary considerably, so we recommend using the official instructions from your router manufacturer or Internet provider whenever possible.
Your port forwarding rule needs three important pieces of information:
Destination
Select the PC you're configuring, or enter the stable local IP address from Step 1.
Internal Port
For a standard Screens connection to a Windows PC, use the port configured by your VNC server. This is normally:
5900
If you've deliberately configured Screens to use a Secure Connection (SSH) and have an SSH server running on the PC, the standard SSH port is:
22
Public or External Port
Choose the port that will be accessible from the Internet.
It doesn't need to be the same as the internal port.
For example, you could configure:
Public port: 59107
PC: 192.168.1.200
Internal port: 5900
Protocol: TCP
This tells your router:
When a TCP connection arrives on port 59107, send it to port 5900 on this PC.
Remember the public/external port number you choose. You'll enter it into Screens Connect in Step 3.
Instructions for Popular Routers and Internet Providers
Here are official port forwarding instructions for several common router platforms:
If your router isn't listed, check its manufacturer's support website for Port Forwarding, NAT Forwarding, or Virtual Server instructions.
You can also use PortForward.com as a reference for many older or less common router models.
Xfinity users: Xfinity currently manages port forwarding through the Xfinity app. Follow Xfinity's instructions and select the PC as the destination device. Choose Manual Set-Up when asked which application or service you're configuring.
Using SSH
If you want to use a Secure Connection (SSH), an SSH server must first be configured on the PC:
Your router should then forward the public port you choose to the PC's SSH port rather than its VNC port.
Step 3: Configure Screens Connect
Double-click the Screens Connect icon in the Windows taskbar notification area to open its settings.
![]()
Open the Advanced tab and enable Custom Configuration.
Enter the public port number you configured on your router.
For example, if your rule is:
Public port 59107 → PC port 5900
enter:
59107

Leave the Public IP Address field empty.
Click Refresh to update Screens Connect.
Screens Connect will update the connection information stored with your account and use the manually configured port from now on.
Multiple PCs Require Different Public Ports
A public port can normally be forwarded to only one computer.
If you're configuring multiple PCs, give each one a different public port, even though they can all forward internally to port 5900.
For example:
Office PC
Public port 59107 → 192.168.1.20:5900
Home PC
Public port 59108 → 192.168.1.21:5900
Configure each PC's Screens Connect installation with its corresponding public port.
Test Your Configuration
Port forwarding should be tested from outside the remote PC's local network.
The easiest test is usually:
- Disable Wi-Fi on your iPhone or iPad.
- Make sure you're using cellular data.
- Open Screens.
- Select your Mac from the Screens Connect section.
- Try connecting to the PC.
You can also test from another Wi-Fi network.
If Screens connects successfully, your manual configuration is working.
If It Still Doesn't Work
If the port forwarding rule appears correct but Screens still cannot connect, something else may be preventing incoming connections.
Check for:
- Windows Firewall or other firewall software.
- Antivirus or security software.
- VPN or network filtering software.
- Router firewall or security features.
- Double NAT.
- Carrier-Grade NAT (CGNAT).
- Restrictions imposed by your Internet provider.
Also make sure your VNC server is running and configured to accept incoming connections.
Some Internet providers provide security features that can block incoming traffic even when a port forwarding rule exists.
For example, Xfinity Advanced Security may block traffic to forwarded ports. Refer to Xfinity's documentation if your forwarding rule appears correct but incoming connections are still blocked.
You can find additional troubleshooting information here:
Screens Connect Troubleshooting
If you don't want to troubleshoot incoming port forwarding, Screens' native Tailscale support is generally the easiest alternative: