Skip to main content
All terms

NAT traversal & hole punching

Techniques that let two devices behind separate routers (NAT) connect directly, by coordinating through a helper server and "punching" a path through each firewall.

Why NAT gets in the way

Most computers sit behind network address translation (NAT): a router that shares one public address among many private ones and only lets in packets that answer a connection started from inside. Two machines on different home or office networks therefore cannot simply open a connection to each other: each router drops the other side's first packet.

How hard the problem is depends on the router. RFC 4787 describes how NATs map and filter UDP traffic: when a router reuses the same public port for every destination, a direct path is usually easy to find; when it picks a new port for each destination (often called symmetric NAT), it is much harder.

How hole punching works

NAT traversal is the set of techniques that find a direct path anyway. First, each side learns how it looks from the outside, usually by asking a STUN server. The two sides exchange these candidate addresses through a coordination server, then both send packets towards each other at the same time. Each router sees an outgoing packet first and treats the reply as part of that flow, so a path opens in both directions. RFC 5128 surveys these techniques.

Routers can also be asked directly: UPnP IGD, NAT-PMP and its successor, the Port Control Protocol (RFC 6887), let an application request a port mapping. Some corporate firewalls and carrier-grade NAT defeat every technique. When nothing works, the session falls back to a relay that forwards traffic between the two sides.

How Vexaro Desk connects

A Vexaro Desk session connects directly wherever the network allows, and through an authenticated Vexaro relay when it doesn't. There is nothing to configure: the client finds a path on its own.

The installer adds a Windows Firewall rule so direct and local-network connections can work; a portable copy cannot add one, so its sessions are more likely to be relayed. Direct connections can be switched off in Settings, and the session window shows whether a session is direct or relayed. Direct sessions are end-to-end encrypted. When a network forces a relayed connection, traffic stays encrypted in transit through Vexaro-operated relays.

NAT traversal techniques

NAT traversal techniques
TechniqueWhat it doesLimits
Port mapping (UPnP IGD, NAT-PMP, PCP)3Asks the router to forward a port to the applicationWorks only where the router supports it and the network allows it
STUN4Tells a device the public address and port the outside seesFinds addresses; carries no session traffic
Simultaneous hole punching2Both sides send first, so each router accepts the other's packets as repliesOften defeated by symmetric NAT and strict firewalls
Trying many ports1,2Raises the odds of a match through a symmetric NATA match is still not guaranteed
RelayForwards traffic when no direct path existsWorks whenever both sides can reach it, but adds latency and costs the operator bandwidth

Help direct connections succeed

  1. Install the client rather than running the portable copy, so the Windows Firewall rule is in place.
  2. Allow outbound UDP: Vexaro Desk sessions, direct and relayed, run over UDP.
  3. Use IPv6 where your network has it: without address translation in the way, a direct path is simpler to find.

Frequently asked questions

What is NAT and why does it block direct connections?
NAT lets many private devices share one public address, and the router only admits packets that answer a connection started from inside. A connection attempt from outside is therefore dropped unless something has opened a path first.
What is hole punching?
Both computers learn their public addresses, exchange them through a coordination server and send packets to each other at the same moment. Each router treats the other side's packets as replies to its own, so a direct path opens.
Does hole punching always work?
No. Symmetric NATs, strict firewalls and carrier-grade NAT can defeat it. That is why remote-desktop tools keep a relay as a fallback; Vexaro Desk connects directly wherever the network allows and through its own authenticated relay when it doesn't.
Are relayed Vexaro Desk sessions encrypted?
Yes. Direct sessions are end-to-end encrypted. When a network forces a relayed connection, traffic stays encrypted in transit through Vexaro-operated relays.

See it in Vexaro Desk

Vexaro Desk brings attended and unattended access, NAT traversal, an adaptive codec engine and governance together in one console. It is in early access, and you can create a free account to try it.