Port Forwarding
In short: A router configuration that forwards incoming connections on a particular port specifically to a device in the local network.
In more detail: Since a router using NAT normally only shows one public IP address for the entire home/company network to the outside, it has to know to which internal device incoming traffic on a particular port should be passed on — e.g. to make a self-hosted server reachable from the internet.
In Depth
The basic problem port forwarding solves: network address translation (NAT) translates many private IP addresses in the home/company network to the router’s single public IP address. As a result, incoming connections from outside don’t know on their own which internal device they belong to — without port forwarding, an incoming request on a particular port simply goes nowhere.
A port forwarding rule specifies: “incoming traffic on port X (external) goes to the internal device with IP Y on port Z (internal)” — external and internal don’t have to be the same port number. Typical use cases are self-hosted game servers, your own web server at home, or remote access via SSH to a home computer.
UPnP as an automated alternative
Instead of setting up port forwarding manually in the router interface, many routers and applications support “Universal Plug and Play” (UPnP) — a protocol with which an application can automatically request a suitable forwarding from the router itself (e.g. a games console that opens the port it needs for online multiplayer on its own). Handy, but also security-critical: UPnP allows practically any application in the local network to open holes in the firewall without asking, which is why it’s often deactivated in security-conscious environments.
Security aspects
In terms of security, port forwarding isn’t without risk: every open forwarding makes the device behind it directly reachable from the internet and thus potentially attackable — automated scanners continuously search the entire IPv4 address space for open ports and try out known vulnerabilities as soon as they find an open service. Best practice is therefore to open only ports that are really needed, to secure the target device accordingly (up-to-date software, strong credentials) and, where possible, to use a VPN instead, which doesn’t need any permanently open ports to the outside.