Top 10 Best Port Forwarder Software of 2026

GITNUXSOFTWARE ADVICE

Telecommunications Connectivity

Top 10 Best Port Forwarder Software of 2026

Top 10 port forwarder software ranked for admins, comparing ngrok, Cloudflare Tunnel, Tailscale Funnel, plus Tunnelmole and Openport.

29 min readUpdated AI-verified · Expert reviewed
How we ranked these tools
01Feature Verification

Core product claims cross-referenced against official documentation, changelogs, and independent technical reviews.

02Multimedia Review Aggregation

Analyzed video reviews and hundreds of written evaluations to capture real-world user experiences with each tool.

03Synthetic User Modeling

AI persona simulations modeled how different user types would experience each tool across common use cases and workflows.

04Human Editorial Review

Final rankings reviewed and approved by our editorial team with authority to override AI-generated scores based on domain expertise.

Read our full methodology →

Score: Features 40% · Ease 30% · Value 30%

Gitnux may earn a commission through links on this page — this does not influence rankings. Editorial policy

Port forwarder software maps inbound traffic to local services over NAT, SSH reverse tunnels, or overlay networking without requiring manual router changes. This ranked list targets admins and technical evaluators who need testable reachability, configuration automation, and governance signals like RBAC and logging, and it orders tools by how reliably each mechanism publishes ports and how repeatably it can be provisioned.

Tunnelmole is the best fit when you need stable inbound TCP and UDP forwarding to private services behind NAT, whereas Openport suits platform teams that want managed TCP port mappings over outbound connections for controlled external access.

Editor’s top 3 picks

Three quick recommendations before you dive into the full comparison below — each one leads on a different dimension.

Editor pick
1

Tunnelmole

Persistent reverse tunnel plus API-managed forwarding rules for stable port-specific ingress.

Built for fits when admins need stable inbound TCP and UDP forwarding to private services behind NAT..

2

Openport

Editor pick

Per-endpoint forwarding rules connect an ingress port to a chosen internal target with admin-managed lifecycle.

Built for fits when platform teams need managed port mappings for controlled external access to internal services..

3

LocalXpose

Editor pick

Local endpoint exposure with stable external ingress built around tunnel lifecycle control for repeatable callbacks.

Built for fits when teams need external test callbacks for local services without router changes..

Comparison Table

1
TunnelmoleBest overall
open source tunneling
9.4/10
Overall
2
remote access
9.0/10
Overall
3
developer utility
8.7/10
Overall
4
8.4/10
Overall
5
developer utility
8.0/10
Overall
6
self-hosting utility
7.7/10
Overall
7
developer utility
7.4/10
Overall
8
7.1/10
Overall
9
6.8/10
Overall
10
Developer
6.4/10
Overall
#1

Tunnelmole

open source tunneling

Open source tunneling software creates public URLs for local servers and forwards incoming requests.

9.4/10
Overall
Features9.3/10
Ease of Use9.6/10
Value9.2/10
Standout feature

Persistent reverse tunnel plus API-managed forwarding rules for stable port-specific ingress.

Tunnelmole focuses on keeping forwarding alive with persistent tunnels and reconnect logic, which matters for workloads that open short-lived connections. Each forwarding rule maps an external port to a destination host and port inside the private network, which fits common port range forwarding needs without manual reverse tunnel plumbing. The API supports lifecycle operations for tunnel and forwarding configuration, which helps teams treat tunnel definitions as deployable artifacts.

A tradeoff is that Tunnelmole requires the internal agent or connection endpoint to be reachable from the tunnel controller side, which can complicate segmented networks with strict egress rules. Tunnelmole fits best when an operator needs deterministic inbound mapping for staging or test services that must be accessible on specific ports with minimal operational overhead.

Pros
  • +API-driven provisioning for tunnel and forwarding rule changes
  • +Persistent tunnel behavior reduces downtime during reconnects
  • +Per-tunnel configuration limits blast radius during port updates
  • +Inbound mapping supports TCP and UDP forwarding rules
Cons
  • –Requires reachable internal agent connectivity through network egress policies
  • –Limited flexibility for protocol-level inspection beyond pass-through forwarding
  • –Fine-grained traffic controls like bandwidth throttling are not exposed as first-class knobs
  • –Port range scaling depends on operator-managed forwarding rule sets
Use scenarios
  • Platform engineering teams

    Expose internal services on fixed ports

    Less manual port juggling

  • DevOps on segmented networks

    Route inbound traffic to private hosts

    NAT traversal without gateway changes

Show 2 more scenarios
  • Security and governance admins

    Centralize tunnel configuration updates

    More consistent change management

    Use authenticated API workflows to change destination bindings with controlled access.

  • QA and test operations

    Provide ephemeral service access

    Faster environment bring-up

    Repoint forwarding destinations as test environments restart on new hosts and ports.

Best for: Fits when admins need stable inbound TCP and UDP forwarding to private services behind NAT.

#2

Openport

remote access

Remote access software forwards TCP ports through outbound connections to reachable internet endpoints.

9.0/10
Overall
Features9.1/10
Ease of Use9.1/10
Value8.8/10
Standout feature

Per-endpoint forwarding rules connect an ingress port to a chosen internal target with admin-managed lifecycle.

Openport’s core workflow maps an exposed port to an internal destination, then keeps that mapping available as a managed reverse tunnel endpoint. The admin surface is built around creating forward rules and tying them to concrete targets, so changes happen at the service mapping layer rather than ad hoc terminal commands. Connection behavior is controlled through forwarding configuration, including which ports are exposed and where traffic is routed.

A key tradeoff is that Openport’s forwarding is tied to its managed ingress and routing model rather than running entirely on a host with direct destination NAT rules. It fits situations like temporary access for CI jobs, partner testing, or incident response where the mapping must be created, rotated, and removed consistently across multiple services.

Pros
  • +Admin-forwarded endpoint provisioning reduces manual tunnel command errors
  • +Ingress listener routing targets specific internal services per mapping
  • +Repeatable configuration supports redeploying the same port mappings
  • +Operational visibility into active forwarding helps incident triage
Cons
  • –Forwarding depends on Openport’s managed ingress model instead of host-level DNAT
  • –Fine-grained network policy controls feel narrower than dedicated network appliances
Use scenarios
  • Platform engineers

    Provision partner test access to services

    Fewer one-off tunnels

  • DevOps on-call

    Restore access during service incidents

    Faster remediation

Show 2 more scenarios
  • Security admins

    Constrain exposure for audit events

    Tighter access control

    Centralizes which ports are exposed and where traffic is routed per forwarding rule.

  • CI and QA teams

    Run integration tests with external reachability

    More reliable test runs

    Provides consistent forwarded ports for test harnesses to reach internal dependencies.

Best for: Fits when platform teams need managed port mappings for controlled external access to internal services.

#3

LocalXpose

developer utility

Tunneling software exposes local HTTP, HTTPS, TCP, and UDP ports with public endpoints.

8.7/10
Overall
Features8.8/10
Ease of Use8.5/10
Value8.7/10
Standout feature

Local endpoint exposure with stable external ingress built around tunnel lifecycle control for repeatable callbacks.

LocalXpose is designed for exposing a local listener to external clients through a persistent reverse tunnel that terminates at LocalXpose infrastructure. It supports common developer workflows where a local HTTP service or custom TCP service needs external callbacks for testing, demos, and integration validation. Administrators typically gain operational control by using consistent endpoint naming and repeatable tunnel configuration per app.

A key tradeoff is that LocalXpose depends on the tunnel broker in the middle, so it cannot replace direct port mapping in environments that require strict source IP preservation. LocalXpose fits situations where router access is unavailable, like locked-down home networks or corporate Wi-Fi, and where a repeatable external test endpoint is needed during development and QA.

Pros
  • +Persistent reverse tunnel simplifies repeated local-to-public testing
  • +Configurable endpoint exposure reduces manual port forwarding steps
  • +Works without UPnP IGD access on client networks
  • +Command-driven setup fits developer and CI handoffs
Cons
  • –Inbound source IP visibility is limited versus direct destination NAT
  • –Governance controls are weaker than full reverse-proxy appliance RBAC
Use scenarios
  • QA engineering teams

    External callbacks against local test servers

    Fewer broken test handoffs

  • Developer teams

    Share a local demo endpoint

    Faster stakeholder reviews

Show 1 more scenario
  • Security operations

    Temporary external access for audits

    Reduced exposure surface

    Creates bounded external ingress to a local system while keeping the network perimeter closed.

Best for: Fits when teams need external test callbacks for local services without router changes.

#4

Tailscale Funnel

networking

Funnel publishes a local service to the public internet over a Tailscale-managed network path.

8.4/10
Overall
Features8.0/10
Ease of Use8.7/10
Value8.6/10
Standout feature

Funnel turns a Tailscale-connected service into a managed public HTTPS ingress without configuring router DNAT rules.

Tailscale Funnel provides a reverse-tunnel ingress path from a Tailscale network to the public internet. It maps an HTTPS front end to internal services reachable over Tailscale, so administrators can expose TCP-based applications without running a separate port-forwarding host.

The product focuses on Tailscale control-plane configuration, including ACL-driven access to underlying nodes and services. It fits teams already using Tailscale for NAT traversal and can add public reachability without managing external DNAT rules.

Pros
  • +Uses Tailscale identity and ACLs to gate what gets exposed
  • +Centralizes ingress configuration through Tailscale’s control plane
  • +Supports multiple exposed services by defining separate Funnel endpoints
  • +Reduces home-gateway dependency by avoiding UPnP IGD forwarding
Cons
  • –Ingress is tied to Tailscale connectivity and its administrative model
  • –Public routing behavior depends on Funnel’s managed ingress listeners

Best for: Fits when teams need public access to internal services while keeping Tailscale as the access and routing plane.

#5

localhost.run

developer utility

SSH tunneling exposes local ports through temporary public endpoints without local agent setup.

8.0/10
Overall
Features8.0/10
Ease of Use8.0/10
Value8.1/10
Standout feature

Persistent authenticated reverse tunnels that keep localhost-facing services reachable across sessions without rebuilding forwarding rules.

localhost.run acts as a local port forwarder that routes inbound traffic to services running on private loopback hosts. It provides a persistent, authenticated reverse tunnel model that supports TCP forwarding for app testing and remote access workflows.

Configuration focuses on mapping specific local ports to externally reachable listeners with repeatable tunnel settings. Session behavior is governed by the tunnel’s lifecycle and connection handling rather than per-request port rules.

Pros
  • +Persistent reverse tunnel reduces frequent re-tunnel setup
  • +Simple port-to-ingress mapping for TCP-based services
  • +Works well for exposing dev servers to testers remotely
  • +Authentication and tunnel lifecycle help prevent unmanaged exposure
Cons
  • –Operational visibility for active connections is limited
  • –UDP forwarding and advanced protocol inspection are not the focus
  • –Requires tunnel configuration discipline to avoid port drift
  • –IPv6 reachability depends on environment-specific network behavior

Best for: Fits when teams need controlled reverse-tunnel exposure of local TCP services for testing and demos.

#6

PageKite

self-hosting utility

Reverse proxy tunneling publishes local servers behind NAT using persistent public frontends.

7.7/10
Overall
Features7.9/10
Ease of Use7.6/10
Value7.6/10
Standout feature

Kite identity-based forwarding maps local services to stable public endpoints through a persistent client configuration.

PageKite is a port-forwarding and reverse-tunnel tool that publishes local services to the public internet using a hosted rendezvous service. It supports both TCP and HTTP-oriented use cases and uses a persistent kite client configuration to maintain inbound reachability through NAT traversal and relaying.

PageKite focuses on application-level forwarding by mapping local ports to public endpoints rather than building a full network mesh. Admin control centers on managing kite identities and configuration on the forwarding host, with less emphasis on centralized policy controls.

Pros
  • +Persistent kite configuration keeps inbound mappings stable across reconnects
  • +Supports local-to-public forwarding for TCP services and web-style workloads
  • +Uses a relay-based path when direct traversal fails
  • +Simple command and config workflow for publishing specific local ports
Cons
  • –Operational governance requires per-host config and identity management
  • –Throughput and concurrency controls are limited compared with enterprise tunnel tools
  • –Less support for fine-grained per-route access control patterns
  • –NAT traversal behavior depends on network conditions and relay availability

Best for: Fits when a small team needs repeatable inbound access to specific local services without a full mesh.

#7

Serveo

developer utility

SSH reverse tunnels forward local ports to public internet addresses without client installation.

7.4/10
Overall
Features7.4/10
Ease of Use7.5/10
Value7.3/10
Standout feature

Public endpoints are generated directly from SSH local or remote forwarding commands without requiring a web-based tunnel configuration object.

Serveo is a port-forwarding and reverse-tunneling service built around SSH, with public endpoints created from short SSH commands. It supports forwarding both HTTP and arbitrary TCP services to an internal host using SSH local forward or remote forward patterns.

The workflow is command-driven rather than configuration-panel-driven, which speeds up ad hoc NAT traversal for developers. Session persistence depends on keeping the SSH tunnel alive, since it does not present a persistent tunnel manager with per-route automation controls.

Pros
  • +SSH-first setup reduces tooling overhead for quick port mapping
  • +Arbitrary TCP forwarding supports non-HTTP services and custom protocols
  • +Works well for temporary reverse tunnels in dev and debugging sessions
  • +Command-based workflow is easy to copy into scripts or CI steps
Cons
  • –No native RBAC or multi-tenant governance for admin role separation
  • –Tunnel lifecycle control is minimal beyond keeping the SSH session running
  • –Limited visibility into per-route metrics and connection-level auditing
  • –Production change management is harder without structured provisioning

Best for: Fits when teams need fast, SSH-driven reverse tunnels for short-lived access to internal services.

#8

PFConfig

SMB

Software that automates router port forwarding configuration.

7.1/10
Overall
Features7.0/10
Ease of Use6.9/10
Value7.3/10
Standout feature

Model-specific port forward configuration guidance that highlights TCP versus UDP and port range details during setup.

PFConfig from portforward.com focuses on generating and validating port forward configurations for routers and gateways, with workflows centered on destination port ranges and protocol selection. It targets faster setup by producing device-specific guidance for common router models and by highlighting conflicts that block expected inbound traffic.

The tool supports a repeatable configuration approach for services that need TCP/UDP exposure from the LAN side to an external ingress point. It is best evaluated as a configuration generator and troubleshooting assistant rather than a runtime tunnel client.

Pros
  • +Router model guidance reduces guesswork for WAN to LAN port mapping
  • +Configuration outputs emphasize correct TCP versus UDP selection
  • +Troubleshooting cues help identify common inbound traffic blockers
  • +Repeatable wizard flow supports consistent port range forwarding
Cons
  • –Best results depend on having the correct router model and LAN IP details
  • –No built-in reverse tunnel or NAT traversal for environments that block inbound
  • –Limited coverage for advanced firewall pinhole scenarios beyond typical forwarding
  • –No API surface for automation against infrastructure-as-code workflows

Best for: Fits when admins need consistent destination port forwarding setup across known router models.

#9

Simple Port Forwarding

SMB

A desktop application for managing router port forwarding rules.

6.8/10
Overall
Features6.6/10
Ease of Use6.7/10
Value7.0/10
Standout feature

Rule-based external-to-internal port mapping with a focused web UI for managing destination NAT-style forwarding without reverse-proxy functions.

Simple Port Forwarding creates external port mappings for internal services by using a small managed forwarding setup and a web-based configuration flow. The product supports both TCP and UDP forwarding and lets administrators manage rules by mapping an internet-facing port to a specific local host and port.

Session handling is designed around maintaining reachability for the forwarded endpoint rather than tunneling full network routes. The interface focuses on rule configuration and change tracking for port mapping operations without adding application-level reverse proxy features.

Pros
  • +Web UI simplifies port mapping rule creation and review
  • +Supports both TCP and UDP forward mappings
  • +Clear mapping from external port to internal host and port
  • +Good fit for single-service forwarding without reverse-proxy overhead
Cons
  • –Limited protocol controls beyond basic TCP and UDP forwarding
  • –No native per-rule authentication or RBAC for access governance
  • –Automation and API surface are minimal for bulk provisioning
  • –Hairpin NAT and complex internal routing cases need extra network design

Best for: Fits when administrators need straightforward TCP and UDP port forwarding for a small set of internal services.

#10

Portmapper

Developer

A CLI tool for managing UPnP port mappings.

6.4/10
Overall
Features6.4/10
Ease of Use6.3/10
Value6.6/10
Standout feature

Portmapper’s local listener port mappings let existing clients connect to stable endpoints while traffic is carried over SSH.

Portmapper turns a Kubernetes service exposure problem into a filesystem of predictable TCP listeners by creating local port mappings that forward traffic over an SSH transport. The workflow is designed for environments where SSH access is already available and where ingress needs to be limited to a specific host or network path.

Portmapper focuses on port forwarding semantics rather than public tunnel URLs, so routing decisions stay close to the chosen listener and forwarding target. Administrators get a small configuration surface and a process model that fits automation around starting and stopping forwarders.

Pros
  • +SSH-based forwarding avoids extra tunnel infrastructure and keeps control close
  • +Uses plain port listener mappings that integrate with standard local client tooling
  • +Simple configuration supports scripting start and stop workflows
  • +Clear failure mode when the SSH transport drops
Cons
  • –No built-in ingress policy layer like per-request authentication or RBAC
  • –Forwarding is bound to SSH reachability and cannot bypass blocked paths
  • –Limited visibility into connection routing beyond process logs
  • –UDP forwarding support is not the focus of the typical port mapping workflow

Best for: Fits when Kubernetes apps need controlled host-to-host reachability using SSH-only transport.

Conclusion

After evaluating 10 telecommunications connectivity, Tunnelmole stands out as our overall top pick — it scored highest across our combined criteria of features, ease of use, and value, which is why it sits at #1 in the rankings above.

Our Top Pick
Tunnelmole

Use the comparison table and detailed reviews above to validate the fit against your own requirements before committing to a tool.

How to Choose the Right port forwarder software

This buyer's guide covers port forwarder software across Tunnelmole, Openport, LocalXpose, Tailscale Funnel, localhost.run, PageKite, Serveo, PFConfig, Simple Port Forwarding, and Portmapper.

Each tool is evaluated for how it handles stable inbound mapping, whether it provisions forwarding rules through an API or a managed control plane, and how admins keep access and routing behavior governed across reconnects.

Tunnelmole is positioned for admins who want persistent reverse tunneling with API-managed forwarding rules. Tailscale Funnel is covered for admins who want public HTTPS ingress based on Tailscale identity and ACLs.

Port forwarder software that maps external ports to private services through tunneling and ingress listeners

Port forwarder software routes inbound traffic from a public or reachable endpoint to a private service by running a reverse tunnel, setting up an SSH forwarding path, or standing up a managed ingress listener that forwards to internal targets.

Admin focus usually centers on forwarding-rule lifecycle control, including whether updates are pushed through an API and whether ingress behavior stays stable across reconnects.

Tunnelmole fits scenarios where persistent reverse tunnel behavior reduces downtime during reconnects and API-driven provisioning manages tunnel and port-specific ingress forwarding. Openport fits scenarios where admin-managed endpoint provisioning ties an ingress listener to a chosen internal target through per-endpoint forwarding rules that are created and managed outside host-level DNAT.

Forwarding rule lifecycle, ingress listener control, and automation surface

A port forwarder lives or dies by how reliably it maps external ports to internal targets across reconnects. Tools that keep a persistent reverse tunnel or persistent forwarding state reduce the operational churn that forces frequent manual re-tunneling.

  • API-managed forwarding rules and persistent tunnel behavior

    Tunnelmole uses an API to manage tunnel and port-specific forwarding rule changes while keeping persistent reverse tunnel behavior to reduce downtime during reconnects. localhost.run also uses persistent authenticated reverse tunnels that keep localhost-facing services reachable across sessions, but it focuses on simpler TCP mapping.

  • Per-endpoint admin provisioning and target routing

    Openport provisions an ingress listener per endpoint and routes each ingress port to a chosen internal target through admin-managed lifecycle. Openport’s control model emphasizes explicit endpoint-to-target mappings instead of host-level destination NAT.

  • Tailscale identity and ACL-gated HTTPS ingress listeners

    Tailscale Funnel turns a Tailscale-connected service into managed public HTTPS ingress and gates exposure through Tailscale identity and ACLs. This ties the public routing behavior to Tailscale connectivity and Funnel’s managed ingress listeners.

  • Local callback exposure with lifecycle-controlled persistent tunnels

    LocalXpose builds local endpoint exposure around tunnel lifecycle control for repeatable external test callbacks without router changes. It keeps a persistent reverse tunnel for repeated local-to-public testing, but inbound source IP visibility is limited versus direct destination NAT.

  • SSH-driven reverse tunnel generation without a centralized tunnel object

    Serveo generates public endpoints directly from SSH local or remote forwarding commands, which removes the need for a separate web-based tunnel configuration object. Serveo supports arbitrary TCP forwarding for non-HTTP services, while tunnel lifecycle control depends on keeping the SSH session running.

  • Focused local port forwarding mapping carried over SSH transport

    Portmapper uses local listener port mappings so existing clients connect to stable endpoints while traffic is carried over SSH. This model keeps control close to the client host, but it lacks a built-in ingress policy layer with per-request authentication or RBAC.

Select by the control plane model, ingress binding model, and governance needs

Port forwarder tools split into two practical philosophies for admin control. One philosophy keeps a persistent tunnel and pushes forwarding rule state through an API or managed control plane. The other philosophy derives forwarding from SSH sessions or local listener mappings and limits governance to what can be enforced at the transport and admin host layer.

  • Pick the rule lifecycle model that matches reconnect tolerance

    Choose Tunnelmole or localhost.run when reconnect stability is measured by reduced forwarding disruption and persistent tunnel behavior. Tunnelmole adds API-driven provisioning for tunnel and forwarding rule changes, while localhost.run focuses on persistent authenticated reverse tunnels with simpler TCP-based mapping.

  • Choose how public routing is governed for multi-service exposure

    Choose Openport when each exposed endpoint needs an explicit ingress listener mapped to a specific internal target with admin-managed lifecycle. Choose Tailscale Funnel when exposure must follow Tailscale identity and ACLs so public HTTPS ingress depends on the Tailscale control plane.

  • Decide between managed ingress listeners and SSH-session derived endpoints

    Choose Serveo when the workflow starts from SSH local or SSH remote forwarding commands and the public endpoint is generated from those commands. Choose Portmapper when the workflow centers on local listener mappings that use SSH transport to carry traffic without adding an ingress policy layer.

  • Validate observability expectations for connection-level debugging

    Choose Tunnelmole or Openport when operational debugging must include visibility into forwarding rules managed outside an ad hoc SSH session. LocalXpose and localhost.run both state limits around inbound source IP visibility or operational visibility for active connections, which can constrain incident response.

  • Confirm governance fit for who can change what gets exposed

    Choose Tailscale Funnel when access control should be enforced through Tailscale identity and ACLs. Choose Openport or Tunnelmole when the admin role model must include provisioning and lifecycle actions for endpoints and forwarding rules through the product control surface.

Who should use each port forwarder software type

Port forwarder software fits teams that need controlled inbound access to private services without changing router configuration. The deciding factor is whether the team wants a managed control plane for ingress listeners and forwarding rules or a transport-derived approach built around SSH and local listeners.

  • Platform admins running private services behind NAT who require stable inbound mapping

    Tunnelmole targets admins who want persistent reverse tunnel behavior plus API-managed forwarding rules for stable port-specific ingress. Openport targets admins who want per-endpoint provisioning that routes each ingress listener to the chosen internal target.

  • Teams standardizing access control through Tailscale identity and ACLs

    Tailscale Funnel is built to gate exposure through Tailscale identity and ACLs while providing managed public HTTPS ingress for Tailscale-connected services.

  • Operators who need SSH-first setup for short-lived access and custom TCP forwarding

    Serveo generates public endpoints directly from SSH forwarding commands and supports arbitrary TCP forwarding for custom protocols beyond HTTP. Portmapper supports controlled host-to-host reachability using SSH-only transport through local listener mappings.

  • QA and developers who need repeatable external callbacks for local services

    LocalXpose focuses on repeatable local-to-public testing through persistent reverse tunnel behavior and configurable endpoint exposure without router changes.

Common mistakes when selecting and operating a port forwarder

Many failures come from treating port forwarding as a one-time command instead of an ongoing control plane. The reconnect path, ingress listener model, and governance surface determine whether exposed ports remain correct and safe over time.

  • Choosing an SSH-session derived tool and then expecting persistent forwarding state across reconnects

    Serveo depends on keeping the SSH session running for tunnel lifecycle control, which limits stable reconnect behavior. Tunnelmole and localhost.run emphasize persistent reverse tunnel behavior to reduce manual re-tunnel churn.

  • Assuming public access control exists at the per-rule or per-request layer without identity integration

    Portmapper lacks a built-in ingress policy layer like per-request authentication or RBAC. Tailscale Funnel ties exposure control to Tailscale identity and ACLs, while Openport and Tunnelmole center governance around forwarding rule provisioning.

  • Building workflows around direct client source IP visibility and expecting it to match destination NAT behavior

    LocalXpose limits inbound source IP visibility compared with direct destination NAT behavior. Tunnelmole and Openport emphasize stable ingress listener routing, but source IP semantics still depend on the forwarding path they use.

  • Misaligning the ingress binding model with the intended service type and protocol scope

    Funnel focuses on public HTTPS ingress for Tailscale-connected services, which may not fit non-HTTP TCP services. Serveo and PageKite are better aligned to arbitrary TCP and web-style workloads, respectively, based on their described forwarding scope.

How We Selected and Ranked These Tools

We evaluated Tunnelmole, Openport, LocalXpose, Tailscale Funnel, localhost.run, PageKite, Serveo, PFConfig, Simple Port Forwarding, and Portmapper using feature coverage for stable inbound mapping, including persistent tunnel behavior and forwarding rule provisioning. Features accounted for 40% of the score, with emphasis on whether forwarding rules and ingress listeners are managed through an API or a control plane.

Ease of use and value each accounted for 30%, focusing on whether admins can provision mappings without SSH session churn or repetitive manual tunnel commands. Tunnelmole ranked first because API-driven provisioning manages tunnel and forwarding rule changes while persistent reverse tunnel behavior reduces reconnect-related downtime for stable TCP and UDP ingress.

Frequently Asked Questions About port forwarder software

How does Tunnelmole’s persistent reverse tunnel differ from Serveo’s SSH command-created endpoints for inbound access?
Tunnelmole keeps named tunnels alive with per-tunnel forwarding rules, so ingress listeners remain available after port or destination rotation. Serveo generates public endpoints from SSH local or remote forward commands, and reachability depends on keeping the SSH session running.
Which tool should handle inbound TCP and UDP forwarding to private services behind NAT without per-request tunnel rebuilds?
Tunnelmole is designed for stable inbound TCP and UDP forwarding through a reverse tunnel that maintains an ingress listener for internal endpoints. localhost.run also keeps a persistent authenticated reverse tunnel, but it focuses on controlled exposure of local TCP services for testing and demos.
When does Cloudflare Tunnel outperform Tailscale Funnel for exposing internal services to the public internet?
Tailscale Funnel is strongest when Tailscale already provides the routing and access control plane, since Funnel maps an HTTPS front end to services reachable over Tailscale. Tunnel-based products that are not tied to a mesh control plane typically fit better when public exposure must bypass mesh membership requirements, which is the main design distinction between Tailscale Funnel and Tunnel-first approaches.
What breaks if Openport needs per-pod routing for Kubernetes services instead of managing a fixed set of forwarded endpoints?
Openport is built around provisioning and managing ingress port mappings to specific internal targets, so it aligns with stable endpoint lists rather than Kubernetes-native service discovery. Portmapper targets Kubernetes exposure by creating local port mappings that forward over SSH transport, which keeps forwarding semantics close to the listener and fits automation around starting and stopping forwarders.
How do admins automate forwarding rule changes with Tunnelmole compared to Simple Port Forwarding’s web UI workflow?
Tunnelmole provides an API-driven workflow for programmatic updates to forwarding rules under named tunnels, which supports pipeline-based provisioning. Simple Port Forwarding centers on web-based rule configuration and change tracking, so automation typically depends on exporting and reapplying configuration rather than direct API rule mutation.
What security and access-control model do Tailscale Funnel and Tunnelmole use for limiting who can reach forwarded services?
Tailscale Funnel ties access to Tailscale control-plane configuration and ACL-driven authorization for nodes and services. Tunnelmole’s security focus is on maintaining stable ingress through reverse tunnels and administering tunnels and forwarding rules as discrete configuration objects that can be rotated without broad change to the forwarding graph.
Where does Serveo fall short when long-lived, always-on forwarding is required for multiple stable routes?
Serveo relies on keeping the SSH tunnel alive, and it does not present a persistent tunnel manager with per-route automation controls. Tunnelmole and localhost.run instead maintain persistent tunnel lifecycles, which reduces operational coupling between tunnel uptime and forwarding rule availability.
How does PFConfig help prevent misconfigured port range forwarding compared with using Simple Port Forwarding rules directly?
PFConfig generates and validates router and gateway port forward configurations by highlighting conflicts and protocol selection issues, which targets destination port range correctness before traffic arrives. Simple Port Forwarding focuses on mapping internet-facing ports to chosen local hosts and ports through a web UI, so it does not replace device-model conflict detection.
Which tool is a better fit for developers who need HTTPS callbacks for TCP apps running on a workstation without router-level port mapping?
LocalXpose is designed to route a developer workstation service into a stable external endpoint using managed reverse tunnels, so router changes are not a requirement. PageKite also publishes local services outward, but it emphasizes hosted rendezvous and kite identities rather than workstation-targeted exposure with CI handoffs.

Tools reviewed

Primary sources checked during evaluation.

Referenced in the comparison table and product reviews above.

Logos provided by Logo.dev

Keep exploring

FOR SOFTWARE VENDORS

Not on this list? Let’s fix that.

Our best-of pages are how many teams discover and compare tools in this space. If you think your product belongs in this lineup, we’d like to hear from you—we’ll walk you through fit and what an editorial entry looks like.

Apply for a Listing

WHAT THIS INCLUDES

  • Where buyers compare

    Readers come to these pages to shortlist software—your product shows up in that moment, not in a random sidebar.

  • Editorial write-up

    We describe your product in our own words and check the facts before anything goes live.

  • On-page brand presence

    You appear in the roundup the same way as other tools we cover: name, positioning, and a clear next step for readers who want to learn more.

  • Kept up to date

    We refresh lists on a regular rhythm so the category page stays useful as products and pricing change.