I wrote this some time back but not realize it may not be accessible to everyone so I’ll bring it forward
I don’t have UPnP turned on in my router so I have to configure the port forwarding manually. I use the Ubiquiti EdgeRouter and here are the notes from my configuration.
rule 100 {
description "Roon mobile port forward"
destination {
address 203.0.113.1
port 55000
}
inbound-interface eth1
inside-address {
address 192.0.2.1
port 55000
}
protocol tcp
type destination
}
I also use a Zone Based Firewall configuration which I’ll share here as well. Do note, this is not a full zbf config. This is just the part I added to make Roon work. I’m assuming you already have a working firewall from inside out and these rules will open holes for outside to come in.
zoon-policy
zone ROON {
default-action reject
from INTERNET {
firewall {
name roonForward
}
}
interface eth2
}
I have a UDM at one location. If the UDM Pro software is similar, you can either enable UPnP on the Internet page for your network (if you are comfortable with that), or create a NAT port forwarding rule on the Firewall & Security page (which I’ve done). However, that won’t be enough if your UDM Pro gets internet from a standard Xfiniti endpoint, because the Xfiniti endpoint will by default also do NAT, that is, you have the curse of “double NAT.” Unfortunately, the UDM (and the UDM Pro?) does not support bridge mode, so you really need to configure both the UDM and the Xfiniti internet endpoint with port forwarding rules (which is what I had to do, not with Xfiniti but a different ISP).