This guide explains Bitcoin Core 22 NAT-PMP port mapping in plain English. It focuses on what the subject is, why it matters and what a beginner should remember.
TL;DR
- What it is: Bitcoin Core 22.0 added NAT-PMP port mapping through the optional libnatpmp dependency. When enabled and supported by the local gateway, it can request an inbound mapping for the node’s listening port.
- Why it matters: NAT-PMP can make a Core 22 node reachable with less router configuration, but it is an exposure mechanism rather than a security control. Enable it only under an explicit inbound policy and verify both the intended P2P port and the absence of management-port exposure.
- Current position: Require a second reviewer and explicit rollback or expiry, and pause payments, signing or network-dependent services until post-change evidence is complete.
Bitcoin Core 22 NAT-PMP port mapping in simple English
Bitcoin Core 22 NAT-PMP port mapping: The node asks the default gateway to map the external Bitcoin port to the local listener. Lease creation can expire or change after router restart, address reassignment or network failover.
Simple example
A node operator is checking Bitcoin Core 22 NAT-PMP port mapping. Disable the feature, remove the lease where possible, verify the port closed externally and monitor inbound peer counts, mapping refreshes, address changes and unexpected exposed services.
Key terms in plain English
- Bitcoin Core:
- Widely used software that validates Bitcoin and can provide wallet, network and operator tools.
- RPC:
- A command that software sends to a node to request information or a local action.
- Node:
- A computer running Bitcoin software that checks data and communicates with other peers.
Version boundary
NAT-PMP support arrived in Core 22.0 and depends on a build that includes libnatpmp. Verify the exact binary’s feature set rather than assuming every package was compiled identically.
What mapping does
The node asks the default gateway to map the external Bitcoin port to the local listener. Lease creation can expire or change after router restart, address reassignment or network failover.
Security boundary
A mapping exposes the P2P listener to the upstream network. It does not expose RPC unless other unsafe settings exist, but operators must still bind RPC locally and audit firewall and container publishing rules.
Privacy and policy
Automatic mapping may conflict with a deliberate outbound-only or Tor-only threat model. Decide whether public inbound reachability is intended before enabling any discovery protocol.
How specialists test it
Developers test the proposal with made-up data on an isolated test network. They check normal cases and deliberately invalid cases. Different implementations should reach the same result before anyone relies on the proposal.
Failure modes
Expect unsupported gateways, disabled NAT-PMP, carrier-grade NAT, double NAT, multiple gateways, stale leases, IPv6 differences and routers that report success without useful public reachability.
Rollback and monitoring
Disable the feature, remove the lease where possible, verify the port closed externally and monitor inbound peer counts, mapping refreshes, address changes and unexpected exposed services. Build a revision-pinned evidence pack on an isolated node, wallet or protocol harness. Record source commit, binary hash, network, chain identity, configuration and dependencies.
Frequently asked questions
What is the main point of Bitcoin Core 22 NAT-PMP port mapping?
Bitcoin Core 22 NAT-PMP port mapping: The node asks the default gateway to map the external Bitcoin port to the local listener.
For Bitcoin Core 22 NAT-PMP port mapping, what should a beginner know about version boundary?
NAT-PMP support arrived in Core 22.0 and depends on a build that includes libnatpmp.
For Bitcoin Core 22 NAT-PMP port mapping, what should a beginner know about what mapping does?
The node asks the default gateway to map the external Bitcoin port to the local listener.
For Bitcoin Core 22 NAT-PMP port mapping, what should a beginner know about security boundary?
A mapping exposes the P2P listener to the upstream network. It does not expose RPC unless other unsafe settings exist, but operators must still bind RPC locally and audit firewall and container publishing rules.
Conclusion
NAT-PMP can make a Core 22 node reachable with less router configuration, but it is an exposure mechanism rather than a security control. Enable it only under an explicit inbound policy and verify both the intended P2P port and the absence of management-port exposure.
Primary sources
Check the current specification status and the documentation for the exact implementation you operate before moving production funds or changing a mining node.
Join the ASIC Mining Discussion
Members can read and join the discussion
Log in to read comments from other miners. Create a free account if you would like to ask a question or share your experience.
Membership helps us protect the discussion from spam and keep answers useful.