Open, moderate or strict: that is the screen telling you, before you even load a match, whether you are about to join your friends or stare at a connection error. A strict NAT is almost always fixed from the router, in under a quarter of an hour and without buying anything. Here is the method, in order, and the one case where it will not be enough.
What is a console's NAT type?
NAT, or network address translation, lets every device in your home share a single public IP address. Console, computer, phone: each one holds its own private address at home, invisible from outside, and your router is what sorts the incoming traffic.
The NAT type measures how permissive that sorting is toward connections that arrive unrequested, exactly what an online game needs so another player can connect straight to you. Three tiers exist, from the most permissive to the most closed: open, moderate, strict.
PS5, Xbox and Switch: the same scale, three vocabularies
Every manufacturer picked its own name for the same three-tier scale, which explains most of the confusion.
| Console | Label shown | Against an open NAT | Against a moderate NAT |
|---|---|---|---|
| Xbox (Series, One) | Open / Moderate / Strict | Connects to everyone | Connects to most, sometimes more slowly |
| PlayStation (PS5, PS4) | Type 1 / Type 2 / Type 3 | Connects to everyone | Connects to most games |
| Nintendo Switch | Open / Moderate / Strict | Connects to everyone | Shut out of some network-demanding games |
The compatibility rule stays the same across all three ecosystems. A player with an open NAT connects to everyone, no exception. A player with a moderate NAT joins open and moderate sessions, but not always strict ones. A player with a strict NAT only connects reliably to an open host, and a multiplayer session can drop them the moment a moderate player joins mid-way. It is this mechanism, documented on Nintendo's own support pages, that explains why two friends never manage to meet even though each of their lines works perfectly on its own.
Why is your NAT strict when the line itself is fine?
A strict NAT is almost never about speed, your provider, or the plan you pay for. Four causes cover nearly every case: a router that refuses unsolicited inbound connections by default, for security; UPnP switched off, the protocol that lets a console request its own port opening; a double NAT, when your own router sits behind the provider's box and creates two chained address translations the console cannot cross; and CGNAT, the hardest to fix, where it is the provider, not your router, sharing a single public IPv4 address between several households.
In that last case, no setting at home can open a port. The public address is not yours alone to begin with.
How do you check your NAT type before starting?
Every console shows it in its own network menu, under a connection test. Write the result down now: it is the only way to know, ten minutes from now, whether anything you changed actually worked.
How do you open your NAT, step by step?
The method always runs in the same order. Skip a step and the next one is liable to fail for no obvious reason.
- Reserve the console's local IP address in the router. Without this reservation, a port forward will one day point at a device that no longer exists. The option sits in the router's DHCP menu, under a name close to "address reservation" or "static lease".
- Turn on UPnP on the router or the box. The simplest fix: the console requests the ports it needs on its own. On most Belgian boxes, the option sits in the advanced home network settings.
- If UPnP is not enough, forward the ports manually. Every manufacturer publishes the exact port list, and it sometimes changes with a firmware update. Check it on Sony's, Microsoft's or Nintendo's own support page, never on a number picked at random off a forum.
- Rule out a double NAT. Is a personal router sitting behind the provider's box? Put the box into bridge mode where the option exists, or place the personal router's address in the box's DMZ.
- Retest the NAT type from the console. Compare it to the result you wrote down earlier. If nothing changed, go back to step 3 before assuming a deeper problem.
- As a last resort, suspect CGNAT and switch to IPv6. A growing number of games and consoles use IPv6, which gives every device a genuinely public address and gets around the problem without any port forwarding at all.
| Step | Time | Equipment | Cost |
|---|---|---|---|
| 1. Local IP reservation | 5 minutes | Access to the router's interface | 0 € |
| 2. Turning on UPnP | 2 minutes | None | 0 € |
| 3. Manual port forwarding | 10 to 15 minutes | The manufacturer's official port list | 0 € |
| 4. Checking for a double NAT | 15 to 30 minutes | Access to the box and the personal router | 0 € |
| 5. New test from the console | 2 minutes | None | 0 € |
| 6. Switching to IPv6 (if CGNAT) | 5 minutes, or no fix | An IPv6-capable box | 0 € |

Is it safe to leave UPnP switched on?
Yes, for the vast majority of households, with one thing worth knowing: UPnP lets any device on your local network request a port opening, with no password and no approval from you. On an ordinary home network, that is not a practical problem. It becomes one if a device on the network is already compromised by malware. The right move is not to switch UPnP off on principle, but to keep the router's firmware up to date.
Watch for these in the fine print: a handful of mistakes keep coming back and explain a NAT that stays strict after hours of tweaking.
- Forgetting the IP address reservation, which makes any manual port forward temporary.
- Confusing the NAT test with the speed test, two menus that sit close together on some consoles.
- Forwarding a port to the old address of a console that has since been replaced.
- Leaving a DMZ permanently active on a device that no longer needs it.
- Only retesting once every change has been made, which makes it impossible to tell which one actually worked.
The Belgian catch: double NAT and shared connections
I checked the procedure on my own line, a fibre Internet Box with a personal router set up behind it for Wi-Fi. The double NAT was indeed there. Switching to bridge mode was enough.
Proximus, for its part, officially documents port forwarding on its b-box and Internet Box, proof that the feature is built in rather than merely tolerated. At Telenet, Orange and VOO, the option exists too, under a name and a location that vary from one modem to the next.
CGNAT, on the other hand, stays rare on Belgian fixed lines as recorded on 26 September 2026, whether fibre, cable or VDSL: each subscription generally gets its own public IPv4 address. It is far more common on mobile access, such as a fixed 5G plan, where the provider deliberately shares addresses between many SIM cards.
Nothing will fix that.
For speed and latency in gaming, our article on fibre and gaming and our glossary of ping, jitter and packet loss round out this guide. To choose the line itself, our ranking of the best fibre internet plans in Belgium is the place to start, and our fibre plan comparison tool narrows it down from there, by address.
Débit & technologie comparator
Compare all débit & technologie side by side.
Compare now →
Frequently asked questions
Nicolas suit le marché belge des télécoms et le déploiement de la fibre depuis plus de huit ans. Ancien technicien réseau devenu analyste indépendant, il teste lui-même les connexions qu'il compare : il mesure les débits réels à différentes heures de la journée, lit les conditions ligne par ligne et traque les hausses de prix qui tombent après douze mois. Son objectif : aider les ménages belges à choisir une offre fibre qui tient ses promesses, au bon débit et au juste prix, sans jargon ni argument commercial.
