Pinholes let you pass specific types of network traffic through the Netopia's NAT interfaces. Once configured, selected types of network traffic, such as FTP requests or HTTP (Web) connections, will be forwarded to a specific host or server behind your gateway device.
PLEASE NOTE: From the LAN (Local Area Network), you will also be able to access these servers, but only using the internal private IP address. Access via the public IP address is not supported from a local ethernet connection.
CAUTION: If you are configuring a pinhole for HTTP port 80 (a web server) on your network, or if you need to forward telnet to a local server, you must change the Default Internal Server in the Netopia router. Click Here for 6.3.0 and later instructions.
This technote will guide you through the setup process for Pinholes in your Netopia.
Please Note: If your router is currently running Netopia Enterprise Firmware version 8.0.10 and later, this technote is not applicable to you.
Please Note: The 3341/3346 does not support IP Maps in firmware version 6.3.0 R9. Also, the Netopia 3341/3346 does not support VPN Passthrough until Firmware version 7.2. Please refer to CQG_027: Software Hosting for configuration of this feature.
Related documents: Address Forwarding | Software Hosting
Firmware Reference
- v7.2 and later -- Netopia 3300 Series
- v6.3 and later -- Netopia 3500 Series
Browse into the Netopia's web interface at http://192.168.1.254 (if using the default IP setting). If your network has a different IP addressing scheme, modify this accordingly.
Login with the user name admin and your password. Admin login is required to save changes. If you are unsure of this, contact your network administrator.
Once logged in, click on the Expert Mode link in the left-hand side menu (if that link is visible). In the Expert Mode Confirmation screen click on Ok to continue. This menu bar will be visible at the top of your screen if you are in Expert Mode.
Remember to click the Submit button to save any entries. Hitting the back button without clicking Submit will undo any changes.
Once you have completed your configuration, click on the
symbol in your upper right hand corner to validate the changes. Then click on Save and Restart.

The Netopia Web GUI Home Page in Expert Mode (Firmware v6.3 and later)
- Click on Configure in the upper Menu bar.
- Click on Advanced.
- Under the NAT heading in the Network Configuration box,
click on the Pinhole selection. - Click on the Add button.
- In the Pinhole Entry box, enter the parameters for your pinhole.
For example, to add a mail server:
- In the Pinhole Entries table, in the first line, type the name you would like associated with the pinhole. For this example you might call it SMTP for a mail server.
PLEASE NOTE: Each pinhole you configure must have a unique name associated with it. If you should duplicate the pinhole name in a subsequent entry, it will overwrite the first entry. - Protocol Select is TCP by default. Different protocols can be selected from the drop-down menu when appropriate.
- External Port Start is 25 for this example.
- External Port End is also 25 for this example.
- Enter the Internal IP Address of your mail server.
- The Internal Port is 25.
- Click on Submit to save the changes.
- Click on the Add More Pinholes link. This takes you back to the Pinholes "menu" screen.
- In the Pinhole Entries table, in the first line, type the name you would like associated with the pinhole. For this example you might call it SMTP for a mail server.
- Again, click on Add in the Pinholes box
and repeat the previous steps to add,
if needed, POP3, and substitute port 110 in the 3 corresponding fields.
Configure a PPTP VPN Pass Through
If you have a PPTP VPN client, such as Microsoft Dial-Up Networking, on a remote computer, and you wish to tunnel into a server (NT or Win2K typically) running VPN services on your LAN, you would create a pinhole for this. This would allow "telecommuters" to access resources on the network.
Please Note: If your router is the model 3346N-002, or any other 3300 Series gateway running firmware version 7.3 and later, please click here for the configuration of the PPTP protocol forwarding. PPTP passthrough is configured using the Software Hosting feature in the Netopia router.
- From the main Pinhole Configuration page, click on the Add button.
- This will require two pinhole entries. For the first:
- We'll name this one VPN-1.
- The Protocol is TCP.
- External Port Start and End is 1723.
- Enter the Internal IP Address of the server. (192.168.1.20 for our example)
- The Internal Port is also 1723.
- Click on the Submit button.
- Click on the Add More Pinholes link.
- Again, click on the Add button.
- Name this pinhole VPN-2.
- Select PPTP from the drop down Protocol menu.
- Leave internal and external ports at 0.
- Enter the same IP Address that was added above.
- Click on Submit.
- Click on Add More Pinholes.
- The router will now forward the PPTP traffic to the local server on the network.
Configure a Timbuktu Host
Timbuktu, manufactured by Netopia, is a popular remote control software application that allows you to control a remete PC or MacIntosh.
PLEASE NOTE: Timbuktu uses a range of ports for the control features of this application. If you have a model 3341/3346 and wish to configure pinholes for this or any application using a range of ports, Please Click Here for specific instructions that pertain to these models ONLY!
- Following the previous example, again click on Add,
and name this one Timbuktu-1.
- Protocol Select is still TCP.
- External Port Start is 1417.
- External Port End is 1420.
- Enter the Internal IP Address of the workstation you wish to control remotely. (Example 192.168.1.15).
- Enter 1417 for the Internal Port.
- Click Submit for this entry.
- Click on the Add More Pinholes link.
- Click on Add.
- Give this entry a unique name such as Timbuktu-2 to prevent overwriting the first entry.
- Change each of the port numbers to 407 in the corresponding three fields.
- Click on the Protocol drop-down box and select UDP.
- Enter the IP address of the workstation again in the Internal IP Address field.
- Click on Submit to save the changes for this entry.
- Click on the Add More Pinholes link.
- Here you can again click Add for a new pinhole, or you can highlight an existing pinhole entry
to Edit the configuration or Delete the entry altogether.
- Once you have finished with the configuration of the pinholes, click on the
in the upper right hand corner.
This will validate that the settings are legal for your network. - Click Save and Restart. This will restart the Netopia and retain the pinhole configuration.
Pinhole configuration in the 3341/3346 models running firmware 6.3.0 R9 are the same with the exception of applications using a range of ports. This platform supports individual port assignments only per entry. For example, the external port start and end, as well as the internal port, must be the same value per unique entry. Using the Timbuktu configuration as an example, the first pinhole would be TCP port 1417, the second pinhole would be TCP port 1418, the third would be TCP port 1419 and the fourth would be TCP port 1420. The fifth entry would then be UDP port 407. Finally, for the purposes of this illustration, there is a mail server on the same computer with the pinhole name SMTP. The first image below illustrates the entry for the first pinhole in the Timbuktu range of ports, and the next image shows the list of pinholes after the configuration is complete as per this example.


- Click on the
in the upper right hand corner.
This will validate that the settings are legal for your network. - If you get Validation Passed, click Save and Restart in the menu. If it doesn't validate the change, a message will indicate the reason. It must be corrected before the configuration change can be applied.
- This completes the configuration of the Netopia for Pinholes.
You've now configured your Netopia Router for port forwarding Pinholes.
The above examples will provide the framework to configure pinholes for the Cayman Router. By referring to the chart included here, you can set up other servers on your network to be accessed through Network Address Translation.
