TP-Link Deco BE63 P2P Network Test

WebRTC peer-to-peer latency, jitter, and packet loss. All measurement runs in the browser. No backend, no account.

ZERO UPLOAD · ALL LOCAL
  1. Wait for the automatic STUN probe to complete; it shows your public IP and NAT type.
  2. Choose a role: click "Start Session" on one browser to become the Initiator, "Join Session" on the other.
  3. Initiator: copy the offer SDP and send it to your partner.
  4. Joiner: paste the offer, click "Generate Answer", then copy the answer SDP and send it back.
  5. Initiator: paste the answer and click "Connect". The live dashboard starts automatically.
  6. Use the Simulated Loss and Artificial Latency sliders to test degraded conditions.

Expected NAT profile for TP-Link Deco BE63

This router typically shows Full / Restricted Cone NAT on the STUN probe above.

Waiting for the STUN probe to finish.

PROBING...

Public IP NAT Type Candidate Types STUN Reachable Gathering Time

YOUR OFFER — COPY AND SEND TO PARTNER

PASTE PARTNER'S ANSWER HERE

PASTE PARTNER'S OFFER HERE

YOUR ANSWER — COPY AND SEND BACK

Current RTT Average RTT Min RTT Max RTT Jitter Packets Sent Packets Received Packet Loss ICE Candidate Type

Accent line = RTT over time. Red markers = simulated packet drops.

Data Channel State Packets Echoed

TP-Link Deco BE63 P2P Test: WebRTC NAT and Mesh Configuration

TP-Link's Deco BE63 earned RTINGS' 2026 best overall mesh router designation by delivering strong performance across coverage, throughput consistency, and ease of setup.1 Each node ships with four 2.5G Ethernet ports and supports both wired and wireless backhaul for whole-home coverage.2 Configuration is handled through the Deco app (iOS/Android) and optionally through a browser interface at 192.168.68.1, providing more NAT configuration access than competing app-only mesh systems.3

For P2P and WebRTC, the Deco BE63 uses restricted cone NAT.4 UPnP is supported and generally reliable in the Deco BE63 firmware generation, without the UPnP failures documented on some eero versions. The STUN probe on this page will return a consistent external port across requests, confirming the cone NAT classification.4 TP-Link HomeShield provides QoS without requiring a paid subscription for the basic QoS tier.1

Specifications2

Wi-Fi standardWi-Fi 7 (802.11be), triband
Ethernet ports4x 2.5G per node (WAN/LAN auto-sensing)
UPnPSupported and reliable in current firmware
NAT type controlStandard cone NAT; port forwarding via app or browser admin panel
Subscription requiredHomeShield basic QoS without subscription; HomeShield Pro requires subscription
Configuration interfaceDeco app + browser admin panel at 192.168.68.1

NAT type and UPnP on the Deco BE63

The Deco BE63 enables UPnP by default. The UPnP status table is visible in the advanced browser admin panel at 192.168.68.1 under Advanced > NAT Forwarding > UPnP, showing all active port mappings from LAN devices.3 This access distinguishes the Deco BE63 from app-only mesh systems; you can directly verify whether a gaming console's UPnP request was honored. Port forwarding rules configured under NAT Forwarding > Virtual Servers persist across router restarts and DHCP lease renewals. Assigning a static IP reservation to the target device before adding port forwarding rules ensures the rule remains accurate. Running the STUN probe in this tool confirms whether the UPnP mappings are actually effective for external reachability, because the probe tests the same path a remote peer would use when establishing a direct WebRTC connection through your Deco network.

Using the browser admin panel for NAT diagnostics

The Deco BE63's browser admin panel at 192.168.68.1 exposes NAT diagnostics that the mobile Deco app does not surface. Under Advanced > NAT Forwarding > UPnP, the full UPnP mapping table shows every active port request including the internal device, requested external port, and lease expiration time. This visibility lets you confirm whether a WebRTC application's port mapping is still active or has expired without waiting for a connection failure. The browser panel also logs NAT table events under System > Log, so you can trace when a specific port mapping was created or removed. If the STUN probe in this tool shows a symmetric NAT classification but the UPnP table shows active mappings, the ISP is applying a second NAT layer above the Deco; contact the ISP to request a public IP or enable IPv6 to bypass the CGNAT restriction.

A practical diagnostic workflow is to run the STUN probe, then immediately check the UPnP table in the browser admin panel. If the probe shows matching external ports and the UPnP table shows active mappings for the test device, the NAT configuration is working correctly. If the probe shows relay or symmetric NAT but the UPnP table shows mappings, the ISP CGNAT layer is the bottleneck and enabling IPv6 on the Deco is the fastest path to direct connectivity. If the UPnP table is empty despite the application requesting ports, the UPnP request is being silently dropped and static port forwarding is the required workaround.

WebRTC and P2P configuration on the BE63

For consistent WebRTC connections, verify UPnP is enabled and check the browser admin panel to confirm port mappings are being created. HomeShield QoS can be configured to prioritize real-time UDP; assign the device running WebRTC or gaming applications to the highest-priority traffic class. The Deco mesh backhaul (wired or wireless) adds a small processing hop within the mesh, but this is typically under 1 ms on wired backhaul. Consequently, connecting the primary gateway node directly to the ISP and using wired backhaul between mesh nodes produces the lowest latency and jitter for P2P applications. CapyToolkit's P2P tester runs over the same network path your applications use, so the ICE candidate type and RTT you see here reflect the actual connectivity your WebRTC applications will experience on the Deco BE63.

Testing the BE63 with this tool

Connect one browser to the Deco network and a second to a remote connection. The STUN probe public IP should match the WAN IP in the Deco app under More > Advanced > IPv4. If the probe shows 100.64.x.x, carrier-grade NAT from the ISP is present above the Deco. The ICE candidate type should show "srflx" on a well-configured Deco BE63 with cone NAT active.5 For multi-node deployments, the primary gateway node handles all WAN routing; satellite nodes relay traffic through the primary regardless of wireless or wired backhaul configuration. The STUN probe in this tool is particularly useful for Deco deployments because it reveals whether the mesh topology is affecting the NAT behavior your external peers observe when they attempt to connect to your network.

HomeShield QoS real-time traffic prioritization on the BE63

The Deco BE63's HomeShield QoS assigns traffic to priority tiers based on device classification and traffic type. Configuring QoS for P2P applications requires assigning the device running WebRTC or gaming software to the Streaming or Gaming category in the HomeShield interface. Access QoS settings through the browser admin panel at 192.168.68.1 under HomeShield > QoS; the browser panel exposes per-device bandwidth allocation alongside traffic category assignment, providing more control than the Deco mobile app alone.

Enabling HomeShield QoS without configuring the WAN upload bandwidth limit does not restrict competing traffic effectively. Set the WAN upload speed to match your ISP plan capacity under the bandwidth settings section. HomeShield uses the configured WAN values to calculate priority fractions: a device in the Gaming tier receives the highest fraction of available bandwidth when contention occurs. Without accurate WAN bandwidth values, the priority calculation defaults to conservative estimates that may not reflect your actual connection speed.

Verifying QoS effectiveness with the jitter tester

After enabling HomeShield QoS and assigning the test device to the Gaming tier, start a large download and watch jitter under load from another LAN device. With QoS correctly configured, jitter during the competing download should stay below 5 ms. Without QoS (or with incorrect bandwidth values), the same download raises jitter to 20 to 50 ms. This before-and-after comparison confirms whether the HomeShield QoS configuration is protecting real-time traffic from competing bulk transfers on the Deco BE63.

IPv6 setup on the Deco BE63 for NAT bypass

IPv6 on the Deco BE63 is available through both the Deco app and the browser admin panel at 192.168.68.1. Navigate to Advanced > IPv6 in the browser admin panel to configure IPv6 address acquisition. The Deco BE63 supports three IPv6 modes: Native (DHCPv6 prefix delegation from the ISP to the Deco, the correct mode for most ISPs), Pass-Through (used when the ISP provides a delegated prefix directly to a specific customer-premises device), and 6to4 Tunnel (a fallback for IPv4-only ISPs). For WebRTC P2P improvement, Native mode is the correct configuration when your ISP provides IPv6.

When IPv6 is active with valid global prefix delegation, devices on the Deco network receive global IPv6 addresses via SLAAC or DHCPv6. WebRTC ICE gathers host candidates from these addresses, which carry higher priority than server-reflexive IPv4 candidates and bypass NAT traversal entirely.6 The browser admin panel shows the active IPv6 prefix and assigned addresses under Network > IPv6 Status, confirming whether prefix delegation from the ISP succeeded. If the status shows no prefix, the ISP is not providing IPv6 through the configured mode and the STUN probe will continue using IPv4 candidates.

Confirming IPv6 candidate generation in the browser console

After enabling IPv6 on the Deco BE63, open the browser developer console before starting a P2P test session. ICE candidates generated during connection appear as RTCPeerConnection icecandidate events logged in the console. Filter the console for "candidate" entries; global IPv6 host candidates appear with addresses in the 2001:xxxx format rather than the fe80:: link-local format. Seeing global IPv6 host candidates confirms the Deco BE63 is providing valid global IPv6 addresses and that WebRTC connections to IPv6-capable peers will bypass NAT traversal.

Sources
  1. 1.

    RTINGS, "The 4 Best Mesh Wi-Fi Systems of 2026," rtings.com, June 2026. https://www.rtings.com/router/reviews/best/mesh-wifi-system

  2. 2.

    TP-Link, "Deco BE63 | Deco 7 Pro BE10000 Whole Home Mesh WiFi 7 System," tp-link.com, accessed June 2026. https://www.tp-link.com/us/deco-mesh-wifi/product-family/deco-be63/

  3. 3.

    TP-Link, "How to Log In to Your TP-Link Deco Web Management Page," tp-link.com, April 2026. https://www.tp-link.com/us/support/faq/2641/

  4. 4.

    webrtcHacks, "STUN the Network – How STUN helps WebRTC Traverse NATs," webrtchacks.com, accessed June 2026. https://webrtchacks.com/stun-helps-webrtc-traverse-nats/

  5. 5.

    Mozilla Developer Network, "RTCIceCandidate: type property," developer.mozilla.org, accessed June 2026. https://developer.mozilla.org/en-US/docs/Web/API/RTCIceCandidate/type

  6. 6.

    P. Martinsen, T. Reddy, and P. Patil, "Guidelines for Multihomed and IPv4/IPv6 Dual-Stack Interactive Connectivity Establishment (ICE)," RFC 8421, IETF, July 2018. https://datatracker.ietf.org/doc/rfc8421/

FAQ