Advertisement

Port forwarding for a Minecraft server

Java Edition needs one open port, and that port is TCP. Remembering this fixes the majority of broken Minecraft setups: the game talks over a plain TCP stream, so a UDP-only rule can look entirely correct on the router's page while letting nobody in.

Your setup

Choose the firmware family rather than your exact model — every router in a family shares the same menus.

Out of the box it is 25565. If you changed that, use whatever you set in server-port (server.properties).

The local address of the computer that runs the server. Find it with ipconfig on Windows or ip addr on Linux; it will begin with 192.168, 10. or 172.

Open these

Your firmware takes ranges, so each line here is one rule.

  • 25565 TCP
  • 25565TCPJava EditionEvery Java client connects here. Minecraft is TCP — forwarding UDP alone is the single most common failed setup.

Only if you want them

The server runs fine without these. Each open port is one more door for strangers to try, so leave out what you do not need.

  • 25565 UDP
  • 25565UDPQueryOnly needed when enable-query=true, which is not the default. Server-list sites read player counts from it.

Do not open these

These are admin sockets. Many guides put them in the same list as the game ports, but forwarding them exposes a remote console for your server to the whole internet.

  • 25575TCPRCONRemote console. The password crosses the wire unencrypted — administer over SSH or your host panel instead.

For remote administration, connect to the machine through SSH or a VPN and use the port locally from there. Nobody else can reach it that way.

Step by step: your router

  1. 1

    Give the server a fixed local IP

    A forwarding rule targets a single local address. If the server comes back from a reboot with a new one, the rule quietly points at an empty address — which is how forwards seem to "break by themselves".

    On this router:look for DHCP Reservation, Address Reservation, Static Lease or Manually Assigned IP

  2. 2

    Open the router admin page

    From a device on the same network, open one of these in a browser:

    • 192.168.0.1
    • 192.168.1.1
    • 192.168.2.1
    • 10.0.0.1

    Almost always printed on a sticker on the router itself.

  3. 3

    Find the port forwarding page

    Port Forwarding, Virtual Server, NAT, Applications & Gaming, or Port Mapping

    Vendors use at least six names for the same feature. Whatever it is called, the page you want is the one asking for a port, a protocol and a device on your network. If the external and internal port fields both exist, set them to the same number.

  4. 4

    Create one rule per line

    a description field, if there is oneExternal / WAN / Public / Service portInternal / LAN / Private portProtocolInternal IP / Device / Server IP
    Minecraft2556525565TCPyour server’s local IP

    Use the same number for the external and internal port. You can make the external one different, but then every player has to connect on that new number, so keep them identical unless you have a specific reason not to.

  5. 5

    Let the server through its own firewall

    The router is now sending traffic to the right computer, but that computer can still turn it away. Windows Defender Firewall is the usual offender: it blocks a newly installed dedicated server by default, and from outside that is indistinguishable from a broken forward.

Take it with you

Minecraft — port forwarding rules
---------------------------------
25565  TCP  ->  <server local IP>

Check whether it worked

Always test from outside your network. A connection from another device in the house proves nothing: that traffic stays on your LAN and never passes through the rule you just created.

Advertisement

The usual mistake

Bedrock Edition is not the same server — different port, different protocol — and you cannot swap one for the other. Players on phones, consoles or the Windows Store edition are on Bedrock, and they need port 19132 over UDP instead. The query port is the other common mix-up. It is only relevant once you enable querying so server-list sites can show your player count; nobody needs it to join.

Advertisement

Skipping port forwarding

An SRV record lets players type a domain rather than an address and port, which tidies things up but does not replace forwarding — the port must still be reachable. A hosted server removes the question altogether, since it already sits on a public address with the port open.

Rather not run the server yourself?

These tools are free and funded by the two hosting services we run. If you want a server that is already set up, here they are.

Advertisement