Port forwarding for a Minecraft server
Java Edition needs one open port, and that port is TCP. Remembering this fixes the majority of broken Minecraft setups: the game talks over a plain TCP stream, so a UDP-only rule can look entirely correct on the router's page while letting nobody in.
Your setup
Choose the firmware family rather than your exact model — every router in a family shares the same menus.
Out of the box it is 25565. If you changed that, use whatever you set in server-port (server.properties).
The local address of the computer that runs the server. Find it with ipconfig on Windows or ip addr on Linux; it will begin with 192.168, 10. or 172.
Open these
Your firmware takes ranges, so each line here is one rule.
- 25565 TCP
25565TCPJava EditionEvery Java client connects here. Minecraft is TCP — forwarding UDP alone is the single most common failed setup.
Only if you want them
The server runs fine without these. Each open port is one more door for strangers to try, so leave out what you do not need.
- 25565 UDP
25565UDPQueryOnly needed when enable-query=true, which is not the default. Server-list sites read player counts from it.
Do not open these
These are admin sockets. Many guides put them in the same list as the game ports, but forwarding them exposes a remote console for your server to the whole internet.
25575TCPRCONRemote console. The password crosses the wire unencrypted — administer over SSH or your host panel instead.
For remote administration, connect to the machine through SSH or a VPN and use the port locally from there. Nobody else can reach it that way.
Step by step: your router
- 1
Give the server a fixed local IP
A forwarding rule targets a single local address. If the server comes back from a reboot with a new one, the rule quietly points at an empty address — which is how forwards seem to "break by themselves".
On this router:look for DHCP Reservation, Address Reservation, Static Lease or Manually Assigned IP
- 2
Open the router admin page
From a device on the same network, open one of these in a browser:
- 192.168.0.1
- 192.168.1.1
- 192.168.2.1
- 10.0.0.1
Almost always printed on a sticker on the router itself.
- 3
Find the port forwarding page
Port Forwarding, Virtual Server, NAT, Applications & Gaming, or Port Mapping
Vendors use at least six names for the same feature. Whatever it is called, the page you want is the one asking for a port, a protocol and a device on your network. If the external and internal port fields both exist, set them to the same number.
- 4
Create one rule per line
a description field, if there is one External / WAN / Public / Service port Internal / LAN / Private port Protocol Internal IP / Device / Server IP Minecraft 25565 25565 TCP your server’s local IP Use the same number for the external and internal port. You can make the external one different, but then every player has to connect on that new number, so keep them identical unless you have a specific reason not to.
- 5
Let the server through its own firewall
The router is now sending traffic to the right computer, but that computer can still turn it away. Windows Defender Firewall is the usual offender: it blocks a newly installed dedicated server by default, and from outside that is indistinguishable from a broken forward.
Take it with you
Minecraft — port forwarding rules --------------------------------- 25565 TCP -> <server local IP>
Check whether it worked
Always test from outside your network. A connection from another device in the house proves nothing: that traffic stays on your LAN and never passes through the rule you just created.
Advertisement
The usual mistake
Bedrock Edition is not the same server — different port, different protocol — and you cannot swap one for the other. Players on phones, consoles or the Windows Store edition are on Bedrock, and they need port 19132 over UDP instead. The query port is the other common mix-up. It is only relevant once you enable querying so server-list sites can show your player count; nobody needs it to join.
Advertisement
Skipping port forwarding
An SRV record lets players type a domain rather than an address and port, which tidies things up but does not replace forwarding — the port must still be reachable. A hosted server removes the question altogether, since it already sits on a public address with the port open.