How to

How to Port Forward a Game Server (Router Guide + Ports for Every Game)

Port forwarding explained step by step, with verified ports for Minecraft, Rust, ARK, Palworld, Valheim and more, plus CGNAT and firewall fixes.

Updated Sep 27, 2026 · 6 min read

On this page

If you run a game server at home, friends on your Wi-Fi can join straight away but everyone else gets "connection timed out". The fix is port forwarding: telling your router which device should receive traffic for your game. This guide explains how it works, how to set it up on any router, the exact ports for every game we host, and what to do when it still does not work.

What port forwarding does

Your home has one public IP address, shared by every phone, console and PC behind the router. When a friend connects to that address, the router has no idea which device the traffic is meant for, so it drops it.

A port forwarding rule says: "anything that arrives on port 25565, send it to 192.168.1.20". Now the router knows your server PC should get the connection. Each game listens on its own port (or a few), and each port is either TCP, UDP or both, so the rule has to match exactly.

Step 1: Find your server's local IP

The rule needs the local address of the machine running the server.

  • Windows: open Command Prompt and run ipconfig. Look for IPv4 Address under your active adapter, for example 192.168.1.20.
  • macOS: open System Settings, then Network, pick your connection and click Details. The IP address is listed there.
  • Linux: run ip addr and look for the inet line on your main interface, or run hostname -I.

Local addresses almost always start with 192.168., 10. or 172.16. to 172.31..

Step 2: Give that PC a fixed address

Routers hand out local addresses automatically and can change them after a reboot. If the address changes, your forwarding rule points at nothing. In your router, find the DHCP reservation (sometimes called static lease or address reservation) and reserve the current IP for your server PC. This is more reliable than setting a static IP on the PC itself.

Step 3: Create the forwarding rule

  1. Open your router's admin page. The address is usually printed on a sticker on the router, or it is your Default Gateway from ipconfig (often 192.168.0.1 or 192.168.1.1).
  2. Sign in. Many ISP routers now use an app instead of a web page.
  3. Find the section called Port Forwarding, Virtual Server, NAT or Applications and Gaming. It is often under Advanced.
  4. Add a rule with your server's local IP, the port or port range from the table below, and the protocol (TCP, UDP or both).
  5. Save and restart the game server.

Every router menu is different. If you get stuck, search your router model plus "port forwarding".

Step 4: Check your public IP and test

Search "what is my IP" to find your public address, and send that to friends along with the port if it is not the default. Test from outside your network, for example with a phone on mobile data. Testing from inside your own network can fail even when forwarding is correct, because many routers do not support connecting to their own public IP.

Online port checkers only work for TCP ports and only while the server is running. Most game ports are UDP, so the real test is a friend joining.

Ports for every game we host

These are the default ports. If you changed the port in the server config, forward the port you chose instead.

Game Ports to forward Notes
Minecraft: Java Edition 25565 TCP Add 19132 UDP if you run Geyser for Bedrock players.
Rust 28015 UDP, 28017 UDP 28015 is the game, 28017 the Steam query port for the server browser. RCON uses 28016 TCP, only forward it if you manage the server remotely.
ARK: Survival Ascended 7777 UDP RCON is 27020 TCP if you enable it.
Palworld 8211 UDP Add 27015 UDP if you want to list the server in the community browser.
Valheim 2456 to 2457 UDP Some guides add 2458 as well; 2456 and 2457 are the ones in use.
Enshrouded 15636 to 15637 UDP 15636 is the game port and 15637 the query port.
DayZ 2302 to 2305 UDP, 27016 UDP 27016 is the Steam query port that makes the server show up in the browser.
7 Days to Die 26900 TCP, 26900 to 26902 UDP Some guides also open 26903 UDP. The web dashboard on 8080 TCP is optional.
Project Zomboid 16261 to 16262 UDP Both are UDP. Forwarding TCP is the most common mistake.
Satisfactory 7777 UDP and TCP, 8888 TCP Update 1.1 added 8888. Without it players hang on "Connecting".
Factorio 34197 UDP
Terraria 7777 TCP
Counter-Strike 2 27015 UDP and TCP
RuneScape: Dragonwilds 7777 UDP One UDP port only, and the internal and external port must match.

Firewalls

Even with the router set up, the firewall on the server PC can block connections.

  • Windows: the first time a server starts, Windows Defender Firewall asks whether to allow it. Tick both Private and Public and click Allow. If you missed it, open Windows Defender Firewall with Advanced Security, click Inbound Rules, then New Rule, choose Port, enter the ports and protocol from the table, and allow the connection.
  • Linux with ufw: for example sudo ufw allow 25565/tcp or sudo ufw allow 2456:2457/udp.
  • Antivirus suites sometimes include their own firewall that ignores Windows settings. Check it if everything else looks right.

CGNAT: when forwarding is impossible

Some internet providers, especially mobile, fixed wireless, satellite and many fiber and cable plans, do not give you a public IP of your own. You share one with other customers through Carrier Grade NAT (CGNAT). No rule on your router can fix this, because the traffic never reaches your router.

To check, compare the WAN IP shown on your router's status page with the address from "what is my IP". If they differ, or the WAN IP starts with 100.64. to 100.127., you are behind CGNAT. Your options are:

  • Ask your ISP for a public IPv4 address. Some provide one free on request, others charge for it.
  • Use a tunnel or VPN service that gives you a reachable address, which adds latency and another thing to maintain.
  • Host the server somewhere else.

Common problems

  • Works on LAN, not for friends: the rule is missing, uses the wrong protocol, or points at an old local IP.
  • Worked yesterday, broken today: your server PC got a new local IP (use a DHCP reservation), or your public IP changed. Most home connections change public IP now and then, so you have to send friends the new one.
  • Double NAT: if your ISP modem is also a router and you have your own router behind it, you need to forward on both, or put the modem in bridge mode.
  • UPnP: some games open ports automatically with UPnP. It is convenient but unreliable and is often disabled for security, so a manual rule is better.

Why hosted servers skip all of this

A hosted server lives in a data center with its own public address and the ports already open. There is no router to configure, no CGNAT, no firewall prompts, and your home IP is never shared with the people who join. You copy the address from your dashboard, paste it into the game and play. If you are weighing it up, dedicated server vs peer to peer explains the trade offs, and every game above links to its own hosting page with plans.

Want a server without the setup?

Pick a game, pay, play. Your address and login appear the moment checkout finishes.

Browse games

Keep reading