Applies to: Minecraft: Java Edition 26.3 server (TCP 25565) and Bedrock Dedicated Server 1.26 (TCP 19132 plus UDP); tested on AlmaLinux 9
Players reach a Minecraft server through a network port. If the port is closed by a firewall or not forwarded by your router, the server runs fine but nobody from outside can join.
The default ports
- Java Edition: TCP
25565(server-portinserver.properties). - Bedrock Edition (Bedrock Dedicated Server 1.26): TCP
19132for the connection, plus UDP ports for game traffic. Current versions use the new NetherNet transport by default (transport=nethernetinserver.properties); set a fixed UDP range withserver-udp-ports, for exampleserver-udp-ports=49152-49200, and open that range too. Older versions (transport=raknet) used UDP19132for IPv4 and19133for IPv6. - Query (only if
enable-query=true): UDP onquery.port, 25565 by default. - RCON (remote console): TCP
25575. Don’t open this one to the internet.
1. Check that the server is listening
sudo ss -ltnp | grep 25565
On our test server this showed LISTEN ... *:25565 ... users:(("java",...)). If nothing is listed, the server isn’t running or uses another port.
2. Open the firewall on the server
# AlmaLinux, Rocky Linux (firewalld) sudo firewall-cmd --permanent --add-port=25565/tcp sudo firewall-cmd --reload # Ubuntu, Debian (ufw) sudo ufw allow 25565/tcp # Bedrock 1.26: open 19132/tcp and your server-udp-ports range, for example 49152-49200/udp
On Windows, allow Java when Windows Defender Firewall asks, or add a rule in PowerShell (as administrator):
New-NetFirewallRule -DisplayName "Minecraft" -Direction Inbound -Protocol TCP -LocalPort 25565 -Action Allow
3. Test from outside
nc -zv SERVER-IP 25565
From our own computer this printed Connection to ... port 25565 succeeded!, and the multiplayer list showed the server with version 26.3. Test from a different network than the server’s (for a home server, use mobile data).
4. Port forwarding (server at home)
- Give the computer running the server a fixed local IP address (a DHCP reservation in your router).
- In your router’s admin page, open Port Forwarding (sometimes Virtual Server or NAT).
- Forward TCP 25565 (Bedrock 1.26: TCP 19132 and your UDP range) to that local IP address.
- Give players your public IP address.
If the WAN address shown in your router differs from your public IP, your provider uses carrier-grade NAT, and port forwarding can’t work. Hosting at home also shows your home IP address to every player.
On a VPS
There is no router to configure: open the port in the server’s firewall and players connect to the VPS IP address. To use a name such as play.example.com, or a port other than 25565 without players typing it, add an SRV record: SRV records for Minecraft.
Change the port
Set server-port=25570 in server.properties, restart the server, open the new port in the firewall, and connect with SERVER-IP:25570 (or use an SRV record).
Setting up a server: make a Minecraft server on Linux. Our Minecraft VPS runs Java or Bedrock with DDoS protection, which a home connection doesn’t have.
Ucartz services for this topic
- KVM VPS hosting: NVMe SSD and full root access, with Free Basic Managed Support.
- Unmanaged dedicated servers: full root access and free IPMI KVM, with Free Basic Managed Support.
- Linux server management: hardening, patching, monitoring and automation for Ubuntu, Debian, RHEL and AlmaLinux.
