1. Home
  2. ›
  3. Guides
  4. ›
  5. GlitchGuard
  6. ›
  7. Ports and Filters

Which Ports and Filters Your Server Needs in GlitchGuard

GlitchGuard only passes traffic on ports you have listed, so the setup comes down to two questions: which ports does your server use, and which filter belongs on each one. This guide answers both, with a quick reference for the servers we see most.

Finding Your Ports

Your server listens on specific ports. You need to allow each one your users connect to. There are four ways to find them.

From your game's documentation or launch settings

Every game server documents its default ports, and your start command or config file shows the ones you have set. Look for words like port, queryport, rconport, gameport, +port, -port, server.port, QueryPort, Port=.

From your game panel

If you run the server through a panel (Pterodactyl, WISP and similar), the server's Allocations or Network page lists every port assigned to it. Each one that players or tools connect to needs a row.

From the server itself (Linux)

ss -tulpn

This lists every port something is listening on. The left columns show tcp or udp and the port after the colon. Ignore anything bound to 127.0.0.1, which is local only and does not need a rule.

From the server itself (Windows)

In PowerShell:

Get-NetTCPConnection -State Listen | Select LocalPort, OwningProcess
Get-NetUDPEndpoint | Select LocalPort, OwningProcess

Or netstat -ano in a command prompt.

If a port appears in those listings but nobody connects to it from outside (a database only your own web app uses, for example), you do not need to open it, and leaving it closed is safer.

Game Port Versus Query Port

Many Steam games use two ports: the game port that players connect to, and a query port that the Steam server browser and tools like Battlemetrics use to ask "what is this server, how many players". Sometimes they are the same number (Source engine, 27015). Often they differ (ARK: game 7777, query 27015; DayZ: game 2302, query 27016). You need both.

If the query port is missing or wrong, your server works for players who connect directly but does not appear in server lists.

Choosing a Filter for a UDP Port

Protocol filters are stricter and better, but only when the protocol matches. Choosing WireGuard only for a Rust port would drop all your Rust traffic. If in doubt, use Rate limited and open a ticket to ask.

TCP ports have one filter, SYN proxy, which is always right.

Quick Reference for Common Servers

Presets exist for all of these. The table is for checking your own ports against them, and for spotting the extra TCP rows (RCON, admin tools) that are easy to forget.

ServerRows you need
Minecraft JavaTCP 25565 SYN proxy
Minecraft BedrockUDP 19132 RakNet
RustUDP 28015 RakNet, TCP 28016 (RCON), TCP 28082 (Rust+)
CS2 / Garry's Mod / TF2UDP 27015 Steam query + game, TCP 27015 (RCON), UDP 27020 (SourceTV)
FiveM / RedMTCP and UDP 30120 Rate limited, TCP 40120 (txAdmin)
ARKUDP 7777 and 7778 Rate limited, UDP 27015 Steam query only, TCP 27020 (RCON)
DayZUDP 2302-2305 Rate limited, UDP 27016 Steam query only
ValheimUDP 2456 Rate limited, UDP 2457 Steam query only
PalworldUDP 8211 Rate limited, UDP 27015 Steam query only, TCP 8212 (REST API)
SA-MP / open.mpUDP 7777 SA-MP query + game
TeamSpeak 3UDP 9987 Rate limited, TCP 10011 (ServerQuery), TCP 30033 (file transfer)
MumbleTCP and UDP 64738
WireGuardUDP 51820 WireGuard only
OpenVPNUDP 1194 OpenVPN only, TCP 1194 if you also run TCP mode
WebsiteTCP 80 and 443
Linux adminTCP 22 (SSH)
Windows adminTCP 3389 (Remote Desktop)

Limits and Good Practice

Frequently Asked Questions

Only if your server uses both. Websites, SSH, Remote Desktop, RCON and Minecraft Java are TCP. Most real-time games, voice servers and VPNs are UDP. Some (FiveM, Mumble) use both on the same port number, so they need two rows.
Rate limited. It passes all traffic on the port subject to flood limits and is always safe. If your game needs a dedicated protocol filter we do not have yet, open a ticket and we will look at building it.
Yes, type it as 27015-27020 in the Add a rule row. Ranges on Rate limited can be as wide as you like. Ranges on a protocol filter count port by port against the 64 port limit.
Load the preset, then remove the preset row for the port that differs and add your own with the same filter. Rows you add yourself are kept when you reload a preset later.
Only if something outside the server connects to it. A MySQL database used only by a web app on the same server is local traffic and does not need a rule. Leaving it closed is safer.

Next Steps

If you have not set the panel up yet, start with the GlitchGuard setup guide. Terms like SYN proxy and query cache are explained in the glossary, and if a service stopped responding after a change, the troubleshooting guide lists the usual causes.

Not protected yet?

GlitchGuard is available as an add-on on VPS and dedicated servers. Open a ticket from your service page and we will switch it on, then come back to this guide.

Open Client Area → How GlitchGuard Works
← Back to Guides