Finding Your Ports
Your server listens on specific ports. You need to allow each one your users connect to. There are four ways to find them.
From your game's documentation or launch settings
Every game server documents its default ports, and your start command or config file shows the ones you have set. Look for words like port, queryport, rconport, gameport, +port, -port, server.port, QueryPort, Port=.
From your game panel
If you run the server through a panel (Pterodactyl, WISP and similar), the server's Allocations or Network page lists every port assigned to it. Each one that players or tools connect to needs a row.
From the server itself (Linux)
ss -tulpnThis lists every port something is listening on. The left columns show tcp or udp and the port after the colon. Ignore anything bound to 127.0.0.1, which is local only and does not need a rule.
From the server itself (Windows)
In PowerShell:
Get-NetTCPConnection -State Listen | Select LocalPort, OwningProcessGet-NetUDPEndpoint | Select LocalPort, OwningProcessOr netstat -ano in a command prompt.
If a port appears in those listings but nobody connects to it from outside (a database only your own web app uses, for example), you do not need to open it, and leaving it closed is safer.
Game Port Versus Query Port
Many Steam games use two ports: the game port that players connect to, and a query port that the Steam server browser and tools like Battlemetrics use to ask "what is this server, how many players". Sometimes they are the same number (Source engine, 27015). Often they differ (ARK: game 7777, query 27015; DayZ: game 2302, query 27016). You need both.
If the query port is missing or wrong, your server works for players who connect directly but does not appear in server lists.
Choosing a Filter for a UDP Port
- Your game is on the Source engine (CS2, CS:GO, Garry's Mod, TF2, Left 4 Dead 2 and other Valve games) and game and query share a port: Steam query + game.
- The port is a dedicated Steam query port (ARK
27015, DayZ27016, Squad27165, Valheim2457, Arma 32303, Palworld27015, Unturned27016, 7 Days to Die26901): Steam query only. Nothing except queries belongs on that port, so anything else is dropped. - The game uses RakNet (Rust game port, Minecraft Bedrock, SA-MP's underlying transport): RakNet.
- SA-MP or open.mp game port: SA-MP query + game.
- A WireGuard endpoint: WireGuard only.
- An OpenVPN UDP endpoint: OpenVPN only.
- Anything else, or you are not sure: Rate limited. This passes all traffic on the port subject to flood limits and is always safe to choose.
TCP ports have one filter, SYN proxy, which is always right.
Quick Reference for Common Servers
Presets exist for all of these. The table is for checking your own ports against them, and for spotting the extra TCP rows (RCON, admin tools) that are easy to forget.
| Server | Rows you need |
|---|---|
| Minecraft Java | TCP 25565 SYN proxy |
| Minecraft Bedrock | UDP 19132 RakNet |
| Rust | UDP 28015 RakNet, TCP 28016 (RCON), TCP 28082 (Rust+) |
| CS2 / Garry's Mod / TF2 | UDP 27015 Steam query + game, TCP 27015 (RCON), UDP 27020 (SourceTV) |
| FiveM / RedM | TCP and UDP 30120 Rate limited, TCP 40120 (txAdmin) |
| ARK | UDP 7777 and 7778 Rate limited, UDP 27015 Steam query only, TCP 27020 (RCON) |
| DayZ | UDP 2302-2305 Rate limited, UDP 27016 Steam query only |
| Valheim | UDP 2456 Rate limited, UDP 2457 Steam query only |
| Palworld | UDP 8211 Rate limited, UDP 27015 Steam query only, TCP 8212 (REST API) |
| SA-MP / open.mp | UDP 7777 SA-MP query + game |
| TeamSpeak 3 | UDP 9987 Rate limited, TCP 10011 (ServerQuery), TCP 30033 (file transfer) |
| Mumble | TCP and UDP 64738 |
| WireGuard | UDP 51820 WireGuard only |
| OpenVPN | UDP 1194 OpenVPN only, TCP 1194 if you also run TCP mode |
| Website | TCP 80 and 443 |
| Linux admin | TCP 22 (SSH) |
| Windows admin | TCP 3389 (Remote Desktop) |
Limits and Good Practice
- Up to 32 rules per IP.
- Up to 64 UDP ports per IP can carry a protocol filter (Steam query, RakNet, SA-MP, WireGuard, OpenVPN). Ranges count port by port, so a 200-port range on Rate limited is fine but on Steam query only is not.
- Open only what you use. Every closed port is one that cannot be attacked.
- Prefer a protocol filter over Rate limited whenever your protocol is supported. It is stricter and catches attacks Rate limited lets through.
- Keep Ping on unless you have a reason to hide the server; uptime monitors need it.
- After any change, test every service you run, not just the one you changed.
Frequently Asked Questions
Next Steps
If you have not set the panel up yet, start with the GlitchGuard setup guide. Terms like SYN proxy and query cache are explained in the glossary, and if a service stopped responding after a change, the troubleshooting guide lists the usual causes.
Not protected yet?
GlitchGuard is available as an add-on on VPS and dedicated servers. Open a ticket from your service page and we will switch it on, then come back to this guide.