Recommended Free Tools
To port forward a Minecraft server, first confirm its configured port, then forward that port and protocol from your router to the server computer’s reserved private IP. Allow the same traffic through the computer firewall and test from outside your home network.
Before you start: choose the right Minecraft port
Port forwarding lets players outside your home network reach a Minecraft server running on your computer. The correct port depends on the server software you are hosting, not simply the edition used by the person joining.
| Server | Default port | Protocol |
|---|---|---|
| Java Edition dedicated server | 25565 |
TCP |
| Bedrock Dedicated Server, IPv4 | 19132 |
UDP |
| Bedrock Dedicated Server, IPv6 | 19133 by default |
UDP |
Java’s port can be changed in server.properties with server-port. Bedrock’s IPv6 port is controlled by server-portv6. Always forward the value actually configured on your server. A Java server normally needs TCP, while an unmodified Bedrock server normally needs UDP; forwarding both protocols is not automatically necessary.
This guide covers the complete path: confirm the server port, find the host computer’s private IP address, reserve that address, create the router rule, allow the traffic through the computer’s firewall, and test from outside your network.
#1 Best Overall
- 𝐅𝐮𝐭𝐮𝐫𝐞-𝐏𝐫𝐨𝐨𝐟 𝐘𝐨𝐮𝐫 𝐇𝐨𝐦𝐞 𝐖𝐢𝐭𝐡 𝐖𝐢-𝐅𝐢 𝟕: Powered by Wi-Fi 7 technology, enjoy faster speeds with Multi-Link Operation, increased reliability with Multi-RUs, and more data capacity with 4K-QAM, delivering enhanced performance for all your devices.
- 𝐁𝐄𝟑𝟔𝟎𝟎 𝐃𝐮𝐚𝐥-𝐁𝐚𝐧𝐝 𝐖𝐢-𝐅𝐢 𝟕 𝐑𝐨𝐮𝐭𝐞𝐫: Delivers up to 2882 Mbps (5 GHz), and 688 Mbps (2.4 GHz) speeds for 4K/8K streaming, AR/VR gaming & more. Dual-band routers do not support 6 GHz. Performance varies by conditions, distance, and obstacles like walls.
- 𝐔𝐧𝐥𝐞𝐚𝐬𝐡 𝐌𝐮𝐥𝐭𝐢-𝐆𝐢𝐠 𝐒𝐩𝐞𝐞𝐝𝐬 𝐰𝐢𝐭𝐡 𝐃𝐮𝐚𝐥 𝟐.𝟓 𝐆𝐛𝐩𝐬 𝐏𝐨𝐫𝐭𝐬 𝐚𝐧𝐝 𝟑×𝟏𝐆𝐛𝐩𝐬 𝐋𝐀𝐍 𝐏𝐨𝐫𝐭𝐬: Maximize Gigabitplus internet with one 2.5G WAN/LAN port, one 2.5 Gbps LAN port, plus three additional 1 Gbps LAN ports. Break the 1G barrier for seamless, high-speed connectivity from the internet to multiple LAN devices for enhanced performance.
- 𝐍𝐞𝐱𝐭-𝐆𝐞𝐧 𝟐.𝟎 𝐆𝐇𝐳 𝐐𝐮𝐚𝐝-𝐂𝐨𝐫𝐞 𝐏𝐫𝐨𝐜𝐞𝐬𝐬𝐨𝐫: Experience power and precision with a state-of-the-art processor that effortlessly manages high throughput. Eliminate lag and enjoy fast connections with minimal latency, even during heavy data transmissions.
- 𝐂𝐨𝐯𝐞𝐫𝐚𝐠𝐞 𝐟𝐨𝐫 𝐄𝐯𝐞𝐫𝐲 𝐂𝐨𝐫𝐧𝐞𝐫 - Covers up to 2,000 sq. ft. for up to 60 devices at a time. 4 internal antennas and beamforming technology focus Wi-Fi signals toward hard-to-reach areas. Seamlessly connect phones, TVs, and gaming consoles.
What port forwarding does—and what it does not do
Your router normally blocks unsolicited connections arriving from the internet. A port-forwarding rule tells it to send traffic arriving on a particular external port to a particular device inside your home network.
For example, a Java rule might send traffic like this:
Internet player → your public IP:25565 → router → 192.168.1.50:25565 → Minecraft server
The public IP identifies your router on the internet. The private IP identifies the server computer inside your LAN. The router rule targets the private IP—not the public IP.
Port forwarding will not correct an incorrect game edition, incompatible version or modpack, an allowlist rejection, a stopped server, or a server that is listening on a different port. Java and Bedrock clients also cannot directly join each other’s unmodified dedicated servers.
Do these 3 things before closing this tab:
1Clear out junk files and repair common Windows errors2Fix the driver behind crashes, sound loss and screen glitches3Repair Windows errors before they cause bigger problemsStep 1: verify the server’s configured port
Java Edition
Start the server once if necessary so it creates its configuration files. Stop it cleanly, then open server.properties in the server directory. Find:
server-port=25565
If the value is different, use that value in the router and firewall rules. For ordinary Java hosting, leave server-ip blank:
server-ip=
Do not paste your public IP into server-ip. That setting is for binding the server to a specific local network interface. An incorrect value can prevent the server from listening and make a correct port forward appear broken.
After changing server-port, save the file and restart the server. The official Java setup uses a launch command from the server directory in this form:
The Tool Desk
Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →java -jar "your jar name".jar
Replace the example filename with the exact name of your downloaded server JAR.
Rank #2
- 𝐍𝐞𝐱𝐭-𝐆𝐞𝐧 𝐖𝐢-𝐅𝐢 𝟕 - Optimize performance on latest WiFi 7 laptops and devices, like the iPhone 16 Pro, Samsung Galaxy S24 Ultra, and PS5 Pro with the latest WiFi 7 technology with Multi-Link Operation, Multi-RUs, 4K-QAM, and up to 320 MHz channels.◇△
- 𝟕-𝐒𝐭𝐫𝐞𝐚𝐦, 𝐁𝐄𝟗𝟕𝟎𝟎 𝐓𝐫𝐢-𝐁𝐚𝐧𝐝 𝐖𝐢-𝐅𝐢 𝟕 𝐒𝐩𝐞𝐞𝐝𝐬 - Delivers smooth 4K/8K streaming, immersive AR/VR gaming, and blazing-fast downloads with speeds up to 5,765 Mbps on the 6 GHz band, 2,882 Mbps on the 5 GHz band, and 1,032 Mbps on the 2.4 GHz band.⌂
- 𝐌𝐚𝐱𝐢𝐦𝐢𝐳𝐞𝐝 𝐂𝐨𝐯𝐞𝐫𝐚𝐠𝐞 - Up to 2,600 sq. ft. coverage for up to 120 devices at a time. 6 optimally positioned antennas and Beamforming technology focus Wi-Fi signals toward hard-to-cover areas for stronger coverage-—ideal for those seeking the best WiFi router for large homes.
- 𝟏𝟎 𝐆𝐛𝐩𝐬 𝐏𝐨𝐫𝐭 𝐟𝐨𝐫 𝐌𝐮𝐥𝐭𝐢-𝐆𝐢𝐠𝐚𝐛𝐢𝐭 𝐂𝐨𝐧𝐧𝐞𝐜𝐭𝐢𝐯𝐢𝐭𝐲 - Features 1x 10 Gbps WAN/LAN port, 1x 2.5 Gbps WAN/LAN port, and 3x 2.5 Gbps LAN ports. Integrate with a multi-gig modem for fast, wired gig+ internet.
- 𝐎𝐮𝐫 𝐂𝐲𝐛𝐞𝐫𝐬𝐞𝐜𝐮𝐫𝐢𝐭𝐲 𝐂𝐨𝐦𝐦𝐢𝐭𝐦𝐞𝐧𝐭 - TP-Link is a signatory of the U.S. Cybersecurity and Infrastructure Security Agency’s (CISA) Secure-by-Design pledge. This device is designed, built, and maintained, with advanced security as a core requirement.
Bedrock Dedicated Server
In the Bedrock server configuration, the normal defaults are:
server-port=19132
server-portv6=19133
For an ordinary IPv4 internet connection, forward 19132/UDP. Only create a separate 19133/UDP rule when you intentionally provide the server over IPv6 and your network and clients support that setup.
Step 2: find the server computer’s private IPv4 address
On a Windows computer hosting the server:
- Open Command Prompt.
- Run
ipconfig. - Under the active Ethernet or Wi-Fi adapter, note the IPv4 Address.
- Also note the Default Gateway; this is usually the address you enter in a browser to open the router’s administration page.
You may see values similar to:
IPv4 Address . . . . . . . . . . : 192.168.1.50
Default Gateway . . . . . . . . : 192.168.1.1
In this example, 192.168.1.50 is the forwarding target. It is not the address an internet player uses.
Reserve the address before creating the rule
A router usually assigns local addresses through DHCP. If the server later changes from 192.168.1.50 to 192.168.1.73, the rule can continue pointing at the old computer address and stop working.
Use your router’s DHCP reservation feature to associate the server computer with a fixed local address. A correctly managed static address is another option, but do not configure one casually if you do not know the network’s address, gateway, and DNS settings.
Step 3: open the router’s port-forwarding page
Sign in to the router using the Default Gateway address from ipconfig. Router interfaces differ by manufacturer, model, firmware, and internet-service-provider customization. Look for a feature named one of the following:
- Port Forwarding
- Virtual Server
- NAT Rule
- Port Mapping
There is no universal current menu path or button name that applies to every router. If the router has a device selector, choose the reserved server computer rather than entering an address that may change.
Free tools Windows power users keep installed
One-click scans. No signup required.
Step 4: create the port-forwarding rule
Default Java server
Create one rule with these values:
| Router field | Value |
|---|---|
| Rule name | Any descriptive name, such as Minecraft Java |
| External/WAN port | 25565 |
| Internal/LAN port | 25565 |
| Protocol | TCP |
| Target/device IP | The server’s private IPv4 address, such as 192.168.1.50 |
If you changed Java’s server-port to another value, use that value for the configured port. Many routers allow a different external port and internal port, but using the same value for both is the least confusing arrangement.
Default Bedrock server over IPv4
| Router field | Value |
|---|---|
| Rule name | Any descriptive name, such as Minecraft Bedrock |
| External/WAN port | 19132 |
| Internal/LAN port | 19132 |
| Protocol | UDP |
| Target/device IP | The server’s private IPv4 address |
Save or apply the rule. Some routers require a restart before the change becomes active. For IPv6 Bedrock hosting, create a separate UDP rule for the configured server-portv6 only if IPv6 service is deliberately enabled.
Rank #3
- NIGHTHAWK WIFI 6 ROUTER FOR YOUR WHOLE HOME: Delivers fast, reliable WiFi across every room of your apartment or small home for streaming, gaming, video calls, and smart home devices, all running at the same time without slowing each other down.
- WORKS WITH YOUR EXISTING INTERNET SERVICE: Pairs with your existing modem or gateway via ethernet. Compatible with most cable, fiber, DSL, and satellite providers. Some gateways and modem router combos may require bridge mode. No coax needed.
- SET UP AND MANAGE YOUR NETWORK WITH THE NIGHTHAWK APP: Download the free Nighthawk app on iOS or Android for guided setup. Manage WiFi, run speed tests, pause devices, and set up guest networks from anywhere. Active internet required.
- READY FOR THE DEVICES YOU ALREADY OWN: Your phones, laptops, and TVs work right out of the box. WiFi 6 delivers speeds up to 1.8 Gbps across 2.4 GHz and 5 GHz bands. Backward compatible with WiFi 5 and earlier.
- COVERAGE IN EVERY ROOM: Covers up to 1,500 sq. ft. for up to 20 connected devices. Walls, floors, and interference can reduce range. Larger or multi-story homes may benefit from a NETGEAR Orbi mesh WiFi system.
Do not place the server computer in the router’s DMZ as a shortcut. A DMZ is not equivalent to forwarding one Minecraft port; it can expose substantially more traffic from that computer.
Step 5: allow the port through the host firewall
The router’s rule does not bypass Windows or Linux firewall filtering. The server computer must also allow the relevant inbound protocol and port.
Windows graphical interface
- Open Windows Defender Firewall.
- Choose Advanced Settings.
- Select Inbound Rules.
- Click New Rule.
- Choose Port.
- Select the correct protocol—TCP for Java or UDP for Bedrock.
- Enter the configured local port.
- Choose Allow the connection, select the appropriate network profiles, and finish the rule.
Windows PowerShell
Run PowerShell as administrator. For a default Java server:
New-NetFirewallRule -DisplayName "Minecraft Java Server" -Direction Inbound -Protocol TCP -LocalPort 25565 -Action Allow
For a default Bedrock IPv4 server:
New-NetFirewallRule -DisplayName "Minecraft Bedrock Server" -Direction Inbound -Protocol UDP -LocalPort 19132 -Action Allow
Replace the port if you changed the server configuration. A separate UDP firewall rule is needed for Bedrock’s IPv6 port only when you are intentionally serving over IPv6.
Linux with UFW
For default ports, run:
sudo ufw allow 25565/tcp
For Bedrock IPv4 instead, run:
sudo ufw allow 19132/udp
Step 6: test locally before testing the internet connection
Keep the Minecraft server running during every test. A port checker can report a port as closed when no program is listening, even if the router rule is correct.
Test on the host computer
A Java server on the same computer can be tested with:
Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchPC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11localhost
Or specify the port explicitly:
localhost:25565
Use your configured port instead of 25565 when necessary. If localhost fails, do not start by changing router settings. The server may be stopped, startup may have failed, the port may be different, or the process may not be listening.
Test from another device on the same LAN
From a second computer on your home network, connect to the server computer’s private address, for example:
192.168.1.50:25565
For Bedrock, use the server’s configured UDP port in the Bedrock connection fields. LAN play does not require port forwarding; the router rule matters only to players connecting from outside your local network.
Rank #4
- Dual-band Wi-Fi with 5 GHz speeds up to 867 Mbps and 2.4 GHz speeds up to 300 Mbps, delivering 1200 Mbps of total bandwidth¹. Dual-band routers do not support 6 GHz. Performance varies by conditions, distance to devices, and obstacles such as walls.
- Covers up to 1,000 sq. ft. with four external antennas for stable wireless connections and optimal coverage.
- Supports IGMP Proxy/Snooping, Bridge and Tag VLAN to optimize IPTV streaming
- Access Point Mode - Supports AP Mode to transform your wired connection into wireless network, an ideal wireless router for home
- Advanced Security with WPA3 - The latest Wi-Fi security protocol, WPA3, brings new capabilities to improve cybersecurity in personal networks
Step 7: test from outside your home network
For Java, an outside player uses your public IPv4 address:
PUBLIC_IPV4
That works when the server uses Java’s default port. With a non-default port, include it:
PUBLIC_IPV4:PORT
Test from a genuinely external network: ask a friend to connect, disable Wi-Fi on a phone and use mobile data, or use an external port-checking service while the server is running.
Testing your public IP from the same home Wi-Fi can fail if the router does not support NAT loopback, also called hairpin NAT. That failure alone does not prove that the internet-facing rule is broken.
Troubleshooting by where the connection fails
localhost fails
- Confirm the server process is running and completed startup.
- Check
server.propertiesfor the actualserver-port. - Confirm the server is listening rather than exiting with an error.
- Leave Java’s
server-ipblank unless you have a deliberate interface-binding configuration.
Fix this stage before changing the router. A router cannot forward traffic to a service that is not listening.
Quick wins for a faster PC:
Clear out junk files and repair common Windows errorsFree Scan →Scan for outdated or missing drivers - takes under a minuteDriver Scan →Repair Windows errors before they cause bigger problemsFix Now →localhost works, but another LAN device cannot connect
Investigate the host firewall first. Then verify the protocol and port, the server computer’s current private IP, and the server’s interface binding. A changed local address is especially common when no DHCP reservation exists.
LAN connections work, but internet connections fail
Check the following in order:
- The forwarding target is the server computer’s current private IPv4 address.
- The protocol matches the server: TCP for normal Java, UDP for normal Bedrock.
- The configured port in
server.propertiesmatches the router and firewall rules. - The host firewall allows that port.
- The server is still running during the external test.
- You are testing from outside the home network rather than relying on NAT loopback.
- The network does not contain another router or carrier-grade NAT.
Check for double NAT or CGNAT
Compare the WAN or internet address shown in the router with the public IP shown by an external IP-checking service. If they differ, an upstream router or carrier-grade NAT may be involved.
Private WAN ranges include:
10.0.0.0/8172.16.0.0/12192.168.0.0/16
Carrier-grade NAT commonly uses the shared range 100.64.0.0/10. A port forward on the inner router cannot receive unsolicited internet traffic if an upstream device or ISP NAT is holding the public address.
When two routers are present, possible solutions include putting the upstream gateway into bridge mode, putting the inner router into access-point mode, or forwarding the port through both NAT layers. The correct choice depends on which device should perform routing and on the ISP’s equipment.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Best Value
- DUAL-BAND WIFI 6 ROUTER: Wi-Fi 6(802.11ax) technology achieves faster speeds, greater capacity and reduced network congestion compared to the previous gen. All WiFi routers require a separate modem. Dual-Band WiFi routers do not support the 6 GHz band.
- AX1800: Enjoy smoother and more stable streaming, gaming, downloading with 1.8 Gbps total bandwidth (up to 1200 Mbps on 5 GHz and up to 574 Mbps on 2.4 GHz). Performance varies by conditions, distance to devices, and obstacles such as walls.
- CONNECT MORE DEVICES: Wi-Fi 6 technology communicates more data to more devices simultaneously using revolutionary OFDMA technology
- EXTENSIVE COVERAGE: Achieve the strong, reliable WiFi coverage with Archer AX1800 as it focuses signal strength to your devices far away using Beamforming technology, 4 high-gain antennas and an advanced front-end module (FEM) chipset
- OUR CYBERSECURITY COMMITMENT: TP-Link is a signatory of the U.S. Cybersecurity and Infrastructure Security Agency’s (CISA) Secure-by-Design pledge. This device is designed, built, and maintained, with advanced security as a core requirement.
With CGNAT, ordinary inbound forwarding may not be available at all. You may need a public IPv4 option from the ISP, an appropriate tunnel or relay service, or another hosting arrangement.
Special cases: VPNs, VPS hosting, and modded servers
Hosting through a VPN
An active VPN can change the interface through which traffic leaves and may prevent ordinary home-router forwarding from reaching the server. The VPN provider must support inbound port forwarding, and the server must use the provider-assigned port. Bedrock hosting also requires suitable UDP support.
Hosting on a VPS
If the server runs on a VPS, your home router is normally irrelevant. Check three separate layers instead:
- The Minecraft process is listening on the intended port.
- The VPS provider’s security group or network ACL permits the correct protocol and port.
- The VPS operating-system firewall permits the same traffic.
Modded Java servers and proxies
A modded Java server normally still uses TCP 25565 unless server-port has been changed. However, proxies, query services, voice chat, or modpack-specific services may require additional ports. Follow the documentation for those components rather than forwarding every port mentioned online.
Even when a port appears open, players can still be rejected because they have the wrong Java version, mod list, modpack version, server version, address format, or because the server’s allowlist blocks them.
Common Minecraft port-forwarding mistakes
- Assuming Minecraft always uses 25565: that is the Java default only. Bedrock’s default IPv4 port is
19132/UDP, and either server can be configured differently. - Forwarding both TCP and UDP automatically: forward the protocol used by the hosted server unless a specific service requires another.
- Using the public IP as the forwarding target: the target must be the server computer’s private LAN IP.
- Putting the public IP in
server-ip: leave Java’s setting blank for normal hosting. - Testing the public address from inside the house: hairpin NAT may be unsupported. Use mobile data or another external network.
- Opening the router port but ignoring the computer firewall: both the router and host firewall must allow the connection.
- Forwarding to an unreserved local address: the router rule can become stale when DHCP assigns a new address.
- Using DMZ as a shortcut: it exposes much more than the single Minecraft port.
Quick verification checklist
- Correct server edition identified: Java or Bedrock.
- Actual port read from the server configuration.
- Java uses TCP unless the relevant software says otherwise; Bedrock IPv4 normally uses UDP.
- Java
server-ipis blank unless a specific local binding is intended. - Server computer’s current private IPv4 address recorded.
- DHCP reservation created for that computer.
- Router rule targets the private IP, not the public IP.
- Router rule saved and applied.
- Host firewall rule matches the same port and protocol.
localhostworks.- A second LAN device can connect, where applicable.
- External testing is performed while the server is running.
- WAN/public IP mismatch, double NAT, and CGNAT have been ruled out.
- Players use the correct edition, version, mods, address, and allowlist status.
For the official Java server setup and connection format, see Minecraft’s official Java Edition server setup guide. For additional port and NAT troubleshooting context, consult the Minecraft port-forwarding reference and the server port-forwarding troubleshooting guide.
Frequently Asked Questions
What port should I forward for a Minecraft Java server?
For a default Java Edition dedicated server, forward TCP port 25565. Confirm the value in `server.properties`; a changed `server-port` takes priority.
What port should I forward for Minecraft Bedrock?
For a default Bedrock Dedicated Server over IPv4, forward UDP port 19132. Bedrock’s default IPv6 port is UDP 19133, configured with `server-portv6`.
Do I need port forwarding for LAN Minecraft?
No. Forwarding is required for players outside your local network. Players on the same LAN can connect using the server computer’s private IP without a router port forward.
Why does my public Minecraft IP fail inside my own house?
Not necessarily. A router without NAT loopback, also called hairpin NAT, may not let a device inside the home network connect through the public address. Test using mobile data or another external network.
Why is my Minecraft port still closed after forwarding it?
A private or carrier-grade WAN address can indicate double NAT or CGNAT. In those cases, the inner router alone cannot accept unsolicited internet traffic; you may need bridge mode, forwarding through both routers, or a public-IP solution from the ISP.
The Bottom Line
The reliable method is to forward the port your server actually uses—normally 25565/TCP for Java or 19132/UDP for Bedrock—to the host computer’s reserved private IP, then allow the same traffic through the computer firewall. Confirm the server works locally before diagnosing the router, and test the public address from an external network.
Free tools Windows power users keep installed
One-click scans. No signup required.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




