LochStudios  /  Help Centre  /  Game Servers  /  Open the Right Firewall Ports for Your Game Server

Open the Right Firewall Ports for Your Game Server

Open game ports on your LochStudios KVM VPS. Check the portal Firewall tab, then UFW or firewalld, so players can connect.

Updated

Players reach a game server on your LochStudios KVM VPS at the IPv4 shown on that server in the portal, on the port the game process is listening on. Two layers can block that traffic:

  1. The Firewall tab on the VPS in the portal (an extra filter in front of the machine).
  2. The OS firewall on the VPS itself: UFW on Ubuntu or Debian, firewalld on AlmaLinux or Rocky Linux.

Open only the ports the game actually uses. Leave SSH (port 22) allowed so you can still log in.

Need a VPS first? See VPS. On a dedicated server, open a support ticket and we will walk through the filter with you.

Before you start

  1. Sign in at the portal, open the VPS service, and keep that page open. Copy the IPv4 from there. Do not guess a hostname.
  2. Connect with a sudo user, or root on a fresh box.

- Connect to your VPS via SSH from macOS or Linux
- Connect to your VPS via SSH from Windows

  1. Know the game port and protocol (TCP or UDP). Defaults are in the table at the end. Always confirm against that game's own docs if you changed the port.

If SSH from your computer will not connect, open the console on the same VPS service. That session does not need port 22 from your network.

Step 1: Check the Firewall tab in the portal

This is the filter in front of the VPS. It is not UFW or firewalld.

  1. Sign in at the portal and open the VPS.
  2. Open the Firewall tab.

No rules listed. We are not filtering at that layer. Player traffic can reach the VPS. Skip to the OS firewall below.

You already added Drop rules. Add an Accept rule for the game port, and keep an Accept for SSH (22, TCP) ahead of any Drop. Rules are evaluated in order.

Add a public game rule like this:

  • Action: Accept
  • Protocol: TCP or UDP (match the game)
  • Ports: the port or range (25565, or 2456-2458, or 27015,27016)
  • Sources: 0.0.0.0/0 so anyone can join. Pin a single IPv4 or a CIDR if only your group should connect.
  • Destinations: leave 0.0.0.0/0
  • Description: optional, for example Minecraft

Click Add rule. The change applies immediately.

Do not add a Drop for all traffic unless you have already allowed SSH and the game ports. A Drop-first layout can lock you out of SSH. If that happens, use the console on the VPS, or open a support ticket.

Unsure about an existing rule? Open a support ticket and we will check the list with you. Tell us the VPS service and the game port. Do not send the password in the ticket.

Step 2: Check the OS firewall

On Ubuntu or Debian:

sudo ufw status

On AlmaLinux, Rocky Linux, or similar:

sudo firewall-cmd --state

If UFW is inactive, or firewalld is not running, the OS is not blocking ports. You can still add the rules below before you turn the firewall on, so you do not lock yourself out later.

If you have never enabled UFW, follow Set up a UFW firewall on Ubuntu first. Allow SSH (22/tcp) before sudo ufw enable.

Step 3: Open ports with UFW (Ubuntu or Debian)

Replace PORT and PROTOCOL with the game's values (tcp or udp).

sudo ufw allow PORT/PROTOCOL

Minecraft (Java Edition):

sudo ufw allow 25565/tcp

Counter-Strike 2 (game port):

sudo ufw allow 27015/udp

CS2 often also wants the Steam range. If the server browser cannot see you, allow it:

sudo ufw allow 27015:27030/udp
sudo ufw allow 27015:27030/tcp

A port range (Valheim):

sudo ufw allow 2456:2458/udp

Confirm the rule is there:

sudo ufw status numbered

You should see the game port and, if UFW is active, Status: active.

Step 4: Open ports with firewalld (AlmaLinux or Rocky Linux)

A single port:

sudo firewall-cmd --permanent --add-port=PORT/PROTOCOL
sudo firewall-cmd --reload

Minecraft:

sudo firewall-cmd --permanent --add-port=25565/tcp
sudo firewall-cmd --reload

Counter-Strike 2:

sudo firewall-cmd --permanent --add-port=27015/udp
sudo firewall-cmd --reload

A port range (Valheim):

sudo firewall-cmd --permanent --add-port=2456-2458/udp
sudo firewall-cmd --reload

Confirm:

sudo firewall-cmd --list-all

The game port should appear under ports.

Step 5: Confirm the game process is listening

The firewall only helps if the server process is up and bound to that port.

sudo ss -tulnp

Look for the game binary and the expected port. No listener means players cannot connect, even with every rule open. Start the server first (see the game articles at the end).

Step 6: Test from another machine

Use the IPv4 from the VPS in the portal. Do not test only from the VPS itself.

TCP (Minecraft, for example):

nc -zv 203.0.113.45 25565

Swap in your real IPv4 and port. A reachable TCP port prints succeeded (or open).

UDP is connectionless, so nc -zvu is a weak test. The real check is to join from the game client.

The strongest test is always a player joining with your-ipv4:port.

Common default ports

Always confirm in that game's documentation if you changed the listen port.

GamePortProtocol
Minecraft (Java)25565TCP
Minecraft (Bedrock)19132UDP
Counter-Strike 227015 (often 27015-27030)UDP (and TCP for some Steam services)
RUST28015 (RCON 28016)UDP (RCON TCP)
Valheim2456-2458UDP
ARK: Survival Evolved27015, 27016UDP
Team Fortress 227015UDP
Left 4 Dead 227015UDP
Palworld8211UDP

Close a port you no longer need

UFW:

sudo ufw delete allow PORT/PROTOCOL

Or delete by number from sudo ufw status numbered:

sudo ufw delete 5

firewalld:

sudo firewall-cmd --permanent --remove-port=PORT/PROTOCOL
sudo firewall-cmd --reload

On the Firewall tab in the portal, use Remove on that rule. The change applies immediately. Do not remove the SSH Accept if you also have a Drop that would catch port 22.

If players still cannot join

The port test works, but nobody can join. The process is probably bound to the wrong port, or only to 127.0.0.1. Check sudo ss -tulnp and the game config (server-port, -port, and so on).

The port test fails, and UFW or firewalld already lists the port. Open the Firewall tab on the VPS. A Drop rule higher in the list will stop the traffic before it reaches the OS. Add or reorder an Accept for that port, or open a support ticket.

You are hitting the wrong address. Use the IPv4 on the VPS in the portal. A domain only works if its A record points at that IPv4 in Domains → the domain → DNS.

You enabled UFW and lost SSH. Open the console on the VPS in the portal, then:

sudo ufw allow 22/tcp
sudo ufw status verbose

Still locked out? Open a support ticket. Tell us the VPS service and what you changed.

What to do next

A step is unclear? Open a support ticket and we will walk through the VPS and the game port with you.


Was this article helpful?

← Back to Game Servers