Skip to content

Ports

Port On Reachable from For
8080/tcp Controller Your browsers and API clients Web UI and REST API (HTTPS)
8443/tcp Controller Every Node Agent sessions (mutual TLS)
8444/tcp Controller Every new Node, while it enrolls Enrollment (TLS)
25565/tcp (network port) The proxy’s Node Players Joining the network
25565–25664/tcp (game port range) Every Node The proxy’s Node; players, for servers joined directly Servers’ game ports

Nodes need no other inbound ports: their Agents connect out to the Controller.

Change the ports with the Controller’s -listen, -agent-listen, -enroll-listen and -game-port-range flags, and the network’s port on the Network page.