Minecraft Server Port Forwarding Guide
Running a Minecraft server from your own PC means friends can't connect until you open a path through your router. Here's exactly how — and what to do when your ISP makes it impossible.
TL;DR
- Give your PC a static local IP (reserve it in router DHCP settings)
- Log into your router, find Port Forwarding / NAT / Virtual Server
- Forward port 25565 TCP (and UDP) to that static IP
- Test with canyouseeme.org from outside your WiFi
- If it won't work at all, you're probably behind CGNAT — see below
Step by step
1.Find your PC's local IP and make it static
Open a command prompt and run ipconfig (Windows) or ip addr (Linux/Mac) to find your local IP — something like 192.168.1.50. Routers hand these out dynamically by default, so if yours changes, your forwarding rule silently points at the wrong device. In your router's DHCP settings, reserve that IP for your PC's MAC address so it never moves.
2.Log into your router's admin page
Type your router's gateway IP into a browser — usually 192.168.0.1 or 192.168.1.1 (ipconfig/ip route shows it as 'Default Gateway'). Log in with the admin credentials, which are either on a sticker on the router itself or still the factory default if nobody's changed them.
3.Find port forwarding (sometimes called 'virtual server' or 'NAT')
Every router brand names and places this differently — look under Advanced, NAT, Firewall or Virtual Server. You're looking for a form that asks for an external port, internal port, internal IP, and protocol (TCP/UDP).
4.Add the rule: port 25565, your PC's static IP
External port 25565, internal port 25565, internal IP = the static local IP from step 1, protocol TCP (and UDP if the form doesn't let you pick 'both'). Save and let the router apply the change — some models need a reboot.
5.Start the server and test from outside your network
Start your Minecraft server, then test with a site like canyouseeme.org (enter 25565) from a phone on mobile data, not your home WiFi — testing from inside your own network can show false positives. If it reports open, give friends your public IP (whatismyip.com) plus the port if you changed it from default.
6.Optional: set up dynamic DNS so the address doesn't change
Services like No-IP or DuckDNS give you a free hostname (yourserver.ddns.net) that auto-updates whenever your public IP changes, so friends can always connect the same way instead of you re-sharing a new IP every few days.
When it just won't work: CGNAT
Every step above can be done perfectly and the server still won't be reachable, because many ISPs — especially on mobile/5G home internet and some cable plans — put customers behind Carrier-Grade NAT. That means your router's "public" IP isn't actually public; it's shared with hundreds of other households behind one real IP at the ISP. There's no port to forward on your end at all — the problem is upstream.
Check this quickly: compare your router's WAN/Internet IP (shown on its status page) against what whatismyip.com reports from a browser. If they don't match, you're behind CGNAT. The fix is either calling your ISP to ask for a public IP (some offer it free, some charge a small monthly fee, some refuse entirely), or skipping the whole problem by hosting the server somewhere that already has a public IP — which is most of what dedicated game hosting actually is.
FAQ
What port does Minecraft Java Edition use?+
25565/TCP by default, set by server-port in server.properties. Bedrock Edition uses 19132/UDP instead. If you run both on one machine, they need different ports — Bedrock can't share 25565 with Java.
Why can't I port forward even though I followed every step?+
The most common reason is CGNAT (Carrier-Grade NAT) — your ISP shares one public IP across many households, so there's no port on your home connection to forward in the first place. Check whether your router's WAN IP matches what whatismyip.com shows you; if they're different, you're behind CGNAT and no router setting fixes it. Call your ISP and ask for a public/static IP, or skip the whole problem with hosting.
Do I need both TCP and UDP forwarded?+
For Java Edition, TCP is what matters — that's the actual game connection. Query (if enabled) uses UDP on the same port number. Forwarding both doesn't hurt, so most guides just say 'forward 25565 TCP/UDP' and move on.
Will my friends' address stop working if my IP changes?+
Yes — most home internet connections get a new public IP periodically (a router reboot, an ISP maintenance window, or just time). Anyone who saved your old IP will suddenly get 'Can't connect to server.' Dynamic DNS (see below) gives you a fixed hostname so this doesn't matter, but it's one more thing to set up and maintain.
Is port forwarding a security risk?+
You're opening a path from the internet straight to a device on your home network, running server software that's had real vulnerabilities (the 2021 Log4Shell bug was exploitable through a Minecraft chat message). Keep the server jar updated, and understand that anyone who can reach port 25565 can see your home IP address in router logs and connection metadata.
Skip the router entirely
CoalHost servers already have a public IP and a ready-made connect address — no port forwarding, no CGNAT roulette, no re-sharing your IP every time it changes.
View Minecraft Hosting →