Minecraft Java Edition listens on 25565/TCP by default. Query and RCON are optional extras — treat RCON as an admin secret, not a public service.
Port table
| Service | Port | Protocol | Public? |
|---|---|---|---|
| Game (Java) | 25565 (or panel allocation) | TCP | Yes — players |
| Query (optional) | Often same as game | UDP | Optional |
| RCON | 25575 (default) | TCP | No — private / allowlisted |
Managed hosting (Chapter22)
- Open panel.chapter22hosting.com and select the Minecraft server.
- Copy the primary allocation (
IP:port) from the console page. - Share that address with players — no home-router port forward required.
- Leave RCON disabled unless you have a specific tool that needs it.
The allocated port may differ from 25565 when the node remaps — always copy from Pterodactyl.
DIY / self-hosted readers
If you run Java on your own VPS elsewhere:
- Confirm the process listens on
0.0.0.0:25565(not only127.0.0.1). - Allow 25565/tcp in UFW or firewalld — see Linux ports.
- Mirror the rule in any cloud security group.
- Do not publish 25575 unless you understand the risk.
server.properties knobs
server-port=25565
enable-query=false
enable-rcon=false
SRV records
Players can type a hostname if you publish _minecraft._tcp SRV to your host and port. See DNS basics.
Verify
- Local:
ss -tlnp | grep 25565or the Pterodactyl network view. - External: a friend joins via Direct Connect with the panel IP:port.
Related guides
- How to Join Your Chapter22 Minecraft Server
- Can't Connect to Minecraft Server (Checklist)
- How to Open Ports on a Linux VPS (UFW, firewalld, iptables)
- VPS Port Forwarding Explained (Firewall vs Home Router)
- DDoS Protection Basics for Game Servers
Frequently Asked Questions
Do I need UDP 25565?
Java gameplay is primarily TCP 25565. Some query tools also use UDP on the same port; open UDP only if you rely on those tools.
Should RCON be public?
No. Keep RCON (default 25575/TCP) private or allowlisted. Prefer the Pterodactyl console.
Managed hosting vs DIY?
On Chapter22 Minecraft hosting, ports are allocated in the panel. DIY VPS readers still need OS firewall rules.
Need help?
If you are stuck after following this guide, open a ticket from the Chapter22 client area with the exact error, the port or DNS change you made, and whether the service listens locally (ss / Resource Monitor) but fails externally.
Build the server. Grow the community. Start your next chapter.
