RUST listens on server.port (wiki 28015/UDP), a separate query UDP port, and rcon.port (commonly 28016/TCP). Chapter22 egg 35 wires these via Startup variables.
Port table
| Service | Port | Protocol | Public? |
|---|---|---|---|
Game (server.port) | Primary allocation (wiki 28015) | UDP | Yes — players |
Query (server.queryport) | Egg default 28017 | UDP | Yes — server browser |
RCON (rcon.port) | Egg default 28016 | TCP | No — private |
Rust+ app (app.port) | Egg default 28082 | TCP | Optional / private |
Managed hosting (Chapter22)
- Open Pterodactyl → your RUST server → Network / Startup.
- Note
SERVER_PORT(game),QUERY_PORT,RCON_PORT, andAPP_PORTallocations. - Players connect with game IP:port (
client.connect); favorites/list need the query port reachable. - Keep RCON and Rust+ off the open internet when possible.
Node may remap away from 28015/28016/28017 — always copy live allocations. Tip: Egg 35 FRAMEWORK supports vanilla|carbon|oxide (Oxide-capable).
DIY / self-hosted readers
DIY readers: allow game+query UDP and keep RCON allowlisted. See Linux ports and port forwarding explained.
Egg verification (Chapter22)
Egg 35 (Rust): SERVER_PORT game; QUERY_PORT default 28017; RCON_PORT 28016; APP_PORT 28082 (Rust+); FRAMEWORK vanilla|carbon|oxide (Oxide-capable). Wiki 28015/16/17 not pre-seeded on node — remapped at provision.
Facepunch query note
When query is unset, Facepunch uses 1 + max(server.port, rcon.port). Chapter22 sets QUERY_PORT explicitly (default 28017).
Related guides
- How to Join / Connect
- Not Showing in List
- How to Open Ports on a Linux VPS (UFW, firewalld, iptables)
- VPS Port Forwarding Explained (Firewall vs Home Router)
- DDoS Protection Basics for Game Servers
Frequently Asked Questions
What is server.port?
Game traffic (wiki default 28015/UDP). On Chapter22 it is the primary SERVER_PORT allocation — copy from Pterodactyl.
Query port formula?
Facepunch: when unset, query is 1 + max(server.port, rcon.port). Egg 35 sets QUERY_PORT default 28017 and RCON_PORT 28016 explicitly.
Is RCON public?
No. Keep rcon.port (default 28016/TCP) private; prefer the panel console.
Need help?
If you are stuck after following this guide, open a ticket from the Chapter22 client area with the exact error, the port or DNS change you made, and whether the service listens locally (ss / Resource Monitor) but fails externally.
Build the server. Grow the community. Start your next chapter.
