Secure client portal

Oxide / uMod Plugins

RCON and Rust+ Ports (Safe Admin Defaults)

Set `rcon.web`, strong passwords, and keep RCON/Rust+ off the open internet when possible.

Safe defaults

  • Change RCON_PASS immediately.
  • Treat 28016/TCP and 28082 as admin surfaces — not community ports.
  • Prefer Pterodactyl console for day-to-day commands.
  • If Rust+ is unused, don’t publish APP_PORT.

Weak RCON passwords get brute-forced on public IPs.



Frequently Asked Questions

Egg defaults?

RCON_PORT 28016, APP_PORT 28082, rcon.web true in startup.

Password?

Set a strong RCON_PASS — never leave CHANGEME.

Public RCON?

Avoid. Prefer panel console; allowlist if a tool requires RCON.


Need help?

If you are stuck after following this guide, open a ticket from the Chapter22 client area with the exact error, the port or DNS change you made, and whether the service listens locally (ss / Resource Monitor) but fails externally.

Build the server. Grow the community. Start your next chapter.

Chapter22 RUST hosting

Deploy a managed RUST server.

Chapter22 RUST hosting is Oxide-capable on Pterodactyl—Scrap, Raid, and Wipe tiers in Ogden, UT.