On a Windows VPS, public reachability almost always comes down to Windows Defender Firewall (and any cloud security group). Optional `netsh interface portproxy` is only for redirecting ports—not a substitute for allow rules.
Keep RDP (TCP 3389) working before you tighten the firewall. Prefer provider console access as a break-glass path.
Confirm the service is listening
In PowerShell (Admin):
Get-NetTCPConnection -State Listen | Sort-Object LocalPort | Format-Table -AutoSize
# specific port example:
Get-NetTCPConnection -LocalPort 30120 -ErrorAction SilentlyContinue
Get-NetUDPEndpoint -LocalPort 30120 -ErrorAction SilentlyContinue
Or use Resource Monitor → Network → Listening Ports.
If the process binds only to 127.0.0.1, remote clients will fail even with a perfect firewall rule.
Open an inbound port with Windows Defender Firewall (GUI)
- Open Windows Defender Firewall with Advanced Security.
- Select Inbound Rules → New Rule…
- Choose Port → Next.
- Select TCP or UDP, enter the port (for example
30120), Next. - Allow the connection, apply to Domain/Private/Public as required on a public VPS (often all profiles).
- Name it clearly:
FiveM 30120 TCP.
Repeat for the other protocol when the game needs both TCP and UDP.
Open ports with PowerShell
New-NetFirewallRule -DisplayName "FiveM 30120 TCP" -Direction Inbound -Protocol TCP -LocalPort 30120 -Action Allow
New-NetFirewallRule -DisplayName "FiveM 30120 UDP" -Direction Inbound -Protocol UDP -LocalPort 30120 -Action Allow
New-NetFirewallRule -DisplayName "HTTPS 443" -Direction Inbound -Protocol TCP -LocalPort 443 -Action Allow
Get-NetFirewallRule -DisplayName "*FiveM*" | Format-Table DisplayName, Enabled, Direction, Action
Allow the Remote Desktop group if needed:
Enable-NetFirewallRule -DisplayGroup "Remote Desktop"
When to use netsh portproxy
Use portproxy only if traffic must arrive on one port/IP and be handed to another local port (legacy apps, container quirks, or temporary redirects).
netsh interface portproxy add v4tov4 listenaddress=0.0.0.0 listenport=8080 connectaddress=127.0.0.1 connectport=80
netsh interface portproxy show all
You still need an inbound firewall rule on the *listen* port. Remove when finished:
netsh interface portproxy delete v4tov4 listenaddress=0.0.0.0 listenport=8080
Provider firewall / security groups
Mirror the same TCP/UDP allows in the VPS provider panel. Windows can be wide open locally and still black-hole traffic at the hypervisor edge.
Quick verification checklist
- Process listening on
0.0.0.0or the public IP. - Inbound firewall rule enabled for the correct protocol.
- Provider firewall allows the port.
- External client or TCP probe succeeds; for UDP, test with the real game client.
- Temporarily disable third-party AV packet filters if a vendor suite overrides Defender.
Common Windows VPS ports
| Service | Port | Notes |
|---|---|---|
| RDP | 3389/tcp | Restrict by IP when the panel allows |
| HTTP/HTTPS | 80/443 tcp | IIS / reverse proxies |
| FiveM | 30120 tcp+udp | txAdmin commonly 40120/tcp |
| File shares | 445/tcp | Do not expose to the internet |
Related guides
- VPS Port Forwarding Explained (Firewall vs Home Router)
- How to Open Ports on a Linux VPS (UFW, firewalld, iptables)
- How to SSH Into Your VPS (Windows, Mac, Linux)
- FiveM Ports Explained: 30120 TCP/UDP and txAdmin
Frequently Asked Questions
Is netsh portproxy the same as opening the firewall?
No. Firewall rules allow traffic into the OS. portproxy redirects a local listen port to another address/port—use it only when you intentionally need that redirect.
RDP stopped working after I enabled the firewall. How do I recover?
Use your provider’s console/VNC, enable the Remote Desktop firewall group, or add an inbound TCP 3389 rule, then reconnect.
Do I need router port forwarding on a Windows VPS?
Not when the VPS has a routed public IP. Open Windows Firewall (and the provider firewall). Home-router NAT applies to residential networks, not typical VPS networking.
Need help?
If you are stuck after following this guide, open a ticket from the Chapter22 client area with the exact error, the port or DNS change you made, and whether the service listens locally (ss / Resource Monitor) but fails externally.
Build the server. Grow the community. Start your next chapter.
