# Mirror server on the cloud: ports and firewall checklist

> Open the one port your Mirror transport really uses, with the right protocol: UDP for KCP, TCP for Telepathy, TCP with TLS for browser WebSocket. Bind the server to 0.0.0.0, allow that port in the machine's firewall and cloud rules, and test from outside.

*NetCraftGames (NCG) by Charging Bull Software. Last updated: 2026-10-03. Canonical page: https://netcraftgames.com/guides/mirror-server-ports-firewall-checklist/*

## The short answer

"Players cannot connect" in a cloud-hosted Mirror game is almost always one of five things: the wrong protocol (TCP opened for a UDP transport), the wrong port, a server bound to `localhost`, a firewall rule on the machine or in the cloud account, or a client pointed at the wrong address. This checklist walks them in the order that finds the problem fastest.

## Which port and protocol

| Mirror transport | Protocol | Common default | Open in the firewall |
| --- | --- | --- | --- |
| KCP | UDP | 7777 | UDP 7777 |
| Telepathy | TCP | as configured | TCP on that port |
| SimpleWeb (WebSocket) | TCP | 7778 | TCP 7778, and put TLS in front for `wss://` |
| Multiplex (several at once) | each | each | one rule per transport |

The numbers come from the Mirror documentation and are defaults you can change. The rule is simple: open exactly the pairs your server opens, nothing broader.

## The checklist


1. **Confirm which transport you use.** Open the NetworkManager and read the transport component. KCP means UDP, Telepathy means TCP, SimpleWeb means WebSocket over TCP.
2. **Pick one fixed port per transport.** Write the port and protocol down. Do not let the port be chosen randomly at startup.
3. **Bind to all interfaces.** Make sure the server listens on `0.0.0.0`, not `127.0.0.1`. Confirm on the machine with `ss -lunp` for UDP or `ss -ltnp` for TCP.
4. **Open the port in every firewall layer.** Allow the exact protocol and port inbound on the operating system firewall and in any cloud security group or network ACL. UDP and TCP are separate rules.
5. **Test from outside the network.** From another network, use a UDP-capable test or a real client. A successful TCP connect proves nothing about a UDP game.
6. **Add a health reply and join probe.** Answer a small request with a known string so you can prove a player could really join, not just that a socket is open.
7. **Retest after every change.** Re-run the outside test after rebuilding, changing a port or moving regions.


## If your server is not Mirror at all

A Unity server with its own raw TCP or UDP protocol uses the same port and protocol rules, but it is not a Mirror game, and declaring Mirror for it is misleading. Declare it as Custom native TCP/UDP (direct): players reach the server's public IP address and port directly, with no gateway, and you supply a game-level join probe, because an open port never proves a player could join. See the [manifest guide](https://netcraftgames.com/guides/connection-config-file-contents/).

## What NetCraftGames does for you

On NetCraftGames you declare the port and protocol pairs in your manifest. The platform controls the firewall on its side and never opens broad port ranges, and a TCP-only probe cannot certify a UDP game. You do not edit cloud security groups. You still must bind to `0.0.0.0` and answer a health check and join probe, which are part of the [connection config](https://netcraftgames.com/guides/connection-config-file-contents/).

## Troubleshooting table

| Symptom | Most likely cause | Check |
| --- | --- | --- |
| Works on LAN, not from the internet | Firewall or security group | Allow the right protocol and port inbound |
| TCP test succeeds, game cannot join | Transport is UDP | Use a UDP test, not `telnet` |
| Port closed on the server itself | Not listening or bound to localhost | `ss -lunp` or `ss -ltnp` |
| WebGL client fails, native works | WebSocket needs TLS from an HTTPS page | Serve `wss://` through a TLS endpoint |
| Fails only on some networks | NAT or carrier restrictions | Test on another network; UDP can be blocked |

## Frequently asked questions


### Which ports does a Mirror server need open?

Only the ports your transport actually listens on, with the matching protocol. KCP uses UDP, with 7777 as its common default. Telepathy uses TCP. SimpleWeb carries WebSocket over TCP and commonly defaults to 7778. Open exactly those pairs and nothing broader, and remember UDP and TCP are separate firewall rules.

## Sources

- [Mirror documentation: Transports](https://mirror-networking.gitbook.io/docs/manual/transports), accessed 2026-10-03
- [Mirror documentation: KCP Transport](https://mirror-networking.gitbook.io/docs/manual/transports/kcp-transport), accessed 2026-10-03

## Related pages

- [Hosting a Unity Mirror dedicated server](https://netcraftgames.com/engines/unity-mirror/): How to host a Unity Mirror dedicated server on NetCraftGames: Linux Server build, KCP or Telepathy ports, health and join probes, and the honest gaps.
- [How to build a Linux dedicated server from Unity](https://netcraftgames.com/guides/build-linux-dedicated-server-unity/): Step by step: build a headless Linux dedicated server from Unity 6 with Build Profiles, bind it correctly, test it and pack it for hosting.
- [What a connection config file must contain](https://netcraftgames.com/guides/connection-config-file-contents/): What a deployment manifest and a player connection config must contain for a hosted multiplayer server, with a real example and the rules that cause rejections.
