The short answer
"Players cannot connect" in a cloud-hosted Mirror game is almost always one of five things: the wrong protocol (TCP opened for a UDP transport), the wrong port, a server bound to localhost, a firewall rule on the machine or in the cloud account, or a client pointed at the wrong address. This checklist walks them in the order that finds the problem fastest.
Which port and protocol
| Mirror transport | Protocol | Common default | Open in the firewall |
|---|---|---|---|
| KCP | UDP | 7777 | UDP 7777 |
| Telepathy | TCP | as configured | TCP on that port |
| SimpleWeb (WebSocket) | TCP | 7778 | TCP 7778, and put TLS in front for wss:// |
| Multiplex (several at once) | each | each | one rule per transport |
The numbers come from the Mirror documentation and are defaults you can change. The rule is simple: open exactly the pairs your server opens, nothing broader.
The checklist
- Confirm which transport you useOpen the NetworkManager and read the transport component. KCP means UDP, Telepathy means TCP, SimpleWeb means WebSocket over TCP.
- Pick one fixed port per transportWrite the port and protocol down. Do not let the port be chosen randomly at startup.
- Bind to all interfacesMake sure the server listens on
0.0.0.0, not127.0.0.1. Confirm on the machine withss -lunpfor UDP orss -ltnpfor TCP. - Open the port in every firewall layerAllow the exact protocol and port inbound on the operating system firewall and in any cloud security group or network ACL. UDP and TCP are separate rules.
- Test from outside the networkFrom another network, use a UDP-capable test or a real client. A successful TCP connect proves nothing about a UDP game.
- Add a health reply and join probeAnswer a small request with a known string so you can prove a player could really join, not just that a socket is open.
- Retest after every changeRe-run the outside test after rebuilding, changing a port or moving regions.
If your server is not Mirror at all
A Unity server with its own raw TCP or UDP protocol uses the same port and protocol rules, but it is not a Mirror game, and declaring Mirror for it is misleading. Declare it as Custom native TCP/UDP (direct): players reach the server's public IP address and port directly, with no gateway, and you supply a game-level join probe, because an open port never proves a player could join. See the manifest guide.
What NetCraftGames does for you
On NetCraftGames you declare the port and protocol pairs in your manifest. The platform controls the firewall on its side and never opens broad port ranges, and a TCP-only probe cannot certify a UDP game. You do not edit cloud security groups. You still must bind to 0.0.0.0 and answer a health check and join probe, which are part of the connection config.
Troubleshooting table
| Symptom | Most likely cause | Check |
|---|---|---|
| Works on LAN, not from the internet | Firewall or security group | Allow the right protocol and port inbound |
| TCP test succeeds, game cannot join | Transport is UDP | Use a UDP test, not telnet |
| Port closed on the server itself | Not listening or bound to localhost | ss -lunp or ss -ltnp |
| WebGL client fails, native works | WebSocket needs TLS from an HTTPS page | Serve wss:// through a TLS endpoint |
| Fails only on some networks | NAT or carrier restrictions | Test on another network; UDP can be blocked |
Frequently asked questions
Which ports does a Mirror server need open?
Only the ports your transport actually listens on, with the matching protocol. KCP uses UDP, with 7777 as its common default. Telepathy uses TCP. SimpleWeb carries WebSocket over TCP and commonly defaults to 7778. Open exactly those pairs and nothing broader, and remember UDP and TCP are separate firewall rules.
Sources
- Mirror documentation: Transports, accessed October 3, 2026
- Mirror documentation: KCP Transport, accessed October 3, 2026