How to host a Minecraft server when port forwarding won't work
Quick answer
A Minecraft server needs friends to reach a public IP on port 25565 (Java) or UDP 19132 (Bedrock). If port forwarding won't work — because your ISP uses CGNAT, you're double-NAT'd, or the router config won't cooperate — you have a few options: a free tunnel tool like playit.gg or ngrok (shared/rotating address, third party in the path), or routing a dedicated public IP to the server over an outbound tunnel (a fixed IP you control, any port, no router changes). All of these work behind CGNAT because the connection is outbound.
You've got the Minecraft server running on a PC at home, it works fine on your own network — but friends outside the house can't connect. This is one of the most common self-hosting walls, and it usually comes down to one of two things.
Why friends can't connect
For someone to join your server, their game has to reach your public IP on the server's port (TCP 25565 for Java, UDP 19132 for Bedrock). Two things commonly block that:
- You're behind CGNAT. Many ISPs (especially mobile, Starlink, and a lot of residential broadband) share one public IP across many customers. You don't have a public IP of your own to forward a port on, so port forwarding silently does nothing no matter how you configure the router. See how to check if you're behind CGNAT.
- Port forwarding won't cooperate. Even with a real public IP, port forwarding trips people up constantly: the setting is buried or mislabeled, you forwarded to the wrong LAN IP, TCP vs UDP is wrong, the address changes because there's no static DHCP reservation, or you're double-NAT'd behind the ISP's gateway and your own router. "I followed the guide and it still doesn't work" is a rite of passage here.
The options
All of the approaches below work behind CGNAT and without touching your router, because the server makes an outbound connection rather than accepting an inbound one. They differ in what you get and what's in the path.
Free tunnel tools (playit.gg, ngrok, etc.)
Purpose-built tunnel services can expose a Minecraft server for free, with no port forwarding, and they work behind CGNAT. They're the quickest way to get friends connected. The usual tradeoffs: you typically get a shared or rotating address rather than a stable IP you own (so the address your friends use can change), and the tunnel provider sits in the connection path. For a casual, get-friends-on-tonight setup, that's often fine.
A managed Minecraft host
Services like Apex or Shockbyte run the server for you on their hardware for a monthly fee. Easiest if you don't want to run anything at home — but you're paying for their hardware and giving up the control (and specs-for-the-money) of running it on your own machine.
A dedicated routed public IP
If you want to keep running the server on your own hardware but need it reachable, you can route a dedicated public IP to the machine over an outbound WireGuard tunnel. Friends connect to that fixed IP on 25565 (or 19132) like any normal server. Because it's a real routed IP:
- Any port and protocol — Java (TCP 25565), Bedrock (UDP 19132), or a custom port; not limited to web traffic.
- A stable IP you control — the address doesn't rotate, so your server address stays put.
- Compatible with your own domain name (optional) — because the IP is fixed, you can point an A record at it so friends connect to
mc.yourdomain.cominstead of a bare IP (Java can use an SRV record to hide the port too). - No router changes — nothing to port-forward, works behind CGNAT and double-NAT.
- Nothing for friends to install — they just connect to the IP.
This is what Get Real IP does: your server opens the tunnel outbound, and a dedicated public IPv4 is routed to it.
Quick comparison
| Free tunnel (playit/ngrok) | Managed host | Get Real IP | |
|---|---|---|---|
| Run on your own hardware | ✓ | ✗ | ✓ |
| Stable IP you control | usually shared/rotating | ✓ (theirs) | ✓ |
| No router config | ✓ | ✓ | ✓ |
| Works behind CGNAT | ✓ | ✓ | ✓ |
| Third party in the path | yes | n/a (hosted) | no |
Pick based on what you want: fastest and free to get friends on tonight (a tunnel tool), hands-off hosting (a managed host), or your own hardware with a stable public IP on any port (a dedicated routed IP). All of them get you past CGNAT and around port forwarding.
