Get Real IP

How to host a Minecraft server when port forwarding won't work

Quick answer

A Minecraft server needs friends to reach a public IP on port 25565 (Java) or UDP 19132 (Bedrock). If port forwarding won't work — because your ISP uses CGNAT, you're double-NAT'd, or the router config won't cooperate — you have a few options: a free tunnel tool like playit.gg or ngrok (shared/rotating address, third party in the path), or routing a dedicated public IP to the server over an outbound tunnel (a fixed IP you control, any port, no router changes). All of these work behind CGNAT because the connection is outbound.

You've got the Minecraft server running on a PC at home, it works fine on your own network — but friends outside the house can't connect. This is one of the most common self-hosting walls, and it usually comes down to one of two things.

Why friends can't connect

For someone to join your server, their game has to reach your public IP on the server's port (TCP 25565 for Java, UDP 19132 for Bedrock). Two things commonly block that:

The options

All of the approaches below work behind CGNAT and without touching your router, because the server makes an outbound connection rather than accepting an inbound one. They differ in what you get and what's in the path.

Free tunnel tools (playit.gg, ngrok, etc.)

Purpose-built tunnel services can expose a Minecraft server for free, with no port forwarding, and they work behind CGNAT. They're the quickest way to get friends connected. The usual tradeoffs: you typically get a shared or rotating address rather than a stable IP you own (so the address your friends use can change), and the tunnel provider sits in the connection path. For a casual, get-friends-on-tonight setup, that's often fine.

A managed Minecraft host

Services like Apex or Shockbyte run the server for you on their hardware for a monthly fee. Easiest if you don't want to run anything at home — but you're paying for their hardware and giving up the control (and specs-for-the-money) of running it on your own machine.

A dedicated routed public IP

If you want to keep running the server on your own hardware but need it reachable, you can route a dedicated public IP to the machine over an outbound WireGuard tunnel. Friends connect to that fixed IP on 25565 (or 19132) like any normal server. Because it's a real routed IP:

This is what Get Real IP does: your server opens the tunnel outbound, and a dedicated public IPv4 is routed to it.

Quick comparison

Free tunnel (playit/ngrok)Managed hostGet Real IP
Run on your own hardware✓✗✓
Stable IP you controlusually shared/rotating✓ (theirs)✓
No router config✓✓✓
Works behind CGNAT✓✓✓
Third party in the pathyesn/a (hosted)no

Pick based on what you want: fastest and free to get friends on tonight (a tunnel tool), hands-off hosting (a managed host), or your own hardware with a stable public IP on any port (a dedicated routed IP). All of them get you past CGNAT and around port forwarding.

Frequently asked questions

Why can friends not connect to my Minecraft server?

Two common reasons. Either your ISP puts you behind CGNAT, so you have no public IP to forward a port on — nothing you do on the router will help. Or you do have a public IP but the port forward isn't working: the router setting is wrong or confusing, you're double-NAT'd behind the ISP's gateway, or the wrong LAN IP/protocol is set. In both cases friends can't reach port 25565 on your connection.

What port does a Minecraft server use?

Java Edition uses TCP port 25565 by default. Bedrock Edition uses UDP 19132. Friends connect to your public IP (and port, if non-default). Because these are raw TCP/UDP ports — not web traffic — HTTP-only solutions like Cloudflare Tunnel can't carry them.

Do I have to set up port forwarding?

Only if you're exposing the server through your own router's public IP. If port forwarding won't work — because of CGNAT, double-NAT, or a router you can't get configured — you can instead route a public IP to the server over an outbound tunnel, which needs no router changes at all.

Are there free ways to do this?

Yes. Tunnel tools like playit.gg and ngrok can expose a Minecraft server without port forwarding, and they work behind CGNAT too, since the tunnel is outbound. The tradeoffs are usually a shared or rotating address rather than a stable dedicated IP, and a third party in the connection path. A dedicated routed IP (like Get Real IP) gives you a fixed IP you control on any port, with no third-party relay.

Will my friends need to install anything?

No. They just connect to your public IP and port like any other server. Only the machine running the server needs the tunnel configured.

Want a dedicated static IP in minutes?

Get Real IP delivers a dedicated static public IPv4 to your server, router, or laptop over an encrypted WireGuard tunnel — any protocol, any port, works behind CGNAT. $8/mo, no contract.

Start your free trial

7 days free · Cancel anytime

Related guides

Updated September 8, 2026