GameGrid
DayZ Server Ports and Firewall - visual guide

DayZ Server Ports and Firewall

Which UDP ports a GameGrid DayZ server uses, why the Steam query port is game port + 4, why BattlEye RCon is not reachable from outside, and the self-hosted equivalents.

The Ports Your Server Uses

GameGrid gives every server a block of 100 ports and assigns DayZ's four ports from it. The numbers below are offsets from your game port, which is shown on the Connect card of the Overview tab. The card shows only the game port; work the others out from this table.

PortProtocolUsed forOpen to the internet?
Game port (+0)UDPPlayers connect hereYes
+1Not usedNo
+2UDPOpened by the DayZ engine itselfYes
+3UDPBattlEye RCon, for the panel consoleNo, it only listens inside the host
+4UDPSteam query: the server browser, Favourites, the DZSA LauncherYes

So a server whose game port is 28000 answers the browser on 28004, and that is the number to use for Steam Favourites and DZSA's Server Check.

Why the Query Port Is Set for You

DayZ does not move its Steam query port when the game port changes. Left alone, every DayZ server on a machine would try to use the same default query port, and all but one would be missing from the server browser.

GameGrid writes steamQueryPort into serverDZ.cfg as your game port + 4 every time the server starts. If it is edited by hand, the next start puts it back. That is deliberate: a wrong query port is the most common reason a DayZ server "is online but not in the list".

BattlEye RCon Stays Inside the Host

BattlEye RCon is DayZ's remote console: kick, ban, messages and shutdown. GameGrid writes the RCon port, a generated password and a local-only address into the BattlEye configuration before each start, and does not open the RCon port in the firewall.

You use RCon through GameGrid instead:

Third-party RCon tools that connect over the internet (DaRT, mobile RCon apps and similar) cannot reach it. The reason is security: BattlEye RCon sends its password unencrypted and gives full kick, ban and shutdown control, so an open RCon port is an easy way for someone else to take over a server.

Changing Ports

Ports are assigned when the server is created and are not customer-editable. Each server's block is its own, so a hand-picked number would collide with another server on the same machine.

Firewall rules are created and removed by GameGrid. You do not need to configure Windows Firewall, router port forwarding or anything else.

If you have a specific need for a particular port, open a support ticket.

Checking the Ports Work

  • Online in the status bar means the server answered a Steam query on its query port.
  • A player joining with Direct Connect proves the game port.
  • DZSA's Server Check with your IP and query port shows what the outside world sees.

Do not use a generic online "port checker" on these ports. They test TCP, and DayZ's ports are UDP: a healthy DayZ server looks "closed" to them.

Self-Hosted Equivalents (Not on GameGrid)

If you run DayZ on your own machine, the usual layout is:

PortSetting
2302 UDPGame port, -port=2302 on the command line
2304 UDPOpened by the engine (game port + 2)
A free UDP port such as 2306RConPort in battleye/BEServer_x64.cfg. Since DayZ 1.13 it must be set and must not be the game port or game port + 2
27016 or 2305 UDPsteamQueryPort in serverDZ.cfg. Set it explicitly

Forward the game, engine and query ports as UDP on your router and allow them in Windows Firewall. Only forward the RCon port if you really need a remote RCon tool, and use a long random password if you do.

On GameGrid none of this is needed.