
DayZ Server Ports and Firewall
Which UDP ports a GameGrid DayZ server uses, why the Steam query port is game port + 4, why BattlEye RCon is not reachable from outside, and the self-hosted equivalents.
The Ports Your Server Uses
GameGrid gives every server a block of 100 ports and assigns DayZ's four ports from it. The numbers below are offsets from your game port, which is shown on the Connect card of the Overview tab. The card shows only the game port; work the others out from this table.
| Port | Protocol | Used for | Open to the internet? |
|---|---|---|---|
| Game port (+0) | UDP | Players connect here | Yes |
| +1 | Not used | No | |
| +2 | UDP | Opened by the DayZ engine itself | Yes |
| +3 | UDP | BattlEye RCon, for the panel console | No, it only listens inside the host |
| +4 | UDP | Steam query: the server browser, Favourites, the DZSA Launcher | Yes |
So a server whose game port is 28000 answers the browser on 28004, and that is the number to use for Steam Favourites and DZSA's Server Check.
Why the Query Port Is Set for You
DayZ does not move its Steam query port when the game port changes. Left alone, every DayZ server on a machine would try to use the same default query port, and all but one would be missing from the server browser.
GameGrid writes steamQueryPort into serverDZ.cfg as your game port + 4 every time the server starts. If it is edited by hand, the next start puts it back. That is deliberate: a wrong query port is the most common reason a DayZ server "is online but not in the list".
BattlEye RCon Stays Inside the Host
BattlEye RCon is DayZ's remote console: kick, ban, messages and shutdown. GameGrid writes the RCon port, a generated password and a local-only address into the BattlEye configuration before each start, and does not open the RCon port in the firewall.
You use RCon through GameGrid instead:
- the Console tab, see BattlEye RCon and the Console Tab;
- the Command Manager on the Event Manager page, for scheduled messages.
Third-party RCon tools that connect over the internet (DaRT, mobile RCon apps and similar) cannot reach it. The reason is security: BattlEye RCon sends its password unencrypted and gives full kick, ban and shutdown control, so an open RCon port is an easy way for someone else to take over a server.
Changing Ports
Ports are assigned when the server is created and are not customer-editable. Each server's block is its own, so a hand-picked number would collide with another server on the same machine.
Firewall rules are created and removed by GameGrid. You do not need to configure Windows Firewall, router port forwarding or anything else.
If you have a specific need for a particular port, open a support ticket.
Checking the Ports Work
- Online in the status bar means the server answered a Steam query on its query port.
- A player joining with Direct Connect proves the game port.
- DZSA's Server Check with your IP and query port shows what the outside world sees.
Do not use a generic online "port checker" on these ports. They test TCP, and DayZ's ports are UDP: a healthy DayZ server looks "closed" to them.
Self-Hosted Equivalents (Not on GameGrid)
If you run DayZ on your own machine, the usual layout is:
| Port | Setting |
|---|---|
| 2302 UDP | Game port, -port=2302 on the command line |
| 2304 UDP | Opened by the engine (game port + 2) |
| A free UDP port such as 2306 | RConPort in battleye/BEServer_x64.cfg. Since DayZ 1.13 it must be set and must not be the game port or game port + 2 |
| 27016 or 2305 UDP | steamQueryPort in serverDZ.cfg. Set it explicitly |
Forward the game, engine and query ports as UDP on your router and allow them in Windows Firewall. Only forward the RCon port if you really need a remote RCon tool, and use a long random password if you do.
On GameGrid none of this is needed.
