A server nobody can find and a server nobody can join look identical from the outside: an empty listing. They are almost never the same fault, and the difference is usually one port.
Two ports doing two different jobs
A game server listens on at least two numbers, and they are not interchangeable.
The game port carries the connection. When a player clicks Join, their client opens a conversation on this port and everything that follows — position updates, chat, the whole session — travels through it. Close it and nobody gets in.
The query port answers questions about the server without joining it. A server browser, a monitoring tool or a directory like this one sends a small packet asking "who are you, what map, how many players", and the reply comes back on this port. Close it and the server works perfectly for anyone who already knows the address, and is invisible to everyone who does not.
That asymmetry is the whole reason this article exists. A closed query port is silent. You can connect to your own server, your friends can connect, the logs look healthy, and meanwhile every list shows you offline.
Which games use which
There is no standard, which is the annoying part.
| Game | Game port | Query port |
|---|---|---|
| Counter-Strike 2, CS:GO | 27015 | 27015 (same) |
| Team Fortress 2, Garry's Mod | 27015 | 27015 (same) |
| Minecraft (Java) | 25565 | 25565 (same) |
| Rust | 28015 | 28016 |
| ARK: Survival Evolved | 7777 | 27015 |
| Valheim | 2456 | 2457 |
| Squad | 7787 | 27165 |
| 7 Days to Die | 26900 | 26900 (same) |
| FiveM | 30120 | 30120 (same) |
The Source family mostly shares one port for both, which is why operators coming from Counter-Strike are the ones most often caught out when they move to something else. ARK is the classic trap: the game port is 7777 and the query port is a Valve-standard 27015 that has nothing to do with it, and opening only the first produces a server that works and cannot be found.
Valheim and Squad follow the "game port plus one" or "some unrelated number" convention respectively, and both are documented only in places you have to go looking for.
Diagnosing it in two minutes
The test that separates the two failures is direct connection.
If you can connect by IP and port but no list shows the server, the query port is the problem. The game port is demonstrably open, because you just used it. Check the firewall for the query port specifically, check that it is UDP and not only TCP, and check that your host's control panel has not silently mapped it somewhere else.
If no list shows the server and you cannot connect either, the game port is closed too, or the server is not actually running, or the address you are testing is not the address the world sees. That last one catches people behind NAT constantly.
If some lists show it and others do not, this is usually not a port at all. It is more often a query rate limit dropping some clients, or a tool that has not been updated for the challenge-response change in the Valve query protocol.
UDP, and why "the port is open" is often wrong
Almost every game query protocol runs over UDP. Almost every firewall tutorial you find opens TCP, because the web is TCP and most examples are written about web servers.
A rule that opens 27015/TCP and not 27015/UDP will pass every "is the port open" check you run in a browser and block every single query. Online port checkers are overwhelmingly TCP-only for the same reason, so they will cheerfully report your query port as open while nothing can reach it.
If you take one thing from this: check the protocol, not just the number. ufw allow 27015/udp and ufw allow 27015/tcp are different rules and you probably want both, because some games use TCP for RCON on a neighbouring port.
Behind NAT, and behind a host
Two situations produce the same symptom for different reasons.
Home hosting. Your router has one public address and your server has a private one. A port forward maps the public port to the private machine. Forward the game port and forget the query port, and you have the invisible server described above. Both need forwarding, both need to be UDP, and both need to point at a machine whose local address does not change — a DHCP lease that rotates will break the forward silently a week later. If you are considering this at all, the tradeoffs against renting are worth reading first.
Rented hosting. Many providers allocate you a block of ports and map them to standard ones internally. Your panel says 27015 and the world sees 28742. Every configuration file you write with 27015 in it is then correct locally and wrong publicly, and the server announces an address nobody can reach. Read what the panel says the external port is, and use that number everywhere a player or a list will see it.
The convar that quietly breaks it
On Source servers, the query port can be set independently of the game port with -port and +hostport, and there is a third setting many operators never touch: query rate limiting.
sv_max_queries_sec and sv_max_queries_sec_global exist so that your server cannot be used as a reflection amplifier in a denial-of-service attack. The defaults are reasonable. Tightened aggressively — which some hosting templates do — they drop legitimate directory queries alongside attack traffic, and the result is a server that appears and disappears from lists at random.
If your listing flickers between online and offline with no pattern, and the machine's own logs show nothing wrong, this is the setting to look at before anything else. It also explains the case where a list shows your server as having lower uptime than you know it had: the uptime figure is built from successful queries, and a dropped query is indistinguishable from a down server to whoever is asking.
For players: what a missing server means
If a server you know is running does not appear in a browser, you have learned something about the list, not necessarily about the server.
Direct connect still works. In most Source games that is the console command connect ip:port; in Minecraft it is Direct Connection in the multiplayer menu; in FiveM it is connect from F8. A server that answers a direct connection and appears in no browser is a server with a query-side problem, and it is often the best-run community on the list precisely because the operator is not chasing visibility.
That is also why finding servers for older games so often means going around the browsers entirely. The games still work. The query infrastructure around them is what decayed.
The short version
Two ports, two jobs, no standard. The game port carries players; the query port carries the answer to "is anyone there". They are the same number in the Source family and different almost everywhere else, both are usually UDP, and the failure mode of a closed query port is a working server that no directory can see.
If your server is invisible, connect to it directly first. That single test tells you which of the two ports you are actually debugging, and it takes thirty seconds.
- Tags
- portsnetworkinghosting
- Share
Published · 6 min read