How to port forward a Team Fortress 2 server
Team Fortress 2 uses one port number on both protocols, the standard Source-engine arrangement. UDP carries gameplay and queries; TCP on the same number handles part of the Steam handshake.
Your setup
Pick the firmware family, not the exact model — the menus are identical across a range.
Default is 27015. If you changed it, it is the value of -port.
The private address of the machine running the server — ipconfig on Windows, ip addr on Linux. It starts with 192.168, 10. or 172.
Open these
This firmware accepts ranges, so each line below is a single rule.
- 27015 TCP
- 27015 UDP
27015UDPGame trafficGameplay and queries.27015TCPSteam handshakeThe same number over TCP.
Only if you want them
The server works without these. Every port you open is a port someone can knock on, so skip anything you do not need.
- 27020 UDP
27020UDPSourceTVOptional demo relay.
Do not open these
This game has no remote-administration port to get wrong. Forward only what is listed on the left and nothing else.
Step by step: your router
- 1
Give the server a fixed local IP
A forward points at one address. If the server picks up a different one after a reboot, the rule silently starts pointing at nothing — this is why forwards "stop working" on their own.
On this router:look for DHCP Reservation, Address Reservation, Static Lease or Manually Assigned IP
- 2
Open the router admin page
Try these addresses in a browser on the same network:
- 192.168.0.1
- 192.168.1.1
- 192.168.2.1
- 10.0.0.1
Almost always printed on a sticker on the router itself.
- 3
Find the port forwarding page
Port Forwarding, Virtual Server, NAT, Applications & Gaming, or Port Mapping
Vendors use at least six names for the same feature. Whatever it is called, the page you want is the one asking for a port, a protocol and a device on your network. If the external and internal port fields both exist, set them to the same number.
- 4
Create one rule per line
a description field, if there is one External / WAN / Public / Service port Internal / LAN / Private port Protocol Internal IP / Device / Server IP Team Fortress 2 27015 27015 TCP your server’s local IP Team Fortress 2 27015 27015 UDP your server’s local IP External and internal port are the same number here. Changing the external port is possible, but then everyone connects on the new one, so keep them matched unless you have a reason.
- 5
Let the server through its own firewall
The router now sends traffic to the machine, and the machine can still refuse it. Windows Defender Firewall in particular blocks a freshly installed dedicated server by default, which looks exactly like a failed forward.
Take it with you
Team Fortress 2 — port forwarding rules --------------------------------------- 27015 TCP -> <server local IP> 27015 UDP -> <server local IP>
Check whether it worked
Test from outside your own network. Connecting from a machine in the house proves nothing — that traffic never leaves the LAN and never touches the rule you just wrote.
What usually goes wrong
If you run SourceTV you need its port as well, and it is a separate fixed number rather than an offset. Leaving it closed does not affect play at all, which is why it usually gets discovered weeks later when someone tries to spectate.
Not forwarding at all
A community TF2 server's custom maps have to reach every joining player, and on a home connection that download is the first impression your server makes.