A Minecraft server can run perfectly on a home machine and still be unreachable to players outside the house. Forwarding TCP port 25565 on the router only works when that router owns a public IPv4 address. Carrier-grade NAT, mobile broadband, and some apartment or campus networks put another NAT device upstream, where the server owner has no port-forwarding control.
This guide uses Minecraft Java Edition on a Linux host. It gives the host a routed public IPv4 through an outbound WireGuard tunnel, then exposes only the game port. The home server initiates the tunnel, so it works when the ISP address changes or the connection sits behind CGNAT.
Confirm that CGNAT is the actual problem
Compare the WAN IPv4 in the router with the address reported by an external IP-check service. A mismatch means another device translates traffic upstream. A WAN address in 100.64.0.0/10, 10.0.0.0/8, 172.16.0.0/12, or 192.168.0.0/16 is not publicly routable.
Dynamic DNS does not change this. It updates a hostname when a reachable public address changes, but cannot create an inbound mapping at the carrier NAT. Ask the ISP for a public IPv4 first. A routed address over an outbound tunnel is the direct alternative when that option is unavailable.
Choose the right exposure model
A public server accepts connections from anyone who knows its address. That differs from private remote access for a few trusted devices, where a mesh VPN can be simpler. Minecraft Realms removes server administration but offers less control. An HTTP tunnel or reverse proxy does not carry the normal Minecraft Java protocol.
Use a whitelist for a private group, keep backups outside the host, and do not publish SSH merely because the game address is public. A public address solves reachability. It does not replace updates, backups, or moderation.
Prepare the Minecraft host
The official Minecraft server download page states that Java Edition needs a compatible Java Runtime Environment and identifies TCP port 25565 for external Java connections. Download the software from Minecraft, accept its EULA, and start it once according to the current release instructions.
sudo ss -lntp '( sport = :25565 )'The listener normally appears as 0.0.0.0:25565 or a host address. If it listens only on 127.0.0.1:25565, remote players cannot reach it. Fix the service configuration before changing the network.
Route one public IPv4 through WireGuard
The home host establishes an encrypted WireGuard session to a provider. The provider routes a public IPv4 through that session. A policy rule sends replies sourced from that address back through WireGuard rather than through the household connection.
| Value | Example | Purpose |
|---|---|---|
| Tunnel address | 10.255.0.2/30 | Home host inside WireGuard. |
| Provider endpoint | 198.51.100.10:51820 | Public peer. |
| Routed address | 203.0.113.42/32 | Address players use. |
| Game port | 25565/tcp | Minecraft Java listener. |
These are documentation values. Replace them with the assigned tunnel details. The full policy-routing configuration is in How to get a public IP for a home server. After bringing the tunnel up, verify both the handshake and return path:
sudo wg show wg0
ip address show dev lo
ip route get 1.1.1.1 from 203.0.113.42wg show should report a recent handshake. The last command must select wg0 for traffic sourced from the routed address. Without it, a player can reach the host but its replies leave through the home ISP and the connection stalls. Set PersistentKeepalive = 25 on the home-side peer when it is behind NAT.
Allow the game port and nothing else
Use the firewall already installed on the host. With UFW, this rule permits Java traffic arriving through the tunnel and addressed to the routed IPv4:
sudo ufw allow in on wg0 to 203.0.113.42 port 25565 proto tcp
sudo ufw status numberedDo not add a port forward to the home router. It cannot help a CGNAT connection. The WireGuard tunnel is the only path the public address needs.
Taipan Transit can route one public IPv4 address through a WireGuard tunnel to a home Minecraft server. Create an account, select the tunnel, then add the address required for the server.
Test from outside the home network
Testing from the same Wi-Fi can hide a routing problem. Ask a player on another connection to join 203.0.113.42, or test over mobile data. A server-list ping is useful, but a real join with the same game version and mods is the final test.
nc -vz 203.0.113.42 25565Once that succeeds, create an A record such as play.example.net pointing to the routed IPv4. The DNS record stays the same if the home connection changes because the address is routed to the tunnel, not assigned by the ISP.
Fix the failures that look like a Minecraft problem
| Symptom | Check |
|---|---|
| No WireGuard handshake | Verify keys, endpoint, UDP port, and ordinary Internet access. |
| Handshake works, port times out | Check ss -lntp, the server process, and the firewall rule. |
| The port opens, then joining stalls | Check the policy route with ip route get using the routed address as source. |
| Small traffic works, larger transfers fail | Check tunnel MTU and MSS. |
| Players report lag | Measure home upload capacity and regional latency. Routing cannot add bandwidth to the household line. |
For tunnel-level issues, use the tunnel health and MTU and MSS references before changing unrelated Java or firewall settings.
Keep the server usable after the first join
Set a backup schedule and test restoring a world to a separate directory. Keep Java, the server jar, mods, and the operating system updated. Review memory use and tick time before inviting more people than the host can support. A replacement host needs the tunnel configuration, firewall policy, and world data ready before the public route moves.
Frequently asked questions
Can I host a Minecraft server behind CGNAT?
Yes. The home server can create an outbound WireGuard tunnel to a provider that routes a public IPv4 address through it. Players connect to that routed address, so an inbound port forward is unnecessary.
Which port does Minecraft Java use?
Minecraft's official server download page identifies TCP port 25565 for Java Edition.
Does Dynamic DNS fix CGNAT?
No. Dynamic DNS updates a name when a reachable public address changes. It cannot make a CGNAT address accept inbound connections.
