App firewall: what your app can reach
The Firewall tab decides what your app may reach on the internet. Connections coming in are a separate thing: those arrive through a web address or a public port.
What you see on the tab depends on the plan. A free app follows a fixed list. A paid app may reach anything by default, and its owner can swap that for a list of their own.
On the free plan
A free app may reach the destinations below and nothing else. The list is the same for every free app and cannot be changed.
| What it is for | Protocol | Ports |
|---|---|---|
| DNS | tcp, udp | 53 |
| Web (HTTP) | tcp | 80 |
| Web (HTTPS) | tcp | 443 |
| Web (alternate HTTP) | tcp | 8080 |
| Web (alternate HTTPS) | tcp | 8443 |
| Web (Cloudflare HTTPS) | tcp | 2053, 2083, 2087, 2096 |
| MySQL | tcp | 3306 |
| PostgreSQL | tcp | 5432 |
| PostgreSQL (pooler) | tcp | 6543 |
| MongoDB | tcp | 27017 |
| Redis | tcp | 6379 |
| Redis (TLS) | tcp | 6380 |
| File transfer (FTP) | tcp | 21 |
| Lavalink | tcp | 2333 |
| Discord voice | udp | 19294-19344, 50000-65535 |
| Minecraft servers | tcp | 25500-26999 |
| Minecraft servers (query, voice mods) | udp | 25500-26999 |
| Minecraft RCON | tcp | 25575 |
| Minecraft Bedrock | udp | 19132 |
| Game server status (FiveM) | tcp, udp | 30120 |
| Game server status (query) | udp | 7777 |
| Game server status (Steam query) | udp | 27015-27030 |
That covers what a bot normally does: resolve a name, call an API over HTTPS, reach a database, join a Discord voice channel, ask a game server who is online. If your app needs something that is not here, it needs a paid plan.
FTP works in passive mode, which is what FTP libraries use unless you tell them otherwise. FTP over TLS (FTPS) does not work on the free plan.
On a paid plan
A paid app’s owner picks one of two settings on the tab.
- Allow everything. The app may open a connection to anything, apart from the ports closed for every app. This is how a paid app starts out.
- Only allow these. The app may reach what is on your list and nothing else.
Each rule on your list is a protocol, a port or a port range, and an optional destination.
- Ports are one port, like
443, or a range, like50000-65535. Ports run from 1 to 65535 and a range has to go upwards. - A destination is an IPv4 address or range, like
203.0.113.7or203.0.113.0/24. Leave it empty to allow that port to any address. - You can save up to 50 rules. A list needs at least one rule; if you want everything allowed, pick Allow everything instead.
Press Save and the app restarts so it comes up with the new rules. Your code and everything under /data are untouched.
A destination has to be a public address. Private and internal ranges are refused when you save, because an app cannot reach them with or without a rule. If you want your app to talk to your own databases and servers, that runs over your private network and is not something the firewall list covers.
What was refused
The Firewall tab lists what the firewall refused in the last day: the port and the address the app tried, how many times, and why. A port that is not on the list reads “The free plan’s list does not include it” on the free plan, or “Your list does not include it” on a paid plan with a list. A private address reads “Private addresses are closed for every app”. When nothing was refused, the tab says so.
A refusal shows up within a few minutes. If a connection your app needs is on that list, that is the port to add on a paid plan, or the reason to move the app to one.
Ports closed for every app
Two ports are closed on every plan, and cannot be put on a list:
- port 25, mail handed straight to another mail server,
- port 7844, which tunnel clients use to dial home. Proxies and tunnels are not allowed on app hosting at all; see what is not allowed.
Sending mail
Mail through a provider, on port 465 or 587, comes with the paid plans. A free app cannot send mail.
- On a paid app set to Allow everything, mail works on those ports.
- On a paid app with a list of its own, put port 465 or 587 on the list as well. Being on a paid plan opens the port; your list still has to allow it.
- An app that has been running since before you moved it to a paid plan gets mail on its next start. The tab says so when that is the case.
Port 25 stays closed either way, so use your provider’s submission port and your provider’s credentials.
Need help?
If something your app needs is being refused and you cannot see why, open a ticket from the panel with the app’s name, or reply to any of our emails.