App firewall: what your app can reach

The Firewall tab decides what your app may reach on the internet. Connections coming in are a separate thing: those arrive through a web address or a public port.

What you see on the tab depends on the plan. A free app follows a fixed list. A paid app may reach anything by default, and its owner can swap that for a list of their own.

On the free plan

A free app may reach the destinations below and nothing else. The list is the same for every free app and cannot be changed.

What it is forProtocolPorts
DNStcp, udp53
Web (HTTP)tcp80
Web (HTTPS)tcp443
Web (alternate HTTP)tcp8080
Web (alternate HTTPS)tcp8443
Web (Cloudflare HTTPS)tcp2053, 2083, 2087, 2096
MySQLtcp3306
PostgreSQLtcp5432
PostgreSQL (pooler)tcp6543
MongoDBtcp27017
Redistcp6379
Redis (TLS)tcp6380
File transfer (FTP)tcp21
Lavalinktcp2333
Discord voiceudp19294-19344, 50000-65535
Minecraft serverstcp25500-26999
Minecraft servers (query, voice mods)udp25500-26999
Minecraft RCONtcp25575
Minecraft Bedrockudp19132
Game server status (FiveM)tcp, udp30120
Game server status (query)udp7777
Game server status (Steam query)udp27015-27030

That covers what a bot normally does: resolve a name, call an API over HTTPS, reach a database, join a Discord voice channel, ask a game server who is online. If your app needs something that is not here, it needs a paid plan.

FTP works in passive mode, which is what FTP libraries use unless you tell them otherwise. FTP over TLS (FTPS) does not work on the free plan.

On a paid plan

A paid app’s owner picks one of two settings on the tab.

  • Allow everything. The app may open a connection to anything, apart from the ports closed for every app. This is how a paid app starts out.
  • Only allow these. The app may reach what is on your list and nothing else.

Each rule on your list is a protocol, a port or a port range, and an optional destination.

  • Ports are one port, like 443, or a range, like 50000-65535. Ports run from 1 to 65535 and a range has to go upwards.
  • A destination is an IPv4 address or range, like 203.0.113.7 or 203.0.113.0/24. Leave it empty to allow that port to any address.
  • You can save up to 50 rules. A list needs at least one rule; if you want everything allowed, pick Allow everything instead.

Press Save and the app restarts so it comes up with the new rules. Your code and everything under /data are untouched.

A destination has to be a public address. Private and internal ranges are refused when you save, because an app cannot reach them with or without a rule. If you want your app to talk to your own databases and servers, that runs over your private network and is not something the firewall list covers.

What was refused

The Firewall tab lists what the firewall refused in the last day: the port and the address the app tried, how many times, and why. A port that is not on the list reads “The free plan’s list does not include it” on the free plan, or “Your list does not include it” on a paid plan with a list. A private address reads “Private addresses are closed for every app”. When nothing was refused, the tab says so.

A refusal shows up within a few minutes. If a connection your app needs is on that list, that is the port to add on a paid plan, or the reason to move the app to one.

Ports closed for every app

Two ports are closed on every plan, and cannot be put on a list:

  • port 25, mail handed straight to another mail server,
  • port 7844, which tunnel clients use to dial home. Proxies and tunnels are not allowed on app hosting at all; see what is not allowed.

Sending mail

Mail through a provider, on port 465 or 587, comes with the paid plans. A free app cannot send mail.

  • On a paid app set to Allow everything, mail works on those ports.
  • On a paid app with a list of its own, put port 465 or 587 on the list as well. Being on a paid plan opens the port; your list still has to allow it.
  • An app that has been running since before you moved it to a paid plan gets mail on its next start. The tab says so when that is the case.

Port 25 stays closed either way, so use your provider’s submission port and your provider’s credentials.

Need help?

If something your app needs is being refused and you cannot see why, open a ticket from the panel with the app’s name, or reply to any of our emails.

Something missing or wrong? Tell us or ask in Discord.