PunktfunkPunktfunk

Ports & firewall

Every port a Punktfunk host and its console use, the firewall profile that opens each, and how to move one.

Find the port a Punktfunk host uses, the firewall profile that opens it, and how to move it. The Linux packages install firewalld services and ufw profiles but never enable them.

PlanePortWhatfirewalld service / ufw profile
Native controlUDP 9777punktfunk/1 QUIC control portpunktfunk-native
DiscoveryUDP 5353mDNS discoverypunktfunk-native
Management APITCP 47990management REST API (HTTPS + token; read-only status/library off loopback)punktfunk-native
Browser streamingUDP 9778browser streaming (preview, off until switched on)punktfunk-native
Video dataUDP (ephemeral)per-session video data plane — ephemeral port the client hole-punches; nothing fixed to open—
Web consoleTCP 47992, 47993web console (HTTPS, login-gated); plugin interfaces on 47993punktfunk-web
GameStream (Moonlight)TCP 47984, 47989, 48010 · UDP 47998, 47999, 48000GameStream/Moonlight-compat planes (opt-in, PUNKTFUNK_GAMESTREAM=1)punktfunk-gamestream
  • punktfunk-native is all a default host needs: paired clients, discovery and the management API.
  • punktfunk-web only when you open the console from another device. Plugin interfaces use its second port — see Two ports, not one.
  • punktfunk-gamestream only with Moonlight compat on.
  • Video needs no open port. The client hole-punches an ephemeral UDP port and the host answers through it. To open one fixed port instead, set PUNKTFUNK_DATA_PORT.
  • The browser client (preview, off by default) uses UDP 9778, in punktfunk-native — see Browser Client. A rule from before 0.41 lacks it: sudo ufw app update punktfunk-native && sudo ufw reload, or sudo firewall-cmd --reload.

Enable the profiles

sudo firewall-cmd --reload     # load the definitions the package installed
sudo firewall-cmd --permanent --add-service=punktfunk-native --add-service=punktfunk-web
sudo firewall-cmd --permanent --add-service=punktfunk-gamestream   # only with Moonlight compat on
sudo firewall-cmd --reload
SystemFirewall as shipped
Fedora, Bazzite, most Fedora spins, EndeavourOSfirewalld, on
CachyOSufw, on
Ubuntuufw, installed but off
Arch, Debiannone
NixOSopenFirewall = true in the module opens the ports
Windowsservice install adds the rules

On Windows each rule names the Punktfunk executable as well as the port, and video gets an inbound UDP rule for the executable alone, because Windows drops the client's hole-punch. The rules cover Private and Domain networks; service install --allow-public-network adds Public — see Host CLI. Another program that answered discovery through Punktfunk's 5353 rule needs a rule of its own.

Who can reach the console

The web console (47992) and its plugin port (47993) answer this machine, private and link-local addresses, and a Tailscale tailnet. A peer from the internet is refused even with the port forwarded. PUNKTFUNK_UI_BIND=127.0.0.1 in host.env keeps both to this machine; one address limits them to one interface.

Moving a port

Set these in host.env. Moving the management port is how you share a machine with Sunshine — see Switching from Sunshine.

PortSettingClients
Management APIPUNKTFUNK_MGMT_BIND=IP:PORTRelearn it from discovery. The console, plugin runner and tray read it from mgmt-endpoint, which the host rewrites on every start.
Native controlPUNKTFUNK_NATIVE_PORTRelearn it over mDNS. A host added by address keeps the port it was added with.
Video dataPUNKTFUNK_DATA_PORTOne fixed UDP port instead of one per session.
Browser clientPUNKTFUNK_WEBTRANSPORT_PORTDefault 9778.

On this page