Animated diagram: on the left, a firewall-style rule list. SSH access, RTMP, and the stats page run over TCP, SRT and SRTLA over UDP, and everything else stays closed. On the right, the three checkpoints service, server firewall, and router. Below, the note to keep your own SSH access allowed before you enable it

Open only the ports you need

The generator builds a conservative UFW baseline. Router port forwarding is only needed if a service really has to be reachable from the internet.

Which streaming ports do you actually need?

RTMP, SRT, SRTLA, stats pages, and remote controls use different TCP or UDP ports. The generator maps the services you choose to the matching rules and can restrict a source IP. That gives you a port list you can check, instead of a firewall that is open across the board.

A server firewall does not replace securing the service itself. Keep unneeded rules closed, protect admin access especially well, and before enabling it make sure your own SSH access is still allowed.

Do not mix up TCP and UDP

TCP confirms the data it transfers and is often used for websites, admin interfaces, RTMP, or stats access. UDP works without that confirmation and is the usual choice for the actual media transport with SRT and SRTLA. A rule with the right port but the wrong protocol does nothing.

That is why the generator lists TCP and UDP rules separately. Only add extra ports if the application actually uses them and the service listens on that port.

Server firewall, router, and service are three checkpoints

  1. The streaming service must be running and listening on the intended port.
  2. The server's firewall must allow exactly that port and the right protocol.
  3. If the server sits on a home network, a targeted port forward on the router may be needed too.

With a VPS you usually do not need the home router forward. Instead, the provider may have an extra network firewall. Limit admin ports to known source addresses where you can, and never open big port ranges just to try things out.

Pick a port profile

PortProtocolPurpose

Check before you run it

Secure your SSH access: If you administer a remote machine, make sure your own SSH access stays allowed before you enable the firewall. Never run the generated file unchecked on a production server.

Privacy and security

This tool works locally in your browser. IRL4YOU neither transmits nor stores what you enter. Even so, credentials do not belong in screenshots or public support messages.

Last technically reviewed: · Published by IRL4YOU