KeeperFX uses UDP port 5556 by default. It tries direct connections over IPv4 and IPv6, UDP hole punching, and automatic port forwarding through NAT-PMP or UPnP.
If players cannot join your online lobby:
100.64.0.0–100.127.255.255, the ISP likely uses CGNAT. Ask the ISP for a public IPv4 address or use IPv6 instead.KeeperFX uses a matchmaking master server to introduce players, then attempts a direct UDP connection over IPv4 or IPv6; the server does not relay game traffic. Online lobby discovery requires HTTPS/WebSocket access to matchmaking.keeperfx.workers.dev. IPv4 hole punching uses STUN servers, including stun.l.google.com on UDP 19302. Firewalls, DNS filters, routers, and restricted networks can block these services or UDP hole punching.
If everyone can join but the game cannot start, try a known-working map and make sure everyone has the same map files.
Some networks simply cannot establish peer-to-peer UDP connections.
To use Direct Connect over the internet, open the launcher menu beside Play, select Direct Connect, enter the host's public IP address or hostname, and click Play. Add the port to the address if the host is not using the default, such as example.com:6000. The host may need to forward the selected UDP port in their router.
Use the LAN Lobby when everyone is on the same network and running the same KeeperFX version. UDP 5557 handles lobby discovery by IPv4 broadcast, while a separate UDP port (5556 by default) handles the game. Broadcast discovery does not normally cross subnets or VLANs.
If the lobby does not appear, open Direct Connect from the launcher menu beside Play and enter the host's local IPv4 address, such as 192.168.1.50. If Direct Connect works, check whether UDP 5557 is blocked. If it fails, allow KeeperFX through both firewalls, temporarily disable VPNs, and disable guest-network, AP-isolation, or client-isolation settings. Restart KeeperFX after changing network settings.
LAN games need no internet port forwarding. Do not use the router's public IP address.