rcon.port (Rust server ConVar)

What rcon.port sets on a Rust server, why it is TCP, why it belongs on the command line, and how it shifts the default query and Rust+ ports.

Last updated Verified on Rust build 25582902, 2026-09-28

Kind
Variable
Value on build 25582902
28016
Server help text
Port to listen for RCON connections
Applies
After a restart
Persists in
Startup argument
Vanilla Rust
Yes, native
Example
+rcon.port 28016

Gotchas

  • It is TCP. The game and query ports are UDP, so a firewall rule for the wrong protocol makes RCON time out.
  • The Facepunch wiki gives its default as equal to server.port, so set it explicitly.
  • The default query port and Rust+ port are derived from the higher of server.port and rcon.port, so moving rcon.port can move them unless you set them too.
  • Two servers on one host need different RCON ports.

rcon.port is the TCP port the server's RCON listener opens. RCON tools, bots and panels connect to it to run console commands. The server's help text: "Port to listen for RCON connections".

Set it on the command line

Pass it as a startup argument, next to the other ports:

+server.port 28015 +rcon.port 28016 +rcon.web 1

The listener starts once, early in boot. On our test server the log prints WebSocket RCON Started on :28016 once per start, about two seconds after Server Config Loaded. We treat a new RCON port as a restart: change the argument, restart, and connect to the port in that log line. The Facepunch wiki also says to keep ports and RCON settings on the command line. server.writecfg does not save any rcon. value; our test server's serverauto.cfg has none.

TCP, not UDP

The game port and the query port are UDP. rcon.port is TCP. A firewall rule or port forward for the wrong protocol is the classic reason a tool times out without an error. Check what the server really opened:

ss -ltnp | grep 28016

Keep this port closed to the internet. WebRCON as Panelra and common tools use it is plain ws:// with the password in the URL, so use it from the host, over an SSH tunnel, or allow only fixed IPs of a tool that needs it.

It moves other defaults

The Facepunch wiki gives the default RCON port as equal to server.port, which is one reason to always set it. It also feeds two other defaults:

  • the query port defaults to one above the higher of server.port and rcon.port;
  • the Rust+ port (app.port) defaults to 67 above the higher of the two.

So moving RCON to a high number without setting +server.queryport and +app.port can move those ports too, and your firewall rules no longer match. Set all four explicitly.

Several servers on one host

Every server needs its own RCON port; the second process cannot open a port the first one holds. In Panelra the game, RCON, query and Rust+ ports are under Settings > Network ports, marked as needing a restart. The agent writes them into the server's systemd unit and rewrites the unit on the next start when they change.

Set it in Panelra

Change rcon.port from the dashboard instead of editing files over SSH.

Web RCON console
  • rcon.webIf set to true, use websocket RCON. If set to false use legacy, source engine RCON. Source engine RCON is DEPRECATED
  • rcon.ipIP Address to listen for RCON connections
  • app.port(Generated) UDP port number the server listens on; default is 28015; must be open in firewall for players to connect
  • rcon.maxconnectionsperipTotal number of allowed connections to RCON server, on a single IP. -1 to disable behaviour. Requires server restart after changes

Skip the manual work: install the Panelra agent

Wipes, updates, restarts, plugins and crash alerts for your Rust servers, from one dashboard. One install command on your Linux host, no inbound ports for the agent.

Free during the open beta. Pricing will be announced before the beta ends.