Checking for Blocked Outbound Ports
Last updated: September 23, 2026
When to use this:
When a Twingate Client works on one network, but not another. When or if a Client can sign in, but Resources won't connect or are not performant.
What Twingate needs
Client endpoints have requirements documented here, but to reiterate:
The Twingate Client requires outbound connectivity on the following ports:
Outbound initiated TCP Port: 443 (basic communication with the Twingate Controller and Relay infrastructure)
Outbound initiated TCP Ports: 30000-31000 (opening connections with Twingate Relay infrastructure in case peer-to-peer is unavailable)
Outbound initiated UDP and QUIC for HTTP/3 (see this guide for more information) Ports: 1-65535 (allows for peer-to-peer connectivity for optimal performance)
The Client does not usually need any special firewall rules opened, but if issues with connectivity are observed use the list above to troubleshoot.
In order to troubleshoot, we can use nmap to identify if your current network is perhaps blocking outbound requests needed by the Client.
Native on Linux, available on Mac via brew and on Windows as a binary
Why portquiz.net
Twingate Relays only accept Twingate traffic and the Client is given Relay addresses dynamically. Meaning there is no fixed Twingate address you can test. portquiz.net is a free public server that accepts connections on every TCP port. If you can reach it on a port, then the network is not blocking that outbound port.
Test 443:
MacOS/Linux:
nc -vz -w 5 portquiz.net 443Windows (Powershell):
Test-NetConnection portquiz.net -Port 443
If this fails, the problem isn't Twingate's port range. Check for a captive portal (when you're at a hotel or on in-flight WiFi) and see if you can't complete the portal's process.
Test the Relay port range
Test the beginning, middle, and end of the range:
MacOS/Linux:
for p in 30000 30500 31000; do nc -vz -w 5 portquiz.net $p; doneWindows (Powershell):
30000,30500,31000 | % { Test-NetConnection portquiz.net -Port $_ } | ft RemotePort,TcpTestSucceedednmap(optional):
nmap -Pn -p 443,30000,30500,31000 portquiz.netThis type of probe should work considering that its typical for the whole range to be blocked, if it's blocked at all. Avoid scanning the whole range, which could trigger a security alert.
Reading the results
Result | Meaning |
nc: | Port is allowed. |
nc: PowerShell: nmap: | Something on the network is silently dropping the traffic. Common sign of outbound FW rule. |
nc: nmap: |
|
nmap: | nmap's discovery check was blocked. Run again with |
Ignore nmap's SERVICE column; for example: pago-services1. It's nmap's name for that port number and unrelated to Twingate.
The typical blocked result:
443 open, but 30000, 30500, and 31000 time out or show filtered. The network only allows web traffic.
If ports are blocked
As your network Admin to allow outbound TCP 30000 - 31000. See Client Endpoint Requirements.
Try a different network temporarily, like a mobile phone hotspot to confirm if Twingate works or not.