Checking for Blocked Outbound Ports

Last updated: September 23, 2026

When to use this:

When a Twingate Client works on one network, but not another. When or if a Client can sign in, but Resources won't connect or are not performant.

What Twingate needs

Client endpoints have requirements documented here, but to reiterate:

The Twingate Client requires outbound connectivity on the following ports:

Outbound initiated TCP Port: 443 (basic communication with the Twingate Controller and Relay infrastructure)

Outbound initiated TCP Ports: 30000-31000 (opening connections with Twingate Relay infrastructure in case peer-to-peer is unavailable)

Outbound initiated UDP and QUIC for HTTP/3 (see this guide for more information) Ports: 1-65535 (allows for peer-to-peer connectivity for optimal performance)

The Client does not usually need any special firewall rules opened, but if issues with connectivity are observed use the list above to troubleshoot.

In order to troubleshoot, we can use nmap to identify if your current network is perhaps blocking outbound requests needed by the Client.

Native on Linux, available on Mac via brew and on Windows as a binary

Why portquiz.net

Twingate Relays only accept Twingate traffic and the Client is given Relay addresses dynamically. Meaning there is no fixed Twingate address you can test. portquiz.net is a free public server that accepts connections on every TCP port. If you can reach it on a port, then the network is not blocking that outbound port.

Test 443:

  • MacOS/Linux: nc -vz -w 5 portquiz.net 443

  • Windows (Powershell): Test-NetConnection portquiz.net -Port 443

If this fails, the problem isn't Twingate's port range. Check for a captive portal (when you're at a hotel or on in-flight WiFi) and see if you can't complete the portal's process.

Test the Relay port range

Test the beginning, middle, and end of the range:

  • MacOS/Linux:

for p in 30000 30500 31000; do nc -vz -w 5 portquiz.net $p; done
  • Windows (Powershell):

30000,30500,31000 | % { Test-NetConnection portquiz.net -Port $_ } | ft RemotePort,TcpTestSucceeded
  • nmap (optional):

nmap -Pn -p 443,30000,30500,31000 portquiz.net

This type of probe should work considering that its typical for the whole range to be blocked, if it's blocked at all. Avoid scanning the whole range, which could trigger a security alert.

Reading the results

Result

Meaning

nc: succeeded PowerShell: TcpTestSucceeded : True nmap: open

Port is allowed.

nc: Operation timed out

PowerShell: False, after a long wait

nmap: filtered

Something on the network is silently dropping the traffic. Common sign of outbound FW rule.

nc: Connection refused

nmap: closed

portquiz.net accepts every port, so a refusal means a FW on the path rejected the connection. Treat it the same as a block.

nmap: Host seems down

nmap's discovery check was blocked. Run again with -Pn

Ignore nmap's SERVICE column; for example: pago-services1. It's nmap's name for that port number and unrelated to Twingate.

The typical blocked result:

443 open, but 30000, 30500, and 31000 time out or show filtered. The network only allows web traffic.

If ports are blocked

  • As your network Admin to allow outbound TCP 30000 - 31000. See Client Endpoint Requirements.

  • Try a different network temporarily, like a mobile phone hotspot to confirm if Twingate works or not.

Back to troubleshooting guide

Go Back