How to Create a Minecraft Server with Friends Using Tailscale
Forget Hamachi! Use Tailscale to create a private network for your Minecraft server, allowing friends to join without port forwarding.

On this page
The problem is always the same: the server runs on one person’s computer, but others are behind different routers and cannot reach it. There are three solutions (opening ports, using a tunnel, or creating a private network) and the last one is the simplest and least risky.
Why not Hamachi #
It worked for years, but today it shows its limits: the free plan is limited to 5 people per network, including the host; the virtual network it creates can conflict with other connections; and problems with the network adapter that force you to reinstall are frequent. Additionally, the installation suggests extra programs that you’ll want to remove.
Tailscale is based on WireGuard, configures itself automatically, and connects devices directly to each other when the network allows it.
Setting up the server #
You need a copy of Minecraft: Java Edition for everyone, an updated Java on the server computer (from version 26.1, you need Java 25), and a connection with at least 5 Mbps upload speed—preferably via Ethernet.
On the computer that will host the game, download the official Java server (
server.jar) from the Minecraft download page and put it in its own folder, for example “Minecraft Server” on your desktop.Launch it for the first time by double-clicking or from the terminal (
java -Xmx4G -jar server.jar nogui): it will close immediately after creating some files.Open the
eula.txtfile and changeeula=falsetoeula=true, accepting the terms of use.Restart the server and wait until the line Done appears in the console: the world is ready.
Close the server, open
server.propertieswith Notepad, adjust the main settings, and then restart it:gamemode:survival,creativeoadventure;difficulty:peaceful,easy,normalohard;pvp:trueto allow player combat,falsefor cooperative play;max-players: how many players can join at once;white-list:trueto only allow people you add with/whitelist add nome;motd: the message that appears in the server list.

server.properties is created upon the first launch of the server
For a group of friends, consider using Paper instead of the official server: it’s the same game, but with better performance and the ability to add plugins.

Configuring the private network #
Create a free account on the Tailscale website (you can also use your Google, Microsoft, or GitHub account) and install the program on every computer that will participate: the server computer and your friends’ computers.
Everyone logs in with their own account. There are two ways to connect them: invite friends to your network from the Users section of the web dashboard, or—the cleaner way—share only the server computer: in the Machines section, open the menu next to the PC and choose Share. This way, your friends only see that specific machine and not the rest of your devices.
On the computer hosting the server, take note of the address Tailscale assigned it: it starts with
100.and you can find it in the dashboard or by clicking the program icon in the notification area.In Minecraft, friends should select Multiplayer → Direct Connection and type that address followed by
:25565(the port can be omitted as it is the default). With MagicDNS enabled, they can also use the computer name instead of numbers.
You don’t need to touch your router, and no one needs to know their public IP.

Windows Firewall #
This is where most people get stuck: the server is running, the private network works, but no one can join. Usually, it’s the fault of the firewall, which blocks incoming connections to Java. When you first launch the server, Windows might ask if you want to allow Java on certain networks: check Private and confirm; you might not need to do anything else.
If that doesn’t work, create the rule manually:
Search for Windows Defender Firewall with Advanced Security from the Start menu.
Select Inbound Rules → New Rule.
Choose Port, then TCP, and specify port
25565.Select Allow the connection.
In the profile screen, check at least Private. If the Tailscale network profile shows as Public, check that one too.
Give the rule a name, such as “Minecraft server”, and save it.

If something goes wrong #
“Unable to connect to server.” Make sure the server is running and that everyone is using the exact same version of Minecraft, down to the last number.

The Tailscale address is not responding. Make sure both devices show as connected in the dashboard. The application must be running, not just installed. From a terminal, tailscale ping 100.x.y.z tells you if the other computer is responding.
It works for some but not others. Those who can’t join are likely not on the same network or haven’t accepted the sharing request: invites must be accepted.
Slow or stuttering connection. Tailscale tries to establish a direct connection between you; if it fails, traffic is routed through a relay server (DERP), which increases latency. tailscale status or the dashboard will tell you what type of connection you have.
Become a server administrator #
To change game modes, teleport, or kick someone, you need operator permissions. In the server console, type op followed by your Minecraft username, for example op Marco, and press Enter. From then on, you can use slash commands, like /gamemode creative, even from inside the game.

Alternatives #
Port forwarding on your router is the classic method: you forward port 25565 to the server computer. It works well, but it exposes the server to the internet, so you need to be careful with security and have a reachable public IP, which not all home connections provide.
A tunneling service like playit.gg exposes the server via a public address provided by the service, without touching your router and without requiring your friends to install anything. It’s convenient, but it adds an intermediary and makes you dependent on them.
Hosting solves everything: the server stays online even when your computer is turned off, which is the main limitation of any home-based solution. There are free services like Aternos, which include queues and automatic shutdowns, as well as paid services for just a few euros per month.
Minecraft’s LAN mode, combined with a private network, works fine for occasional games without a dedicated server: open your world to the local network from the pause menu, and others can connect using the Tailscale address and the port shown in your chat. However, the world only exists as long as you are playing.
FAQ #
Is Tailscale free? #
The personal plan is free and includes unlimited devices for up to six users for non-commercial use. For a group of friends playing together, it’s more than enough, and by sharing a single computer, your friends don’t even count toward your network user limit.
Does the server stay online if I turn off my computer? #
No: the world lives on the computer hosting it, so if you turn it off or close the server, no one else can join. If your group plays at different times, this is the main reason to switch to external hosting.
How much memory does the host computer need? #
For four or five players without mods, 2-4 GB for the server (the -Xmx4G startup parameter) is enough. With mods or many players, you’ll want to go up to 6-8 GB—don’t overdo it: too much memory can actually decrease performance instead of improving it.
Is it safe to use a private network instead of opening ports? #
Yes, and it is safer. With an open port on your router, the server is reachable by anyone on the internet; with a private network, only those you have invited can enter.
Does it work with Bedrock Edition too? #
The private network works with any game, but the two versions of Minecraft cannot talk to each other and use different ports. For Bedrock, you need its specific server (Bedrock Dedicated Server) and a firewall rule for port 19132 on UDP. On Bedrock consoles, you cannot enter addresses manually, so with Tailscale, it only works on PC and mobile.

