How to Fix RCON Not Connecting
RCON stays off until enable-rcon is true and rcon.password isn't empty. Check the lines the server writes to its log, then the address, port and firewall.
Quick Fix
Set enable-rcon=true, a non-empty rcon.password and rcon.port (25575 by default) in server.properties, restart, and look for "RCON running on" in the log.
Error Message
No rcon password set in server.properties, rcon disabled!How to Fix
In server.properties set enable-rcon=true and choose a long, random rcon.password. An empty password disables RCON on purpose.
Leave rcon.port at 25575 or pick another free TCP port between 1 and 65535 that isn't the same as server-port.
Restart the server and read the log. "RCON running on 0.0.0.0:25575" means it is listening; any of the warnings above tells you what went wrong.
RCON listens on the address in server-ip, or on every address (0.0.0.0) when server-ip is empty. With server-ip empty you can test from the server itself on 127.0.0.1.
Only open the port to addresses you trust. RCON isn't encrypted, so the password and every command travel as plain text; an SSH tunnel or VPN is the safer way to reach it from outside.
broadcast-rcon-to-ops is on by default and sends RCON command output to operators who are online. Turn it off if you don't want them to see it.
Common Causes
- rcon.password is empty. The server then logs "No rcon password set in server.properties, rcon disabled!" and never opens the port.
- enable-rcon is still false, so the "Starting remote control listener" line never shows up in the log.
- rcon.port is outside 1 to 65535, which logs "Invalid rcon port ... found in server.properties, rcon disabled!".
- The port couldn't be opened, for example because another program already uses it or server-ip is set to an address the machine doesn't have. The log then says "Unable to initialise RCON on ...".
- A firewall blocks the TCP port, or on a hosting panel or in a container the port was never assigned or forwarded to the server.
- The RCON client sends the wrong password. The server answers a failed login with request ID -1, which most tools show as an authentication error.
Diagnostic Steps
- Check enable-rcon, rcon.password and rcon.port in server.properties.
- Restart and search the log for "rcon".
- Test with an RCON client on the server itself first.
- Only then test from outside, and check the firewall or port forwarding if that fails.
FAQ
Is RCON secure?
No. RCON isn't encrypted, so anyone between you and the server can read the password and your commands. Keep it on localhost or reach it through an SSH tunnel or VPN, and never leave the port open to the whole internet.
What is the default RCON port?
25575, over TCP. Query is a separate protocol that uses UDP on query.port.
Why do some RCON commands return nothing?
Many commands produce no output, and the protocol can't report an unknown command, so an empty reply doesn't always mean the command failed.
Does Bedrock Dedicated Server have RCON?
No. RCON is a Java Edition server feature.