Bedrock works differently from Java: it uses UDP and doesn't tell which domain the player typed. So every server gets its own Bedrock address with its own port at BlackProtect.
You enable Bedrock in your route settings, enter your Geyser's host and port, and give your players the new address including the port.
Contents
Why Bedrock is different
- Java sends the domain the player typed when connecting. That lets many servers share the same address at the protection.
- Bedrock (phone, console, Windows edition) connects over UDP and doesn't send the domain. So every server needs its own address with its own port.
- Bedrock doesn't support SRV records. Players have to enter the port themselves.
How to set it up
You need a running Geyser (as a plugin on Velocity or Paper, or standalone) and to know the address and port it is reachable on. The default port is 19132.
- Open your route
In the dashboard under Domains & Routes, open your domain's settings.
- Enable Bedrock
In the Bedrock (Minecraft mobile/console) section, enter the Geyser host (your server's IP or domain) and Geyser port, then click Enable Bedrock.
- Note the address
Under Bedrock ingress you now see the address and port Bedrock players use to reach your server.
- Create a nice address
At your domain provider, create an A record, e.g.
bedrock.yourserver.com, pointing to the IP shown. If the domain is on Cloudflare: proxy status DNS only (grey cloud). - Tell your players
Server address
bedrock.yourserver.com, port: the port shown. They enter both under “Add Server”.
Real player IPs on Bedrock
Without anything else, Geyser sees our filter's address for every Bedrock player. To get the real IP, set Forward real player IP at BlackProtect to On – first packet only (recommended) and enable it in Geyser's config.yml in the bedrock section:
bedrock:
port: 19132
enable-proxy-protocol: trueIf it's only on at one side, Bedrock players see the server but can't join. If BlackProtect says Off, Geyser needs enable-proxy-protocol: false.
Locking down the Bedrock port
Just like with Java, only our filter servers should reach the Geyser port. On your own Linux server with ufw it looks like this (addresses load live):
- Frankfurt
194.62.248.59 - Nuremberg
185.217.124.16
# Allow SSH first, or you will lock yourself out!
# (If SSH runs on a different port, use that instead of 22.)
sudo ufw allow 22/tcp
# Bedrock (Geyser) only for the BlackProtect filter servers
sudo ufw allow from 194.62.248.59 to any port 19132 proto udp
sudo ufw allow from 185.217.124.16 to any port 19132 proto udp
# Remove an old rule that allowed everyone (if there is one)
sudo ufw delete allow 19132/udp
sudo ufw enable
sudo ufw statusIf Geyser runs on another port, replace 19132 with yours. More on firewalls, including Docker and Pterodactyl: Hide your server IP.
Common problems
- Server shows in the list but joining fails: almost always the real-player-IP setting doesn't match on both sides (see above).
- Server doesn't show at all: check port and host at BlackProtect, whether Geyser is running, and whether the UDP port is open in the firewall for our filter servers.
- Error “no free Bedrock ingress available”: all Bedrock addresses are taken right now. Message us on Discord and we'll free up more.
Frequently asked questions
Can console players (Xbox, PlayStation, Switch) join?
Consoles can't add custom servers out of the box, only the featured ones. That's down to the consoles, not the protection. There are workarounds using special DNS settings that players have to set up themselves.
Does Floodgate keep working?
Yes. Floodgate lets Bedrock players join without a Java account and keeps working as usual.
Does Bedrock cost extra?
No, you can enable Bedrock for your route on every plan.
