---
title: "TCP vs UDP: which protocol to use on each server | StreetHosting"
description: "Compare TCP and UDP in practice: delivery, ordering and latency, which games, APIs and voice services use each one, and how to open the right firewall port."
url: "https://streethosting.com.br/en/guides/infrastructure/tcp-vs-udp"
type: "page"
language: "en-US"
---

Infrastructure · 9 min · Intermediate

Published on Sep 28, 2026 · Updated on Sep 28, 2026

# TCP or UDP: how each protocol behaves in games, APIs and voice

TCP guarantees everything arrives, and in the right order. UDP delivers what it can without waiting for anyone. Understanding that trade explains why games and voice use UDP, why APIs use TCP and why opening lots of ports in the firewall does not work.

By [Equipe StreetHosting](https://streethosting.com.br/en/autores#equipe-streethosting) · StreetHosting infrastructure and support team

[Network, DNS and domains](https://streethosting.com.br/en/guides/topics/networking) [Security and hardening](https://streethosting.com.br/en/guides/topics/security)

Summarize with:

[](https://chat.openai.com/?q=Summarize%20the%20key%20points%20of%20this%20StreetHosting%20guide%3A%20https%3A%2F%2Fstreethosting.com.br%2Fen%2Fguides%2Finfrastructure%2Ftcp-vs-udp.%20Highlight%20the%20step-by-step%20instructions%2C%20the%20prerequisites%20and%20the%20most%20common%20mistakes. "ChatGPT") [](https://claude.ai/new?q=Summarize%20the%20key%20points%20of%20this%20StreetHosting%20guide%3A%20https%3A%2F%2Fstreethosting.com.br%2Fen%2Fguides%2Finfrastructure%2Ftcp-vs-udp.%20Highlight%20the%20step-by-step%20instructions%2C%20the%20prerequisites%20and%20the%20most%20common%20mistakes. "Claude") [](https://www.google.com/search?udm=50&aep=11&q=Summarize%20the%20key%20points%20of%20this%20StreetHosting%20guide%3A%20https%3A%2F%2Fstreethosting.com.br%2Fen%2Fguides%2Finfrastructure%2Ftcp-vs-udp.%20Highlight%20the%20step-by-step%20instructions%2C%20the%20prerequisites%20and%20the%20most%20common%20mistakes. "Google AI Mode") [](https://x.com/i/grok?text=Summarize%20the%20key%20points%20of%20this%20StreetHosting%20guide%3A%20https%3A%2F%2Fstreethosting.com.br%2Fen%2Fguides%2Finfrastructure%2Ftcp-vs-udp.%20Highlight%20the%20step-by-step%20instructions%2C%20the%20prerequisites%20and%20the%20most%20common%20mistakes. "Grok") [](https://www.perplexity.ai/search/new?q=Summarize%20the%20key%20points%20of%20this%20StreetHosting%20guide%3A%20https%3A%2F%2Fstreethosting.com.br%2Fen%2Fguides%2Finfrastructure%2Ftcp-vs-udp.%20Highlight%20the%20step-by-step%20instructions%2C%20the%20prerequisites%20and%20the%20most%20common%20mistakes. "Perplexity")

Share:

[](https://x.com/intent/tweet?text=TCP%20vs%20UDP%3A%20which%20protocol%20to%20use%20on%20each%20server&url=https%3A%2F%2Fstreethosting.com.br%2Fen%2Fguides%2Finfrastructure%2Ftcp-vs-udp "Share on X") [](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Fstreethosting.com.br%2Fen%2Fguides%2Finfrastructure%2Ftcp-vs-udp "Share on Facebook") [](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Fstreethosting.com.br%2Fen%2Fguides%2Finfrastructure%2Ftcp-vs-udp "Share on LinkedIn") [](https://wa.me/?text=TCP%20vs%20UDP%3A%20which%20protocol%20to%20use%20on%20each%20server%20https%3A%2F%2Fstreethosting.com.br%2Fen%2Fguides%2Finfrastructure%2Ftcp-vs-udp "Share on WhatsApp")

For agents: Copy as Markdown [.md](https://streethosting.com.br/en/guides/infrastructure/tcp-vs-udp.md)

In this guide 8 sections

* [The difference that matters](https://streethosting.com.br/en/guides/infrastructure/tcp-vs-udp#diferenca)
* [How TCP works](https://streethosting.com.br/en/guides/infrastructure/tcp-vs-udp#como-tcp-funciona)
* [How UDP works](https://streethosting.com.br/en/guides/infrastructure/tcp-vs-udp#como-udp-funciona)
* [Who uses which protocol](https://streethosting.com.br/en/guides/infrastructure/tcp-vs-udp#quem-usa-o-que)
* [Games, voice, APIs and web](https://streethosting.com.br/en/guides/infrastructure/tcp-vs-udp#casos-de-uso)
* [Opening and testing ports](https://streethosting.com.br/en/guides/infrastructure/tcp-vs-udp#firewall-e-testes)
* [UDP, TCP and attacks](https://streethosting.com.br/en/guides/infrastructure/tcp-vs-udp#ddos)
* [Where to run it](https://streethosting.com.br/en/guides/infrastructure/tcp-vs-udp#onde-rodar)

Quick answer

In **TCP vs UDP**, the choice is between reliability and predictable latency. TCP guarantees that everything arrives in the right order, which is why websites, APIs, SSH, databases and Minecraft Java use it. UDP delivers without waiting for a resend, which is why it is the default for action games, voice, live video, DNS and VPNs. In practice you do not choose: the program decides the protocol, and your job is to open the port with the right protocol in the firewall.

## The difference that matters[](https://streethosting.com.br/en/guides/infrastructure/tcp-vs-udp#diferenca)

TCP and UDP are transport protocols: they sit between IP, which carries the packet from one machine to another, and the application, which decides what to send. Both use ports to keep the services on one machine apart, which is why a firewall rule always names the port and the protocol together. Port 25565 on TCP and port 25565 on UDP are different things.

The real difference shows up when the network misbehaves. Every network drops a packet now and then. TCP treats a loss as something that has to be fixed before moving on. UDP does not handle loss at all and leaves the decision to the application. Neither is better than the other: each one suits a different kind of data.

| Feature            | TCP                                        | UDP                                   |
| ------------------ | ------------------------------------------ | ------------------------------------- |
| Connection         | Opens with a handshake before sending data | None, every packet is independent     |
| Delivery           | Guaranteed, with acknowledgment and resend | No guarantee, what gets lost is gone  |
| Ordering           | Always in sending order                    | May arrive out of order or duplicated |
| Header             | 20 bytes at minimum                        | 8 bytes                               |
| Congestion control | Yes, slows down when there is loss         | No, the application decides           |
| Effect of a loss   | Pauses the flow until the resend arrives   | Only that one packet is missing       |
| Typical uses       | Web, APIs, SSH, databases, email           | Action games, voice, DNS, VPN, QUIC   |

## How TCP works[](https://streethosting.com.br/en/guides/infrastructure/tcp-vs-udp#como-tcp-funciona)

Before any data is sent, client and server exchange three messages: `SYN`, `SYN/ACK` and `ACK`. That handshake costs one full round trip. On an API over HTTPS, TLS adds another trip before the first useful byte, which is why latency weighs so heavily on applications that open many short connections.

After that, every segment sent gets an acknowledgment. If the acknowledgment does not arrive in time, TCP resends. The receiver only hands data to the application in order: if segment 5 was lost, segments 6, 7 and 8 wait in the buffer until 5 arrives. This effect is called head of line blocking, and it is why a small loss turns into a stall followed by a burst of data.

TCP also controls congestion. When it notices a loss, it reduces the amount of data in flight and then speeds up again gradually. That is great for sharing a link among many users and terrible for anyone who needs a constant rate in real time. The relationship between loss, latency and throughput comes up again in the guide on [ping, jitter and packet loss](https://streethosting.com.br/en/guides/infrastructure/ping-vs-jitter-vs-packet-loss).

## How UDP works[](https://streethosting.com.br/en/guides/infrastructure/tcp-vs-udp#como-udp-funciona)

UDP is little more than an envelope with a source port, a destination port, a length and a checksum. There is no connection, no acknowledgment and no resend. The application sends the datagram and moves on. If it arrives, great; if it does not, nobody tells you.

It sounds fragile, but it is exactly what a game needs. The server sends the world state dozens of times per second. If one update is lost, the next one already carries the new position, and waiting for the old one would only delay everything. When something really does have to arrive, like a purchase command, the game itself numbers the message and resends it on its own, without stalling the rest of the flow.

UDP datagrams too large for the path end up fragmented, and losing a single fragment discards the whole datagram. That is why well built protocols on top of UDP keep their packets small. The details are in [what MTU is and how it affects your connection](https://streethosting.com.br/en/guides/infrastructure/what-is-mtu).

The line got blurrier with QUIC, the foundation of HTTP/3. It runs on UDP port 443 but implements acknowledgment, resend and encryption on its own, without TCP's head of line blocking between different streams. When a site announces HTTP/3 support, the browser starts using QUIC and falls back to TCP if UDP port 443 is blocked along the path.

## Who uses which protocol[](https://streethosting.com.br/en/guides/infrastructure/tcp-vs-udp#quem-usa-o-que)

The table lists the default ports of common services on a VPS. Ports can be changed in each program's configuration, so confirm in the documentation for the version you use.

| Service           | Default port    | Protocol                          |
| ----------------- | --------------- | --------------------------------- |
| SSH               | 22              | TCP                               |
| HTTP and HTTPS    | 80 and 443      | TCP, and UDP 443 for HTTP/3       |
| DNS               | 53              | UDP, with TCP for large responses |
| MySQL and MariaDB | 3306            | TCP                               |
| PostgreSQL        | 5432            | TCP                               |
| WireGuard         | 51820           | UDP                               |
| Minecraft Java    | 25565           | TCP                               |
| Minecraft Bedrock | 19132           | UDP                               |
| CS2               | 27015           | UDP for the game, TCP for RCON    |
| FiveM             | 30120           | TCP and UDP                       |
| Rust              | 28015 and 28016 | UDP for the game, TCP for RCON    |
| Palworld          | 8211            | UDP                               |
| Terraria          | 7777            | TCP                               |

## Games, voice, APIs and web[](https://streethosting.com.br/en/guides/infrastructure/tcp-vs-udp#casos-de-uso)

* **Action games:** FPS, battle royale and survival games use UDP. A small loss becomes a position jump or an unregistered shot, but the game does not freeze. A high loss shows up as teleporting and rubber banding.
* **Minecraft Java:** this is the famous exception, because it runs over TCP. On a good network, nobody notices. With loss, the player sees the world stop for a moment and then everything happens at once, which is head of line blocking in action.
* **Voice and live video:** they use UDP. Audio that arrived late is useless, so the app keeps a small buffer to absorb variation and the codecs mask short losses. High loss turns into robotic or choppy voice.
* **APIs and websites:** they use TCP because half a JSON response is useless. Latency here is multiplied by the number of trips: TCP handshake, TLS handshake, request. Keeping connections open with keepalive and using HTTP/2 reduces that cost.
* **Databases and SSH:** always TCP. Every byte of the command or the query has to arrive intact and in order.
* **VPN:** WireGuard uses UDP only, and OpenVPN works better over UDP. Putting TCP inside TCP creates two layers of resends fighting each other, which drags throughput down when the network drops packets.

## Opening and testing ports[](https://streethosting.com.br/en/guides/infrastructure/tcp-vs-udp#firewall-e-testes)

The most common mistake on a new game server is opening the port on TCP when the game uses UDP, or the other way around. In UFW, always give the protocol:

`sudo ufw allow 25565/tcp # Minecraft Java sudo ufw allow 19132/udp # Minecraft Bedrock sudo ufw allow 30120 # FiveM: without a protocol, opens TCP and UDP sudo ufw status numbered`

Then confirm that the program is actually listening and on which protocol. In the output, TCP sockets show up as `LISTEN` and UDP sockets as `UNCONN`, which is normal for UDP:

`sudo ss -tulpn`

Testing TCP from outside is simple, because there is a handshake: if it completes, the port is open. On Linux or Mac use `nc -zv IP_DA_VPS 25565`; in Windows PowerShell, `Test-NetConnection IP_DA_VPS -Port 25565`.

UDP has no handshake, so no test from outside can tell you for sure whether the port is open. The reliable way is to check on the server side whether the packet arrived:

1. On the VPS, leave tcpdump listening on the port: `sudo tcpdump -ni any udp port 19132`
2. From your computer, send a datagram: `echo teste | nc -u -w1 IP_DA_VPS 19132`
3. If the packet line shows up in tcpdump, the network and the firewall are open. If the game still does not respond, the problem is in its configuration, not in the port.

The rules, the evaluation order and the Docker pitfalls are covered in the guide on [UFW firewall on an Ubuntu VPS](https://streethosting.com.br/en/guides/vps/ufw-firewall-ubuntu-vps). If the server is at your home and nothing gets through, on neither TCP nor UDP, check whether your internet connection uses [CGNAT](https://streethosting.com.br/en/guides/infrastructure/what-is-cgnat).

## UDP, TCP and attacks[](https://streethosting.com.br/en/guides/infrastructure/tcp-vs-udp#ddos)

The lack of a handshake has a downside. Because UDP does not confirm who is on the other end, it is easy to forge the source address. That allows amplification attacks: the attacker sends a small question to thousands of DNS, NTP or similar servers with your IP as the source, and the large responses all land on your server. UDP game servers are frequent targets of this kind of flood.

TCP has its own weakness, the SYN flood, which tries to exhaust the table of half-open connections. Linux defends against it with SYN cookies, enabled by default. Neither volumetric attack can be solved with a firewall inside the VPS, because the link arrives saturated before the firewall ever sees the packet. Filtering has to happen at the network edge, as the guide on [Anti-DDoS for game servers](https://streethosting.com.br/en/guides/infrastructure/anti-ddos-game-server-brazil) explains, and the breakdown of attacks by layer is in [DDoS at layers 3, 4 and 7](https://streethosting.com.br/en/guides/infrastructure/layer-3-vs-layer-4-vs-layer-7-ddos).

Never leave UDP infrastructure services open to the internet without a reason, such as a recursive DNS resolver or an old NTP server. They become reflectors in attacks against third parties and can get your IP onto blocklists.

## Where to run it[](https://streethosting.com.br/en/guides/infrastructure/tcp-vs-udp#onde-rodar)

On a [StreetHosting VPS](https://streethosting.com.br/en/vps) you get root access and control the firewall, so you can open any combination of port and protocol your service requires. The VPS plans run in São Paulo, with a 1 Gbps uplink and Anti-DDoS included, which matters especially for a UDP game server.

* **Game server:** the [Ryzen 9 9950X VPS](https://streethosting.com.br/en/vps/ryzen) has a clock speed of up to 5.7 GHz and DDR5 memory, which helps games that simulate the world on a few threads. It ranges from R$ 40.00 (1 vCPU, 2 GB, 20 GB NVMe) to R$ 846.00 (14 vCPU, 64 GB, 640 GB NVMe), with intermediate steps such as R$ 118.00 for 4 vCPU and 8 GB.
* **API, website or database:** the Xeon VPS delivers more vCPU per real, from R$ 26.00 (2 vCPU, 2 GB, 20 GB NVMe) to R$ 553.00 (24 vCPU, 64 GB, 640 GB NVMe), good for workloads with many parallel TCP connections.

Activation happens within 60 seconds after payment by Pix, boleto or card, and upgrading through the control panel charges only the proportional difference when your service grows.

In this guide

* [The difference that matters](https://streethosting.com.br/en/guides/infrastructure/tcp-vs-udp#diferenca)
* [How TCP works](https://streethosting.com.br/en/guides/infrastructure/tcp-vs-udp#como-tcp-funciona)
* [How UDP works](https://streethosting.com.br/en/guides/infrastructure/tcp-vs-udp#como-udp-funciona)
* [Who uses which protocol](https://streethosting.com.br/en/guides/infrastructure/tcp-vs-udp#quem-usa-o-que)
* [Games, voice, APIs and web](https://streethosting.com.br/en/guides/infrastructure/tcp-vs-udp#casos-de-uso)
* [Opening and testing ports](https://streethosting.com.br/en/guides/infrastructure/tcp-vs-udp#firewall-e-testes)
* [UDP, TCP and attacks](https://streethosting.com.br/en/guides/infrastructure/tcp-vs-udp#ddos)
* [Where to run it](https://streethosting.com.br/en/guides/infrastructure/tcp-vs-udp#onde-rodar)

## Frequently asked questions

What is the difference between TCP and UDP?

TCP opens a connection, acknowledges every piece it receives, resends whatever got lost and delivers everything in order. UDP just sends packets, with no connection, no acknowledgment and no resend. TCP trades latency for reliability, and UDP trades reliability for predictable latency.

Is UDP faster than TCP?

Not in transfer speed. The difference shows up when there is loss: TCP stops everything until it recovers the lost packet, while UDP keeps delivering the next ones. That is why UDP has steadier latency in real time, but it does not download a file any faster.

Why do online games use UDP?

Because a player position from 50 milliseconds ago is already worthless. With UDP, the game drops the lost packet and uses the next one instead of freezing while it waits for a resend. The game itself resends only what has to arrive, such as a purchase command or a chat message.

Do I need to open TCP and UDP on the same port?

Only when the service uses both, like FiveM on port 30120. Check the documentation for the game or program and open only the protocol it needs. In UFW, giving the port without a protocol opens both at once, which is convenient but opens more than necessary.

Does Minecraft use TCP or UDP?

Minecraft Java uses TCP on port 25565. Minecraft Bedrock uses UDP on port 19132. Some plugins and mods add their own ports, like Simple Voice Chat, which uses UDP on a separate port.

Next step

See VPS plans

Root VPS in Brazil with NVMe and Anti-DDoS.

[See VPS plans](https://streethosting.com.br/en/vps)

[See Ryzen VPS Ryzen 9 9950X VPS in São Paulo with root access, NVMe and gamer Anti-DDoS.](https://streethosting.com.br/en/vps/ryzen)

## Related guides

[VPS Beginner UFW on Ubuntu VPS: firewall rules without losing SSH UFW makes the Ubuntu firewall simpler, but one rule in the wrong order locks you out of your VPS. Learn how to enable it without losing SSH, open only what you need, deal with Docker, and get back in through the console if something goes wrong. 10 min Read guide](https://streethosting.com.br/en/guides/vps/ufw-firewall-ubuntu-vps) [Infrastructure Beginner Ping, jitter and packet loss: the difference in practice Ping measures how long the network takes, jitter measures how much that time varies and packet loss measures what never arrives. Each one ruins the experience in a different way, and knowing which one is bad is what decides the fix. 9 min Read guide](https://streethosting.com.br/en/guides/infrastructure/ping-vs-jitter-vs-packet-loss) [Infrastructure Intermediate What is MTU and how a wrong value breaks your connection MTU sets the largest packet that crosses a link without being split. When it is wrong somewhere along the path, the connection opens and ping answers, yet websites, VPNs and downloads still hang. 9 min Read guide](https://streethosting.com.br/en/guides/infrastructure/what-is-mtu)

[← Back to the Guide Center](https://streethosting.com.br/en/guides)
