Enablers for Fortnite

Does anyone have enablers for Fortnite. My son is failing to “ready up” and I seem to be unblocking half the internet with forwarders. A huge amount of tcp:443 and a number of other ports.

Hey @NickH with some online games especially where they need P2P, the only option is to put them on a separate policy without DTTS or where the required ports are wide open.
Depending on the level of your network you could also put them on a separate VLAN to further isolate them.

Good question @NickH , I’m sure we’ll face that as we deploy into our teams homes. I’ll try turning off DTTS too and if there are any other tweaks we end up doing, will post them here.

I didn’t get to the bottom of it and had to move it to my unfiltered (which is really DNSHarmony without AdGuard) for the moment. My son had had enough waiting. There is a lot of tcp:443 traffic ot IPs. After 14 IP’s where I tried whitelisting the /24 subnet, I gave up and whitelisted 0.0.0.0/0.

There are all sorts of other ports as well. So far I’d got:
tcp:5228
udp:15018, 15046, 15066, 15104
udp:22222
tcp:27029
udp:33106

For these I did 0.0.0.0/0

I suspect the udp:15xxx is a range of ports as each time I whitelisted one and tried to get onlone again, another one would appear.

I also can’t guarantee these are all Fortnite (on a PC) because of other software running on the PC. I also can’t drive Fortnite so I need my son’s help. Apparently he was blocked from “readying up”, so joining a multi-player game.

I hope I can get to the bottom of this. I was trying to protect my son who has learning difficulties. So far, he is only protected by DNSHarmony.

I have found https://www.epicgames.com/help/en-US/c-Category_EpicGamesStore/c-EpicGamesStore_LauncherSupport/how-to-unblock-ports-to-connect-to-the-epic-games-launcher-and-fortnite-a000084740 but it does not specify if udp or tcp. This, Port Forwarding on Your Router for Fortnite, is more specific.

This has not been a good journey. I have it working now and will been some patience to narrow it down. I now have:
tcp:433, 5222, 5228,
tcp/udp:433, 3478-9, 5060, 5062, 6250, 9000-65000

I had to open the big range from 12000 to 9000 as I saw some entries popping into the logs in the 9000 range. They seemed to change every time my son “Readied Up”. This can probably be narrowed down a bit. UDP:443 was essential but not nice to open.

TBH, it may just be easier to turn off DTTS, but I don’t want to.

Not that I have specific knowledge of this game, but in general online games are P2P and will use random ephemeral ports.
And P2P is fundamentally incompatible with DTTS.