# NIP-14: Nym Exit Policy Update – Opening Additional Ports for Applications and Community Services

ID title created status kind author(s) champions
NIP-14 Nym Exit Policy Update – Opening Additional Ports for Applications and Community Services 27-07-2026 proposed standard Serinko, Nym network technical lead & devrel serinko@nymtech.net, Jaya, Chief of strategy jaya@nymtech.net Merve, Operator technical mentor merve@nymtech.net, Sudo, Head of community simon.toth@nymtech.net

NIP-14 proposes updating the Nym exit policy to open additional TCP and UDP ports requested by NymVPN users and the node operators community.

The goal is to improve compatibility with proxy services, gaming platforms, voice communication applications, decentralized services, remote desktop applications, and community-hosted infrastructure while maintaining privacy, security, and operator governance.

Motivation

The Nym exit policy defines which ports are accessible on exit nodes to ensure privacy, security, and reliable service.

The requested additions include:

  • Proxy Services – require additional port ranges for SOCKS5 and HTTP proxy providers.
  • DarkFi / DarkIRC Services – require TCP port 9600 for DarkIRC clearnet configuration support.
  • Space Station 14 Services – require TCP/UDP port 1212 for game server communication.
  • RustDesk Services – require ports for remote desktop infrastructure communication.
  • Syncplay Services – require ports used by official and community Syncplay servers.
  • Viber Services – require additional ports for Viber desktop communication.
  • WhatsApp VoIP Services – require additional ports for voice and video calling.
  • Nightfall.city Services – require port 1900 for community-hosted services.
  • AnyDesk Services – require port 6568 for remote desktop communication.
  • SPICE Services – require port 1923 for remote desktop protocol communication.
  • Croc Services – require additional ports for peer-to-peer file transfer communication.
  • Iroh Services – require UDP port 7842 for decentralized networking communication.
  • Telegram Services – require UDP ports for group call support and STUN communication.

This update will follow operator governance, consistent with previous exit policy changes (example).

Since NIP-1, exit policy decisions are managed via Nym Governator to ensure transparency and accountability.

Proposal to Enable Ports for NymVPN Users

Proxy Services

Nodemaven SOCKS5 proxy services:

*:1080-2080

Nodemaven HTTP proxy services:

*:8081-9080

Proxy-seller services:

*:10001-10999

DarkFi / DarkIRC Services

DarkIRC clearnet communication:

*:9600

Space Station 14 Services

Game server communication:

*:1212

RustDesk Services

Remote desktop communication:

*:21114-21119

Syncplay Services

Syncplay server communication:

*:8995-8999

Viber Services

Viber desktop communication:

*:5242
*:5243
*:7985

WhatsApp VoIP Services

WhatsApp voice and video calling:

*:5224-5227

Nightfall.city Services

Nightfall.city communication:

*:1900

AnyDesk Services

Remote desktop communication:

*:6568

SPICE Services

Remote desktop protocol:

*:1923

Croc Services

Croc file transfer communication:

*:9009-9013

Iroh Services

Iroh communication:

*:7842

Telegram Services

Telegram group call support, STUN services:

*:32001-32003

Stragglers

Battlefield / EA:

*:3659

Magic Wormhole:

*:4001

Jitsi:

*:4443

Note: Some of the ports are within already opened ranges, but we keep them in the NIP for transparency. If the ranges already include the newly proposed ports, they will stay as they are.

Voting options

Voting takes place at Nym Governator. Proposed options:

  • YES: Approve opening the above ports.
  • NO: Reject the proposal entirely.

Submit any concerns with supporting documentation for review before finalizing.

Process

If the vote meets quorum and a majority approves:

  1. A pull request will update the exit policy.
  2. The Network Tunnel Manager (NTM) will be updated to allow operators to configure WireGuard exit policy ports in line with the Mixnet policy.

Background

The Nym exit policy protects operators and users by controlling accessible ports.

Previously, Network Requesters used a centralized allow list. To decentralize control and enhance privacy, Nym transitioned to a deny list, forming the current exit policy.

Exit nodes in Gateway mode act both as:

  • SOCKS5 Network Requesters
  • Exit nodes for IP traffic from mixnet and VPN clients

Applying a uniform policy ensures reliable, privacy-preserving service for all NymVPN users.

@rwrv1 @Numbless @Lando

1 Like