| ID | title | created | status | kind | author(s) | champions |
|---|---|---|---|---|---|---|
| NIP-14 | Nym Exit Policy Update – Opening Additional Ports for Applications and Community Services | 27-07-2026 | proposed | standard | Serinko, Nym network technical lead & devrel serinko@nymtech.net, Jaya, Chief of strategy jaya@nymtech.net | Merve, Operator technical mentor merve@nymtech.net, Sudo, Head of community simon.toth@nymtech.net |
NIP-14 proposes updating the Nym exit policy to open additional TCP and UDP ports requested by NymVPN users and the node operators community.
The goal is to improve compatibility with proxy services, gaming platforms, voice communication applications, decentralized services, remote desktop applications, and community-hosted infrastructure while maintaining privacy, security, and operator governance.
Motivation
The Nym exit policy defines which ports are accessible on exit nodes to ensure privacy, security, and reliable service.
The requested additions include:
- Proxy Services – require additional port ranges for SOCKS5 and HTTP proxy providers.
- DarkFi / DarkIRC Services – require TCP port 9600 for DarkIRC clearnet configuration support.
- Space Station 14 Services – require TCP/UDP port 1212 for game server communication.
- RustDesk Services – require ports for remote desktop infrastructure communication.
- Syncplay Services – require ports used by official and community Syncplay servers.
- Viber Services – require additional ports for Viber desktop communication.
- WhatsApp VoIP Services – require additional ports for voice and video calling.
- Nightfall.city Services – require port 1900 for community-hosted services.
- AnyDesk Services – require port 6568 for remote desktop communication.
- SPICE Services – require port 1923 for remote desktop protocol communication.
- Croc Services – require additional ports for peer-to-peer file transfer communication.
- Iroh Services – require UDP port 7842 for decentralized networking communication.
- Telegram Services – require UDP ports for group call support and STUN communication.
This update will follow operator governance, consistent with previous exit policy changes (example).
Since NIP-1, exit policy decisions are managed via Nym Governator to ensure transparency and accountability.
Proposal to Enable Ports for NymVPN Users
Proxy Services
Nodemaven SOCKS5 proxy services:
*:1080-2080
Nodemaven HTTP proxy services:
*:8081-9080
Proxy-seller services:
*:10001-10999
DarkFi / DarkIRC Services
DarkIRC clearnet communication:
*:9600
Space Station 14 Services
Game server communication:
*:1212
RustDesk Services
Remote desktop communication:
*:21114-21119
Syncplay Services
Syncplay server communication:
*:8995-8999
Viber Services
Viber desktop communication:
*:5242
*:5243
*:7985
WhatsApp VoIP Services
WhatsApp voice and video calling:
*:5224-5227
Nightfall.city Services
Nightfall.city communication:
*:1900
AnyDesk Services
Remote desktop communication:
*:6568
SPICE Services
Remote desktop protocol:
*:1923
Croc Services
Croc file transfer communication:
*:9009-9013
Iroh Services
Iroh communication:
*:7842
Telegram Services
Telegram group call support, STUN services:
*:32001-32003
Stragglers
Battlefield / EA:
*:3659
Magic Wormhole:
*:4001
Jitsi:
*:4443
Note: Some of the ports are within already opened ranges, but we keep them in the NIP for transparency. If the ranges already include the newly proposed ports, they will stay as they are.
Voting options
Voting takes place at Nym Governator. Proposed options:
- YES: Approve opening the above ports.
- NO: Reject the proposal entirely.
Submit any concerns with supporting documentation for review before finalizing.
Process
If the vote meets quorum and a majority approves:
- A pull request will update the exit policy.
- The Network Tunnel Manager (NTM) will be updated to allow operators to configure WireGuard exit policy ports in line with the Mixnet policy.
Background
The Nym exit policy protects operators and users by controlling accessible ports.
Previously, Network Requesters used a centralized allow list. To decentralize control and enhance privacy, Nym transitioned to a deny list, forming the current exit policy.
Exit nodes in Gateway mode act both as:
- SOCKS5 Network Requesters
- Exit nodes for IP traffic from mixnet and VPN clients
Applying a uniform policy ensures reliable, privacy-preserving service for all NymVPN users.