All locations active · 99.99% uptime
Automation Sandbox · Online Games

Factorio Proxy: Lockstep, Servers and Network Scope

Factorio multiplayer is a lockstep simulation that distributes player inputs rather than the world state. This structure makes connection problems look different from other games and puts the proxy decision on a different footing. This page builds that footing.

The topics this page covers

01
LockstepThe trace on the network of a simulation based on input distribution.
02
Server hostingHeadless servers, dedicated hosting and community servers.
03
Router scopeThe traffic actually covered by configuration made on the network device.
04
Closed portsTelling apart the layer of the block on campus and office networks.

Factorio's multiplayer architecture differs from most open-world games. The server does not continuously broadcast the whole world; instead it gathers each player's input, puts it in order and distributes it to all clients in the same order. Every client processes the same inputs in the same order and produces the same result. This approach is called lockstep simulation.

The consequence on the network side is this: the data carried is small but ordering and timing are critical. However large the factory grows, what flows over the line is player commands. In return, if a client falls out of the stream, resynchronisation is needed, and that is a far heavier operation than small packets.

This page first explains step by step how the connection is established, then covers server hosting options, the scope of configuration at router level and the route to follow on restricted networks.

How is a session based on input distribution established?

The connection proceeds in four stages, and the first three use a different transport layer from the fourth. When you list public servers and want to join, the client first sends an authentication request to the multiplayer service; this request is web traffic and runs over TCP. Likewise, the server list itself comes from the application layer.

The second stage is version and mod matching. For the lockstep simulation to work, all clients must compute with the same code and the same data set. If the version or the mod list does not match, the connection ends before it even starts; this is the most common case that looks like a network problem but has nothing to do with the network.

The third stage is the transfer of the save file. The joining client receives the world state up to that moment from the server. In a large factory this transfer takes a noticeable amount of time and is the most voluminous moment of the connection. You cannot enter the game before the transfer is complete.

The fourth stage is the input stream that covers the rest of the session. This stream is carried over UDP and consists of continuous but small packets. A classic HTTP proxy cannot touch this stage at all; in the first three stages, routing is possible.

In games opened on a local network the first two stages are shortened or skipped entirely: the client finds the server directly by address and needs no authentication step. That is why a session that is established without trouble in the same house can give a completely different error when you try to establish it over the internet. When comparing the two scenarios, telling which stages are in play is the first step of diagnosis.

DIAGRAMThe chain by which a Factorio session is established
The chain by which a Factorio session is establishedFour-box flow: authentication, server list, save file transfer and input stream.FLOW01AuthenticationWeb request to themultiplayer service, over TCP02Server listCommunity serversfrom the application layer03Save transferThe world state is copied from the serverto the client04Input streamLockstep simulationcontinues with datagramsThe first three steps TCP, the fourth UDP

The first three links proceed at the application layer and can fall within proxy scope; the fourth carries datagrams and requires client support.

The timeline of the joining moment and where it gets stuck

The most useful tool in problem diagnosis is determining at which step the connection stops. If you get stuck at the authentication step, the problem is in web traffic: an access block, a closed endpoint or an incorrect proxy definition. Since this step falls within the proxy's scope, a hitch here can be fixed with configuration.

Getting stuck at version matching is entirely outside the network. The mod list and version number must match exactly; a missing mod or a different sub-version ends the connection. Looking for this error on the network side costs hours.

Getting stuck during the save file transfer is about bandwidth. If the transfer proceeds slowly, either the server's upload speed is limited or an intervening layer is throttling it. If you are connecting through a proxy, this step is the most honest test of your exit's real capacity.

Drops during the input stream, on the other hand, are on the UDP side, and in most setups the proxy is not even in play at this stage. What to look at here is the local network, the access line and the server's own connection. Ping test A long-duration measurement taken with narrows down at which end the loss arises.

DIAGRAMStep-by-step chart of the joining moment
Step-by-step chart of the joining momentFour-row vertical timeline: connection request, version and mod matching, save transfer and entry into the simulation.TIMELINEstep 1Connection requestsThe client reaches the server and starts the handshakestep 2Version and mod matchingThe code and data set must match exactlystep 3Save file transferThe most voluminous moment of the session; it shows the bandwidthstep 4Entry into the simulationThe client joins the step order and the game begins

Knowing at which row the connection stops is the only information needed for diagnosis; each row has a different fault profile.

Exit options for your Factorio server and client

Choose the right exit type for access lists that require a fixed address and for external verification tests.

Choose whichever you need from our residential proxies, datacenter proxies, IPv6 and ISP solutions. Every plan comes with unlimited options, 99.9% uptime, rotating proxies, sticky sessions and 24/7 support. Ideal for web scraping, ad verification, SEO monitoring and digital data collection.

ISP ProxyStatic Turkish IPs registered to an ISP

ISP-registered static Türkiye IPs; they combine datacenter speed with the reputation of a real carrier. Ideal for long sessions and low-ping use.

150₺/mo

Starting price for 1 month

500–1000 Mbit130+ SubnetsDDoS Protection
View Plans

PACKAGE CONTENTS

  • Vodafone and Türk Telekom carriers
  • DDoS protection
  • Personalized setup
  • The lowest ping values
  • 500-1000 Mbit down/up speed
  • HTTP & SOCKS5 protocol support
  • Automatic delivery
  • Turkey location

For social media management and anyone who wants long sessions with low ping.

Read product details
Mobile Proxy4G/5G carrier IPs

The most natural mobile traffic, on 4G carrier IPs; high success rates even on the strictest platforms. Ideal for social media and automation work.

239₺/day

Starting daily price

LTE 4G15-40 MbpsDedicated SIM
View Plans

PACKAGE CONTENTS

  • LTE 4G mobile connection
  • Vodafone · Turkcell · Türk Telekom
  • 30 GB quota
  • 15-40 Mbps connection speed
  • Dedicated SIM card infrastructure
  • Username & password or IP:Port
  • IP change link
  • HTTPS / SOCKS5 (UDP)

Ideal for social media and gaming users; a good fit for individuals.

Read product details
Residential ProxyReal home-user IP pool

A real home-user IP pool, for the highest trust and the widest geographic coverage. The right choice for data collection and regional testing.

350₺/30 Days

Starts at 5 GB / 30 days

50K Connections190+ CountriesSticky Session
View Plans

PACKAGE CONTENTS

  • Real residential (home-user) IP pool
  • Rotating and sticky sessions
  • City and state targeting
  • HTTP(S) and SOCKS5 protocols
  • 24/7 priority support
  • Activation in 2 minutes
  • Suitable for social media management
  • Flexible session management

The right choice for data collection, regional testing and multi-account management.

Read product details
IPv6 ProxyA large next-generation IPv6 pool

A large IPv6 pool; an economical solution for high-volume, cost-sensitive projects. Google Ads compatible and future-proof.

100₺/plan

Starts at 100 units (total)

/64 Subnet100-500 MbitNetfactor ISP
View Plans

PACKAGE CONTENTS

  • Netfactor / Turknet ISP infrastructure
  • Google Ads compatible IPv6s
  • /64 subnet options
  • HTTP & HTTP(S) support
  • Automatic delivery
  • Unused (clean) IP pool
  • 100-500 Mbit speed
  • Large IPv6 address pool

For anyone who needs Google Ads compatibility, high-volume use and an economical solution.

Read product details

You can also explore our Rotating Proxy and Datacenter Proxy you can explore our solutions, and to try them out our free proxy list you can use.

Connection states and the moments when a proxy is effective

A session moves among several states, and each state has its own fault profile. The moment of connecting is full of handshakes and verifications; an error received at this stage usually comes with a clear message. An interruption during the map transfer, on the other hand, is silent: progress stops, the error message comes late.

While in the synced state, client and server advance at the same step. If a client falls behind, the game slows down for it or the client is put into resynchronisation. Since resynchronisation means the world state being transferred again, it consumes bandwidth and interrupts the session.

In this state map, a proxy plays a meaningful role only at the first stage. Authentication and server list requests carry TCP; using an exit to reach these endpoints from a network with restricted access can make sense. The same does not apply to the game stream itself. SOCKS5 although datagram transfer is possible in theory, it requires client support; SOCKS5 UDP support the article details this condition.

Note

Frequent resynchronisation is usually a sign not of an unstable connection but of one of the clients not having enough processing power. Eliminate this possibility before examining the network side.

DIAGRAMThe connection states a client passes through
The connection states a client passes throughA state chain of five circles: connecting, receiving map, synced, resyncing and left.STATESConnectinghandshakeMapbeing receivedtransferSyncedstep orderRe-syncre-transferLeft

Transitions between states determine the fault profile; resynchronisation is the most costly transition.

Three ways to host your own server

The first way is for the player who opens the game to be the server at the same time. It is the simplest option to set up but has two costs: when the person who started the session leaves, the game stops, and every hitch on that person's home connection is reflected on all players. Sufficient for small groups, fragile for a team that plays regularly.

The second way is a headless server: a process that runs without a graphical interface and only executes the simulation. You can run it on your own machine or on a server you rent. The configuration is read from a text file, the port to listen on is defined there too and can be changed. This route frees the session from depending on the presence of a single player.

The third way is community servers. Here the one setting the rules is not you but the server administrator: accepted addresses, player count, mod list and rules of conduct are all defined by them. A connection being refused may not be a technical fault but the enforcement of that policy, and the right step is to get in touch with the administrator.

When you open your own server to the outside, verifying reachability is a separate job. A test made from inside your own network is misleading, because the packet never leaves for the outside world. A check made from a different line shows the real situation; tools such as proxy checker tool can be used to see whether an endpoint responds from outside. For the difference between the inbound direction on the server side and the outbound direction on the client side, the difference between forward and reverse proxies article.

What does configuration on the router cover?

The idea of defining a proxy on the home router looks attractive: let all devices be routed from a single point. The real scope, however, is narrower than supposed. Most consumer-grade devices have no setting that routes outbound traffic to a proxy; on those that do, this setting generally covers only web traffic. For details, using a proxy via the router article.

There are two concepts that get confused: address translation and a proxy are not the same thing. What your router does is map the addresses on the internal network to a single external address; this is a mapping operation working at the transport layer and it does not send the traffic to another server. A proxy, on the other hand, is an intermediary that terminates the connection and re-establishes it on its own behalf. The difference between the two difference between a proxy and NAT article.

This distinction has a practical consequence on the Factorio side. If you host your own server on your home network, what you need to do is not a proxy definition but the forwarding of incoming connections to the internal machine. These two operations are done in different menus, with different logic, and one is no substitute for the other.

The scope table clarifies which configuration affects what:

Configuration locationTraffic it affectsEffect on the game session
Router, outbound routingGenerally only web trafficNext to none
Router, inbound routingConnections coming from outside to the internal serverDecisive if you host a server
Operating system settingMost TCP-based applicationsCovers authentication and list requests
Application-based ruleOnly the selected processDepends on client support

Finding the layer of the block on networks with closed ports

On dormitory, campus and office networks, outbound traffic is mostly limited to a narrow set. Web traffic is free, the rest is closed. On such a network it is a typical picture for the authentication and server list steps to pass without trouble while the game stream cannot be established, and the reason is directly this policy.

Here you first have to separate the layer of the block. A block at the application layer is the closing of access to a specific domain name and looks like a problem that can be overcome by using an exit; a block at the transport layer, on the other hand, is the complete closing of certain protocols, and having a server in between does not change that. The latter is the case that applies to Factorio's game stream.

The right approach is the administrative one: conveying the destination, the protocol and the purpose to the network administrator in writing. Defined exceptions are normal on corporate and academic networks. Trying to work around network policy by technical means is against institutional rules and does not produce a lasting solution. The general framework access blocks on school and workplace networks article.

There is also an intermediate case: if the network allows outbound access but your address comes from a dynamic pool, defining an access list for your server becomes difficult. In such cases a fixed exit address helps; how the gateway architecture provides this gateway architecture article.

Mod lists, updates and download traffic

In a group that uses mods, part of the network traffic also comes from the mod portal. Mod download and update requests are web traffic; they therefore fall within proxy scope and may be the only component that is unreachable on a restricted network. If the game stream works but the mod list cannot be fetched, it becomes clear that the block is at the application layer.

On the volume side, mod traffic is larger than the game session but generally smaller than the save file transfer. If you are using an exit with a quota counter, the real thing to watch is update periods; when a group updates a large mod package at the same time, the total volume rises fast.

Version consistency is, moreover, not a network matter but a coordination matter. Since the lockstep simulation requires all clients to run the same code, fixing the mod list within the group is the most practical solution. Otherwise every session starts with a round of version matching, and that is mistaken for a connection problem.

An in-group update schedule makes this easier: mod versions are fixed before the session rather than during it, and the change is applied to everyone at the same time. The party hosting the server has to use the same list as well; even the smallest difference between the server and the clients prevents joining. This is a matter of discipline independent of network configuration, and in groups that play regularly it eliminates a significant portion of connection complaints.

If you hesitate over what the terms correspond to, a short glossary makes your job easier; for the transport layer and relay concepts mentioned on this page, proxy terms glossary is a quick reference source.

Compliance, server rules and realistic expectations

Community servers hold an important place around Factorio and each has its own rules. Using an intermediary server does not change those rules, it only changes the address the connection comes from. The server administrator's choice not to accept certain address ranges is legitimate and should not be read as a technical fault.

This page is not intended to interfere with anti-cheat mechanisms, nullify account sanctions or work around institutional network policies. Such expectations are both contrary to agreements and technically unfounded.

The realistic expectation is this: on the Factorio side a proxy is a routing tool for the components that carry TCP — authentication, the server list, the mod portal and external verification of the server you host. Since the game stream itself carries UDP, it stays out of scope in most setups, and a configuration built in the knowledge of that puts the expectation in the right place.

One last reminder: every hop added in between adds to latency, it does not subtract from it. A proxy does not lower your ping; the rarely seen exception is the case where the default route is circuitous and a more direct path is proven by measurement. Build your setup decision on that fact.

Common questions about Factorio and proxies

01Which step does a proxy affect in Factorio multiplayer?

Authentication, the server list and mod portal requests are web traffic; these are affected by a proxy definition. Since the game stream carries datagrams, it stays out of scope in most setups and requires the relevant protocol support in the client.

02No one can connect to my server from outside — should I set up a proxy?

No, this is an inbound connection problem. What needs to be done is to forward incoming connections on the router to the internal machine; a proxy definition does not do that job. Verify reachability not from your own network but from a different line.

03Why does resynchronisation happen so often?

This is usually a sign not of the connection but of one client not keeping up with the simulation speed. In large factories, processing power becomes decisive. Eliminate the hardware side before examining the network side; if the problem persists, take a long-duration latency measurement.

04If I define a proxy on the router, will all devices be routed?

Most consumer-grade devices have no such setting; on those that do, the scope is generally limited to web traffic. Besides, address translation and a proxy are different things: one maps addresses, the other re-establishes the connection on its own behalf.

05The game stream will not establish on my campus network — what is the solution?

If the block is at the transport layer, having an exit in between does not change the outcome. The right route is to convey the destination and the purpose to the network administrator in writing and to request a defined exception. A block at the application layer presents a different picture.

06Will the game be smoother if I use a proxy?

Every hop added in between adds to latency; a proxy does not lower your ping. The rare exception is the case where your default route is circuitous and a more direct path is proven by a before-and-after measurement. This is not a rule but a possibility that has to be measured.

07What is the network difference between a headless server and a normal server?

In terms of network behaviour there is no marked difference; both listen on a port defined in the configuration. The difference is in operation: a headless server runs without a graphical interface, frees the session from depending on the presence of a single player and is suited to continuous running.

Further reading

NEXT STEP

Clarify the network side of your Factorio server.

Fixed exit, external verification and web traffic routing are managed from a single panel.

FREEPROXY.TR

Looking for a free proxy? You're in the right place

A complete proxy platform where you can browse up-to-date free proxy addresses, compare HTTP and SOCKS proxy types, and check your proxy connections with free tools.