How to Fix Roon Firewall, Local Network, and VLAN Issues

FAQ: Adding Roon as a Firewall Exception

Symptom Summary

If Roon Server or Roon Remote can't see other devices, zones, or your Roon Server on the network, a firewall or antivirus software may be blocking Roon's network access. This guide will walk you through checking your firewall settings and adding the appropriate exceptions.

Follow the steps below for Roon on Windows, macOS, or Linux. Using a Chromebook? Roon Server isn't supported on Chrome OS, but you can use the Roon Remote Android app instead. For Roon Remote on iPhone or iPad, see iOS Permission Settings.

Before You Begin

  1. Turn off the firewall on both the server and the remote device, if applicable.
  2. Restart Roon Server and the device.
  3. Try connecting again.

If your devices still aren't visible with the firewall turned off, skip ahead to Still Having Trouble? Something other than the firewall is likely causing the issue.

If your devices connect with the firewall turned off, turn it back on and continue below to add the correct exceptions.

Cause 1: Your Operating System's Firewall or Antivirus Is Blocking Roon

Info
If you're running Roon Server on a Nucleus or ROCK, you can skip this section. Roon OS manages its own network access, so there's no firewall to configure on the device itself.

Add Roon to your firewall or antivirus exceptions list using the applications below. We recommend allowing Roon by application name rather than by specific ports, since Roon uses a range of ports that can change between updates.

Windows: roon.exe, raatserver.exe, roonbridge.exe. For a headless server, also add roonserver.exe and roonappliance.exe.

macOS: roon.app, raatserver.app, roonbridge.app. For a headless server, also add roonserver.app and roonappliance.app.

Linux: roonserver.bin, raatserver.bin, roonbridge.bin, roonappliance.bin

Windows 10

Open Control Panel > Windows Firewall, click "Allow an app or feature through Windows Firewall," then "Change settings" > "Allow another app" > Browse to Roon, select it, and choose the Private network type.

Windows Firewall dialog showing Roon added as an allowed app on a Private network.

Windows 11

Open Windows Security > Firewall & network protection > "Allow an app through firewall" > "Change settings," enable Roon, and confirm the Private network type is selected. Administrator credentials are required.

The resulting dialog looks the same as the Windows 10 screenshot above, since Windows 11 just reaches it through a different menu path.

macOS

Open System Settings > Network > Firewall > Options, then add Roon using the "+" button.

macOS Firewall Options pane showing Roon added as an allowed app.

McAfee users should also see McAfee's firewall exception documentation, since McAfee manages its firewall separately from the macOS system firewall.

Linux

Configure your distribution's firewall, such as ufw or firewalld, to allow RoonServer, RAATServer, RoonBridge, and RoonAppliance to communicate on your local network.

Since firewall configuration varies between Linux distributions, please get in touch with our Technical Support team if you're unable to allow Roon by application name.

Cause 2: macOS Is Blocking Local Network Access Separately from the Firewall

Since macOS Sequoia, apps need separate Local Network permission to discover other devices. If this permission is turned off for Roon, Roon may not be able to find other devices on your network.

  1. Open System Settings.
  2. Go to Privacy & Security > Local Network.
  3. Find Roon (or RoonServer) in the list and turn the toggle on.
  4. Restart Roon.
macOS Local Network settings showing Roon permission enabled.

Notes
macOS may turn this permission off after a system update. If Roon disappears from the network after updating macOS, check this setting and restart Roon.

Cause 3: Your Network Uses VLANs or Multiple Subnets

Roon requires your Roon Server, endpoints, and Roon Remotes to all be on the same subnet. It doesn't support devices split across VLANs or separate subnets, even when firewall rules allow traffic through.

If you're running a segmented or enterprise-style network, such as a network using pfSense, see Networking Best Practices for supported network layouts.

Alert
Firewall exceptions will not fix discovery problems caused by VLANs or multiple subnets. Make sure your Roon Server, Remotes, and endpoints are on the same subnet.

A Note on Roon ARC

If you're setting up remote listening with Roon ARC rather than local discovery, see Getting Started With ARC. Roon ARC requires port 55000/TCP to be reachable, which is separate from the local firewall exceptions covered in this article.

Still Having Trouble?

If you've confirmed the correct application exceptions, checked the macOS Local Network permission where applicable, and confirmed that your devices are on the same subnet, please get in touch with our Technical Support team.