BattlEye RCon for DayZ
How BattlEye RCon is configured for DayZ: config file, password, port, and RestrictRCon.
BattlEye ships with the DayZ dedicated server. Its RCon is configured in BEServer_x64.cfg on Windows and beserver_x64.cfg on Linux. The file is small. The three lines that matter are the RCon password, RConPort, and RestrictRCon. Everything else in that file is you copying advice you did not test. Set the three lines, restart, and prove a connection before you add opinions.
The password has a length limit of 32 characters and does not want spaces or the punctuation people use to look secure. A long passphrase with symbols will be rejected and you will think the port is closed. Use a random string that fits. Do not reuse the join password. Do not reuse a personal password. CFTools Cloud will ask for this string once when you connect the server. After that, your moderators use Cloud, not the string.
RConPort is a UDP port that is not the game port. The usual choice is the game port plus three: game 2302, RCon 2305. It can be another port. It cannot be a port you forgot to allow inbound. RestrictRCon 0 is required if you want kicks and bans to work from outside. A value of 1 looks like a security feature and then silently drops the commands you opened the port to send. The port guide has the firewall side, including the part where Linux and Windows name the file differently and the behavior stays the same.
Connect from outside the host. A test that only works from localhost proves the process is up and proves nothing about the route Cloud will use. If the provider blocks UDP, no cfg tweak fixes it. That is a provider problem. If you are on CFTools Architect, the host already expects this port to exist. You still set the password yourself. Architect does not publish it, and DayZ Manager does not display it.
RestrictRCon 0 means the password is the whole lock. Make the password good, and do not expose the cfg in a web file manager that other customers can browse. If a panel shows beserver_x64.cfg to every user on the machine, leave. Rotate the password after any moderator who saw it leaves the staff. Cloud's user list is the nicer version of "who can kick." The raw password should be in the cfg and in the Cloud connection, not in a pinned Discord message titled "for the boys."
When the connection works, stop using the BattlEye RCon tool on a PC that sleeps. One live session is enough to confirm the port. Day-to-day management belongs in Cloud, with a log. The command reference is what those buttons send. The admin log is why you want the buttons in a product that remembers them. A kick with no record is a fight you will relitigate in chat for a week.
Prove it from a laptop that is not the host
Edit the cfg, restart, and stop. The next test is not another key in the file. Join the server as a player from a normal connection, the same way a stranger would, using the address you expect to see on the server list. From a second network, connect the RCon client or CFTools Cloud. If the player list is empty while you are standing in the mission, you are talking to a different process or a different port. Two DayZ instances on one machine will do this to you without an error that says "wrong server." Name the profiles directories so you can tell them apart before the community can.
RestrictRCon 1 is the setting people copy from a security blog and then defend. It feels like a lock. In practice it lets a connection look half-alive and then drops the commands that justified opening the port. Set it to 0, make the password unguessable within the 32 character rule, and firewall the port to the world only because Cloud's egress is the world. If your provider offers a real allow-list and you know Cloud's addresses will not change, use it. If you are guessing addresses, you will lock yourself out during the incident you bought the tool for. A closed RCon port is not a hardened server. It is a server you have to drive to.
Windows and Linux differ in the filename and in how you notice the file was never read. On Windows, people edit a copy on the desktop and leave the real BEServer_x64.cfg next to the binary untouched. On Linux, the lowercase beserver_x64.cfg is easy to miss if you followed a Windows paste. After the restart, change the say text to something unique and look for that string. If you do not see it, the process did not load the file you edited. Search the machine for the filename before you blame the firewall.
When the test works, delete the local BattlEye shortcut from the PCs of people who should not have the password. Leave Cloud. Then look at your public row on the community list and on the open list if you did not set a join password. Neither page should mention 2305. The country page for the host will mention the region. That is the player-facing fact. RCon stays off the page. If a moderator later leaks the cfg into a ticket attachment, rotate the password the same day and assume the port was scanned. The rotation is one line and one Cloud reconnect, which is cheap if you are not also rotating it through six group chats.
Questions
Which file holds DayZ RCon settings?
BEServer_x64.cfg on Windows, beserver_x64.cfg on Linux.
What should RestrictRCon be?
0, if you want remote kicks and bans. 1 blocks those commands.
What is a safe RCon port?
Any free UDP port you actually open. The common choice is the game port plus three.