# What Are croc's Default Relay Ports and How Does Multiplexing Help

> Discover croc's default relay ports 9009-9013 and how multiplexing enables faster, more resilient file transfers using multiple parallel TCP streams.

- Repository: [Zack/croc](https://github.com/schollz/croc)
- Tags: deep-dive
- Published: 2026-07-23

---

**By default, croc uses ports 9009 through 9013 to establish five parallel TCP streams that multiplex file transfers, significantly improving throughput and resilience compared to single-stream transfers.**

croc is a secure file transfer tool that establishes a lightweight TCP relay between sender and receiver. According to the schollz/croc source code, the relay architecture relies on a specific port range and multiplexing strategy to maximize transfer performance across variable network conditions.

## Default Relay Port Configuration (9009–9013)

In [`src/cli/cli.go`](https://github.com/schollz/croc/blob/main/src/cli/cli.go), lines 20–23 define the base relay port as **9009** when the `--port` flag is omitted. The CLI then generates a *port slice* containing the base port plus consecutive ports equal to the `--transfers` value. With a default of **4** parallel transfers, croc creates five ports total: **9009, 9010, 9011, 9012, and 9013** (lines 43–46).

## How Multiplexing Works

Multiplexing in croc relies on deterministic port selection implemented in [`src/croc/croc.go`](https://github.com/schollz/croc/blob/main/src/croc/croc.go), lines 2150–2164. The sender selects a port based on the transfer index, while the receiver matches using the same index modulo the number of ports. This allows both peers to coordinate parallel streams without additional signaling.

The [`src/tcp/tcp.go`](https://github.com/schollz/croc/blob/main/src/tcp/tcp.go) layer handles the underlying TCP connections, creating separate listeners for each port in the `RelayPorts` slice.

## Performance Benefits of Multiplexing

**Parallel streams** provide two primary advantages for file transfers:

- **Increased throughput**: Multiple TCP connections circumvent single-stream congestion control limitations, saturating high-bandwidth links more effectively than one connection.
- **Resilience to packet loss**: If one stream experiences latency or loss, remaining streams continue transferring data unaffected, preventing the entire transfer from slowing down.

## Customizing Relay Ports and Parallel Streams

Run a transfer with default ports (9009–9013):

```bash

# Sender side

croc send file.txt

# Receiver side

croc receive

```

Specify a custom base port and reduce parallel streams to 2 (creates ports 8000, 8001, 8002):

```bash
croc send --port 8000 --transfers 2 large.zip

```

Provide an explicit comma-separated list to override the automatic range:

```bash
croc send --ports 9009,9015,9020 batch.tar

```

## Summary

- croc defaults to relay ports **9009 through 9013** when no custom configuration is specified.
- The port range is calculated as `base port` plus `transfers + 1` (five ports by default), defined in [`src/cli/cli.go`](https://github.com/schollz/croc/blob/main/src/cli/cli.go).
- **Multiplexing** distributes data across parallel streams using deterministic port mapping in [`src/croc/croc.go`](https://github.com/schollz/croc/blob/main/src/croc/croc.go).
- Parallel streams deliver **increased throughput** and **resilience** to network degradation on individual connections.

## Frequently Asked Questions

### Why does croc use five ports by default?

With `--transfers` defaulting to 4, the port slice length becomes 5 (representing `transfers + 1` as calculated in [`src/cli/cli.go`](https://github.com/schollz/croc/blob/main/src/cli/cli.go)). This provides one channel for handshake negotiation and four parallel streams for data transfer.

### Can I use custom port ranges?

Yes. Use `--port` to set the base port, `--transfers` to control the number of parallel streams (which determines the port count), or `--ports` to specify an explicit comma-separated list that overrides the automatic range generation entirely.

### Does multiplexing affect security?

No. Multiplexing operates at the transport layer using multiple TCP connections, but each stream carries **PAKE-encrypted** data as implemented in the croc protocol. The encryption layer remains consistent regardless of how many ports are used for transport.

### What happens if firewall rules block some relay ports?

If specific ports in the configured range are unavailable, the transfer may fail or experience degraded performance. Configure alternative ports using `--ports` to specify firewall-friendly values, or ensure all ports in the default 9009–9013 range are open for outgoing TCP connections.