Bitmern Solo
Bitmern Solo
Log inStart Mining
← Back to blog

Firewall Blocking Bitmern Solo Stratum (Outbound Ports)

If your Bitaxe or home ASIC will not show accepts on Bitmern Solo after the stratum string looks right, run an ordered outbound path checklist: confirm TCP…

9 min read
Firewall Blocking Bitmern Solo Stratum (Outbound Ports)
Firewall Blocking Bitmern Solo Stratum (Outbound Ports)

A blocked outbound path to stratum looks exactly like “the pool is down” or “no accepts” — even when the host, port, and WALLET.worker string are already correct. The board never lands a session, accepts stay empty, and you waste time rewriting fields that were fine. That is not a copy-paste URL bug, and it is not a reconnect flap after a good connect.

If your Bitaxe or home ASIC will not show accepts on Bitmern Solo after the stratum string looks right, run an ordered outbound path checklist: confirm TCP reachability to the coin host and port (BTC easy-start btc.bitmernsolo.com:3132), rule out guest Wi-Fi AP isolation and router/firewall denies, note CGNAT weirdness without inventing ISP SLAs, then prove the first accepts on the matching coin tab. Username WALLET.worker, password exactly x. This post does not invent product firewall ports beyond stratum or claim any ISP will open a port for you.

This is the outbound-block / firewall path. Wrong host or https paste: stratum URL mistakes. Flaps after the session already connects: reconnect loops fix. Link type vs Wi-Fi noise: Ethernet vs Wi-Fi. Field wiring: AxeOS setup and connect ASIC.

Bitmern Solo is solo infrastructure: flat 1% fee on finds only, you keep 99%. Fee context stays light here — the job is opening a clean path so the account can attribute work.

Firewall block ≠ wrong URL ≠ reconnect loops ≠ Wi-Fi tutorial

Four patterns get mixed up:

  1. Outbound firewall / path block — router, OS firewall, guest SSID isolation, or upstream filter silently drops TCP to host:port. Stratum string can be perfect; accepts never appear. That is this post.
  2. Wrong stratum URL — https paste, wrong coin host, :3102 treated as home default, trailing slash, typo domain. Use stratum URL mistakes.
  3. Reconnect loops — host/port already correct; session connects, drops, reconnects. That is reconnect loops.
  4. Ethernet vs Wi-Fi — unstable radio path after TCP sometimes works. See Ethernet vs Wi-Fi once outbound TCP is known open.

Do not invent a Bitmern Solo “firewall allowlist product” or a magic port range beyond the stratum endpoints you already use. The product facts that matter: per-coin hosts (for BTC, btc.bitmernsolo.com), BTC easy-start :3132, username WALLET.worker, password x.

What usually looks like “pool down”

Common outbound failures on Bitaxe-class and small ASIC desks:

  1. Router / firewall outbound deny — outbound TCP to the stratum port blocked by default on a “secure” home rule set.
  2. Guest Wi-Fi AP isolation — board associates; client-to-internet (or client-to-LAN) is restricted so stratum never completes.
  3. OS firewall on a USB/Ethernet bridge PC — laptop firewall drops outbound mining ports while the browser still loads the dashboard.
  4. Corporate / school / hotel network — outbound non-web ports filtered; marketing site loads, stratum does not.
  5. CGNAT / carrier weirdness — rare asymmetric path issues; do not invent an ISP SLA or “always fix by calling support” claim — just note it as a path variable after local rules are clean.
  6. Failover slot still on old pool — primary looks right; secondary steals the session (see tomorrow’s failover angle or clear unused slots while you diagnose).

Separate these from wrong URL (stratum URL mistakes) and from flaps after a known-good connect (reconnect loops).

Ordered fix checklist

Run top to bottom. Stop when the matching coin tab shows the worker under the expected label, fresh accepts move, and you are not still flipping Wi-Fi SSIDs every minute.

1. Confirm the stratum string is already correct

Symptom: You have never verified host/port/user/pass; “firewall” is a guess.

Action: First pass stratum URL mistakes. For BTC easy-start:

stratum+tcp://btc.bitmernsolo.com:3132
WALLET.worker
password: x

Never treat :3102 as the Bitaxe / home default. Host must match the coin. Only after the string is clean do you treat empty accepts as a path problem.

2. Open the matching coin tab before you blame the pool

Symptom: You watch LTC (or another coin) while the board points at BTC — or the reverse — and conclude “firewall” or “pool down.”

Fix: Open the same coin the miner is pointed at. A BTC-pointed board will not populate LTC worker cards. Coin flips: switch coins when you intentionally change endpoints.

3. Prove outbound TCP to host:port from the same LAN

Symptom: Dashboard loads in the browser; miner never shows accepts; firmware logs show connect timeout or “cannot connect.”

Fix: From a laptop on the same LAN as the miner (not guest-isolated), verify you can reach the stratum host and port your board uses. Exact tools vary by OS — the point is “can this LAN open TCP to btc.bitmernsolo.com:3132 (or your coin’s host:port)?” If the laptop also cannot open that outbound path, the block is upstream of the Bitaxe (router rule, ISP filter, or guest isolation), not a bad wallet string.

Do not invent a Bitmern Solo product requirement for a specific diagnostic tool or a guaranteed open-port SLA.

4. Kill guest Wi-Fi and AP isolation

Symptom: Board joins a “Guest” SSID; phone works; stratum never completes; or devices cannot talk across the LAN.

Fix: Move the miner to the primary LAN SSID (or Ethernet). Disable AP isolation / client isolation on that SSID if you must keep Wi-Fi. Re-apply pool settings and watch the matching coin tab. Deeper radio vs cable: Ethernet vs Wi-Fi.

5. Soften router / OS outbound rules for stratum

Symptom: Strict outbound firewall; only 80/443 allowed; mining firmware logs refuse / timeout on the stratum port.

Fix: Allow outbound TCP from the miner (or its LAN) to the coin host and stratum port you use — for BTC easy-start, :3132 on btc.bitmernsolo.com. Prefer a narrow allow for that destination rather than “open everything.” Save rules, reboot the board once, and re-check accepts.

This post does not invent extra Bitmern Solo “management ports” beyond stratum. Stick to the coin host:port you configured.

6. Corporate / hotel / filtered networks

Symptom: Same board works at home; fails on a restricted network; browser still opens bitmernsolo.com.

Fix: Move to a network that allows outbound stratum TCP, or tether/hotspot only if that path is known open. Do not invent product VPN features or ISP guarantees. If the path cannot open stratum ports, no username rewrite will help.

7. Note CGNAT without inventing ISP SLAs

Symptom: Local rules look open; intermittent or one-way failures; carrier-grade NAT in play.

Fix: Treat CGNAT as a path variable: retest from another upstream (different ISP, tether) after local firewall and guest isolation are ruled out. Do not invent confirmation times, carrier SLAs, or “Bitmern Solo requires a public IP” product claims — solo stratum is outbound client TCP; weird carrier paths are environmental, not a fee or luck issue.

8. Username and password shape (still required)

Required:

WALLET.worker
password: x

Traps that scramble attribution while you chase “firewall”: missing dot, spaces, wrong wallet prefix vs the registered receive address, password not exactly x, or watching the wrong worker suffix.

Field wiring: AxeOS setup. Full connect: connect ASIC.

9. Primary slot only while diagnosing

Symptom: Primary points at Bitmern Solo; secondary still points at an old pool; Bitmern Solo never sees steady work.

Fix: Put Bitmern Solo on the primary (or only) pool slot. Clear or disable failover slots that point elsewhere while you diagnose. Host must match the coin. Save and apply. Flaps after the path is open: reconnect loops.

10. Prove first accepts on the Bitmern Solo dashboard

Open the matching coin tab. Confirm:

  • Worker row present under the expected WALLET.worker label
  • Fresh accepts moving (not stuck empty)
  • Hashrate reading believable while the board hashes
  • Current Effort leaving a stuck empty reading when attribution works

Card reading stays in the dashboard guide. Here you only verify the outbound path landed work on the account.

When wrong URL, reconnect loops, or Wi-Fi is the real story

If host/port/user/pass were never validated, switch to stratum URL mistakes. If the session connects then flaps, use reconnect loops. If TCP sometimes works but radio is noisy, use Ethernet vs Wi-Fi. First-time fields: AxeOS setup or connect ASIC.

What this post will not invent

  • No product firewall ports beyond the stratum host:port you configure
  • No claim that :3102 is the home Bitaxe default (easy-start is :3132)
  • No ISP SLA, public-IP requirement, or “first accept within N seconds” promise
  • No luck formulas, dollar EV, or find-time promises from an open path
  • No competitor fee comparisons

Fee reminder only if you need it: flat 1% on finds; you keep 99%. An open outbound path is an ops signal, not a fee.

Soft next step

Lock a correct stratum string (btc.bitmernsolo.com:3132 for BTC easy-start, WALLET.worker / x), open outbound TCP past guest isolation and router denies, clear failover junk, then confirm first accepts on the matching coin tab before you chase deeper hardware issues.

Start mining

Start Mining — after login, open the matching coin tab and confirm workers / shares / hashrate.

FAQ

Is a firewall block the same as a wrong stratum URL?

No. Wrong URL is a bad string (https, host, port, slash, typo). Use stratum URL mistakes. This post assumes the string is correct and outbound TCP is blocked or filtered.

What BTC port should a home Bitaxe use first?

:3132 on btc.bitmernsolo.com. Never treat :3102 as the Bitaxe / home default.

What username and password does Bitmern Solo expect?

Username WALLET.worker (wallet prefix must match the registered receive wallet for that coin). Password exactly x.

Does Bitmern Solo require a public IP or port forward inbound?

This guide does not invent that product claim. Typical home solo stratum is outbound client TCP to the coin host:port. Focus on outbound allow and guest isolation first.

Can guest Wi-Fi block stratum even if the password is right?

Yes. AP isolation and filtered guest SSIDs often allow web browsing but break miner outbound paths. Move to the primary LAN or Ethernet.

Where do reconnect loops fit?

If the session connects then flaps on a known-good URL and open path, use reconnect loops.

Where do I confirm the fix on Bitmern Solo?

Matching coin tab → worker row → fresh accepts → believable hashrate. Guide: dashboard workers / shares / effort.

Related posts