Port Requirements
7 min
ensure that ports are configured correctly so that all components open correctly for all deployments for all deployments, we recommend that you open the following ports port service 53 for active directory select the udp (for dns) or tcp protocol 139 or 445 for deploying agents to other computers select the udp (for dns) or tcp protocol 443 for sending surveys however, port https 7075 is supported until further notice 1433 for the sql server 2323 voice web services port set to match the web services port set in the ivanti service manager voice management portal 5743 for the voice server 5986 for winrm to receive remote commands 8097 the default proxy port used unless defined in the endpoint address for example, http //company/users 8113 7200 for the message queue 61000 the public tcp port of the voice message server service 62000 the public tcp port of the voice reset password service 6379 for the redis enterprise software 1213 for integration service for deployments with all components installed on one host port configuration shows the port requirements for a deployment where all components are installed on one host fig 1 port configuration the ports to open are as follows self service users and service desk analysts tcp 80/443 (http/https) application server ( internal components) tcp 80/443 custom servers (erp, sharepoint, exchange, hris, and so on) tcp 80/443 (web services) tcp 25 (smtp, outgoing notifications) tcp 110/995 (email listener if pop3/s is used) tcp 143/993 (imap listener, if imap/s is used) tcp 389/636 (ldap/s) tcp 3389 (rdp) microsoft sql server tcp 1433 (sql) to and from specific hosts, use windows integrated security no credentials are stored on the server the outbound port may not be the same as the inbound port the outbound is determined by your environment for deployments with the web server installed on a different host if your deployment has the web server outside of the firewall, ensure that the following ports are also open tcp 80/443 tcp 25 (smtp, outgoing notifications) tcp 1433 (sql) tcp 54327 (license) tcp 389/636 (ldap/s) for deployments that include discovery for additional information about the discovery requirements, see the online help and look for the topic called "standard gateway system prerequisites" see "related documentation" for information on accessing the documentation about the discovery servers docid\ gp0q9t1lh4ibrdwe dvsfport information docid\ gp0q9t1lh4ibrdwe dvsf about the discovery servers the discovery components reside on two servers the discovery web server and the discovery application server you can view the components that are deployed to each server from microsoft iis the agenttaskws and clienttransportprocessor components reside on the discovery web server the messagesender, assetprocessor, discoprocessor, and taskprocessor components reside on the discovery application server all communication from the gateway or client agent goes to the agenttaskws and clienttransportprocessor components (on the discovery web server), and those components then relay the messages or requests to the corresponding components on the discovery application server commands sent to the agenttaskws component are relayed to the taskprocessor component via net tcp on port 7100 asset and discovery data sent to the clienttransportprocessor component is forwarded to the message sender via net tcp on port 5000 the message sender component then queues the message on one of the processor queues depending on the message type; you do not need to open a particular port for this port information if your deployment includes discovery, ensure that the following ports are also open for the discovery application server tcp 8080 tcp 5000 tcp 8382 tcp 7100 for deployments with remote control to use the remote control feature without the plugin (using html5), port 11438 must be opened for more information about the remote control feature, see the online help (see "related documentation" for information about accessing the documentation, including the online help )
