Firewall ports

You might need to open the following ports on your DMZ firewall, depending on your network configuration.

Port Network Protocol Application / Service Protocol Direction Description
20 TCP FTP In / Out
  • Backup & Restore using a standard FTP server.

  • Export of transaction logs using a standard FTP server.

21 TCP FTP In / Out
  • Backup & Restore using a standard FTP server.

  • Export of transaction logs using a standard FTP server.

22 TCP SFTP In / Out
  • Backup & Restore using SFTP.

  • Export of transaction logs using SFTP.

  • Connecting with a server containing lexical data for import using SFTP.

22

TCP SSH

In

  • SSH access to the Gateway.

25 TCP SMTP

In

  • Inbound SMTP.

25 TCP SMTP Out
  • Outbound SMTP.

    (If your system uses an alternative port, open that instead.)

53 TCP / UDP DNS Out
  • DNS access to TRUSTmanager.

  • DNS requests using DNS servers.

    (Only allow outbound requests to the specified DNS servers, and responses from those servers.)

80 TCP HTTP Out
  • HTTP access to the Junk Email and Malware Detection Servers.

  • HTTP access to the policy rule/engine and spam update servers.

  • HTTP access to OCSP CRL lookup.

  • HTTP access to the RSS Feed from:

    www.clearswift.com

80 TCP HTTP Out

*.mailshell.net

  • HTTP access to the Spam Detection statistics from mailshell.

  • HTTP access to SpamLogic Rule/Engine updates.

123 UDP NTP In / Out
  • Access to NTP services (if configured).

  • The following server is configured by default:

    2.rhel.pool.ntp.org

135 TCP

NTLM

Out
  • NTLM user authentication when using PMM in Full mode.

137 UDP

NTLM

Out
  • NTLM user authentication when using PMM in Full mode.

139 TCP

NTLM

Out
  • NTLM user authentication when using PMM in Full mode.

161 UDP SNMP Out
  • SNMP inbound.

    (The port used by an SNMP browser when scanning the Gateway.)

162 UDP SNMP Out
  • SNMP alerts.

389 TCP LDAP In / Out
  • LDAP directory access.

  • LDAP Key Server Queries.

443 TCP HTTPS In
  • HTTPS access to the PMM interface, if using PMM.

443 TCP HTTPS In / Out
  • HTTPS access to the web UI and for communications between Peer Gateways.

  • HTTPS Key Server Queries.

443 TCP HTTPS Out
  • General HTTPS web access.

  • HTTPS lexical data import.

  • HTTPS access to the Online Help.

  • HTTPS access to the update server for TRUSTmanager statistics.

  • HTTPS MTA-STS policy file queries.

443 TCP HTTPS Out
  • HTTPS access to the managed lists, such as the Managed Lexical Expression Lists:

    applianceupdate.clearswift.com

443 TCP HTTPS Out
  • HTTPS access to Sophos URL Lookup Server:

    4.sophosxl.net

  • HTTPS access to Sophos Sandboxing Servers to allow the rendering of sandboxing reports:

    cdn.analysis.sophos.com

  • HTTPS access to Sophos Sandboxing Server (port is used for sending potential malware for scanning, and this traffic must not be blocked):

    analysis.sophos.com

    apac.analysis.sophos.com

    au.analysis.sophos.com

    de.analysis.sophos.com

    uk.analysis.sophos.com

    us.analysis.sophos.com

443 TCP HTTPS Out

*.fortra.com

  • HTTPS access to the Service Availability List.

  • HTTPS access to the Update Server for license management.

  • HTTPS access to the product and Operating System updates.

  • HTTPS access to the Fortra Threat Brain service and its authentication service.

443 TCP HTTPS Out

*.clearswift.net

  • HTTPS access to the Avira Update Servers for fetching anti-virus updates and software upgrades. (You may also add *.apc.avira.com.)

  • HTTPS access to the Sophos Update Servers for fetching anti-virus updates and software upgrades.

  • HTTPS access to the SpamAssassin ruleset database.

  • HTTPS access to the PhishTank URL database.

445 TCP

NTLM

Out
  • NTLM user authentication when using PMM in Full mode.

514

TCP syslog Out
  • Access to a syslog server (default port for log export).

636 TCP LDAPS In / Out
  • LDAPS directory access.

  • LDAPS Key Server Queries.

989 TCP FTPS In / Out
  • Backup & Restore using a secure FTP (FTPS) server.

  • Export of transaction logs using a secure FTP (FTPS) server.

  • Connecting with a server containing lexical data for import using a secure FTP (FTPS) server.

990 TCP FTPS In / Out
  • Backup & Restore using a secure FTP (FTPS) server.

  • Export of transaction logs using a secure FTP (FTPS) server.

  • Connecting with a server containing lexical data for import using a secure FTP (FTPS) server.

3268 TCP LDAP Out
  • LDAP connection to an Active Directory Global Catalog port.

3269 TCP LDAPS Out
  • LDAPS connection to an Active Directory Global Catalog port.

9090 TCP HTTPS In
  • HTTPS connection to Red Hat Cockpit.

11371 TCP HTTPS In / Out
  • HTTPS Key Server Queries.

19200 UDP - In / Out
  • Broadcasting of greylisting data to Peer Gateways.