Skip to main content

Activity Agent Ports

Firewall settings depend on the type of environment being targeted. The following firewall settings are required for communication between the Agent server and the Netwrix Activity Monitor Console:

Communication DirectionProtocolPortsDescription
Activity Monitor to Agent ServerTCP4498Agent Communication

The Windows firewall rules need to be configured on the Windows server, which require certain inbound rules be created if the scans are running in applet mode. These scans operate over a default port range, which cannot be specified via an inbound rule. For more information, see the Microsoft Connecting to WMI on a Remote Computer article.

There might be a need for additional ports for the target environment.

CTERA Additional Firewall Rules

The following firewall settings are required for communication between the Activity Monitor Agent and the CTERA Portal.

Communication DirectionProtocolPortsDescription
Agent Server to CTERA PortalHTTPS443CTERA Portal API
CTERA Portal to Agent ServerTCP/TLS4488CTERA Event Reporting

Dell Celerra & Dell VNX Devices Additional Firewall Rules

The following firewall settings are required for communication between the CEE server/ Activity Monitor Activity Agent server and the target Dell device:

Communication DirectionProtocolPortsDescription
Dell Device CEE ServerTCPRPC Dynamic RangeCEE Communication
CEE Server to Activity Agent Server (when not same server)TCPRPC Dynamic RangeCEE Event Data

Dell Isilon/PowerScale Devices Additional Firewall Rules

The following firewall settings are required for communication between the CEE server/ Activity Monitor Activity Agent server and the target Dell Isilon/PowerScale device:

Communication DirectionProtocolPortsDescription
Dell Isilon/PowerScale to CEE ServerTCPTCP 12228CEE Communication
CEE Server to Activity Agent Server (when not same server)TCPRPC Dynamic RangeCEE Event Data

Dell PowerStore Devices Additional Firewall Rules

The following firewall settings are required for communication between the CEE server/ Activity Monitor Activity Agent server and the target Dell device:

Communication DirectionProtocolPortsDescription
Dell Device CEE ServerTCPRPC Dynamic RangeCEE Communication
CEE Server to Activity Agent Server (when not same server)TCPRPC Dynamic RangeCEE Event Data

Dell Unity Devices Additional Firewall Rules

The following firewall settings are required for communication between the CEE server/ Activity Monitor Activity Agent server and the target Dell device:

Communication DirectionProtocolPortsDescription
Dell Device CEE ServerTCPRPC Dynamic RangeCEE Communication
CEE Server to Activity Agent Server (when not same server)TCPRPC Dynamic RangeCEE Event Data

Exchange Online Additional Firewall Rules

The following firewall settings are required for communication between the Activity Monitor Activity Agent server and the target tenant:

Communication DirectionProtocolPortsDescription
Activity Agent Server to Microsoft Entra ID TenantHTTPS443Entra ID authentication, Graph API, Office 365 API

Microsoft Entra ID Tenant Additional Firewall Rules

The following firewall settings are required for communication between the Activity Monitor Activity Agent server and the target tenant:

Communication DirectionProtocolPortsDescription
Activity Agent Server to Microsoft Entra ID TenantHTTPS443Entra ID authentication, Graph API, Office 365 API

Nasuni Edge Appliance Additional Firewall Rules

The following firewall settings are required for communication between the Activity Monitor Activity Agent server and the target Nasuni Edge Appliance:

Communication DirectionProtocolPortsDescription
Agent Server to NasuniHTTPS8443Nasuni API calls
Nasuni to Activity Agent ServerAMQP over TCP5671Nasuni event reporting

NetApp Data ONTAP 7-Mode Device Additional Firewall Rules

The following firewall settings are required for communication between the Activity Monitor Activity Agent server and the target NetApp Data ONTAP 7-Mode device:

Communication DirectionProtocolPortsDescription
Activity Agent Server to NetApp*HTTP (optional)80ONTAPI
Activity Agent Server to NetApp*HTTPS (optional)443ONTAPI
Activity Agent Server to NetAppTCP135, 139 Dynamic Range (49152-65535)RPC
Activity Agent Server to NetAppTCP445SMB
Activity Agent Server to NetAppUDP137, 138RPC
NetApp to Activity Agent ServerTCP135, 139 Dynamic Range (49152-65535)RPC
NetApp to Activity Agent ServerTCP445SMB
NetApp to Activity Agent ServerUDP137, 138RPC

*Only required if using the FPolicy Configuration and FPolicy Enable and Connect options in Activity Monitor.

NOTE: If either HTTP or HTTPS are not enabled, the FPolicy on the NetApp Data ONTAP 7-Mode device must be configured manually. Also, the External Engine will not reconnect automatically in the case of a server reboot or service restart.

NetApp Data ONTAP Cluster-Mode Device Additional Firewall Rules

The following firewall settings are required for communication between the Activity Monitor Activity Agent server and the target NetApp Data ONTAP Cluster-Mode device:

Communication DirectionProtocolPortsDescription
Activity Agent Server to NetApp*HTTP (optional)80ONTAPI
Activity Agent Server to NetApp*HTTPS (optional)443ONTAPI
NetApp to Activity Agent ServerTCP9999FPolicy events

*Only required if using the FPolicy Configuration and FPolicy Enable and Connect options in Activity Monitor.

NOTE: If either HTTP or HTTPS are not enabled, the FPolicy on the NetApp Data ONTAP 7-Mode device must be configured manually. Also, the External Engine will not reconnect automatically in the case of a server reboot or service restart.

Nutanix Devices Additional Firewall Rules

The following firewall settings are required for communication between the Activity Monitor Activity Agent server and the target Nutanix device:

Communication DirectionProtocolPortsDescription
Activity Agent Server to NutanixTCP9440Nutanix API
Nutanix to Activity Agent ServerTCP4501Nutanix Event Reporting

Protect the port with a username and password. The credentials will be configured in Nutanix.

Panzura Devices Additional Firewall Rules

The following firewall settings are required for communication between the Activity Monitor Activity Agent server and the target Panzura device:

Communication DirectionProtocolPortsDescription
Activity Agent Server to PanzuraHTTPS443Panzura API
Panzura filers to to Activity Agent ServerAMQP over TCP4497Panzura Event Reporting

Protect the port with a username and password. The credentials will be configured in Panzura.

Qumulo Devices Additional Firewall Rules

The following firewall settings are required for communication between the Activity Monitor Activity Agent server and the target Qumulo device:

Communication DirectionProtocolPortsDescription
Activity Agent Server to QumuloTCP8000Qumulo API
Qumulo to Activity Agent ServerTCP4496Qumulo Event Reporting

Protect the port with a username and password. The credentials will be configured in Qumulo.

SharePoint Online Additional Firewall Rules

The following firewall settings are required for communication between the Activity Monitor Activity Agent server and the target tenant:

Communication DirectionProtocolPortsDescription
Activity Agent Server to Microsoft Entra ID TenantHTTPS443Entra ID authentication, Graph API, Office 365 API

SQL Server Additional Firewall Rules

The following firewall settings are required for communication between the Activity Monitor Activity Agent server and the target SQL Server:

Communication DirectionProtocolPortsDescription
SQL Server to Activity Agent ServerTCP1433Default SQL Server Port

If the Activity Monitor cannot connect to the SQL Server, ensure that SQL Server Browsing state is Running.

Integration with Netwrix Enterprise Auditor Additional Firewall Rules

Firewall settings are dependent upon the type of environment being targeted. The following firewall settings are required for communication between the agent server and the Access Analyzer Console:

Communication DirectionProtocolPortsDescription
Access Analyzer to Agent ServerTCP445SMB, used for Agent Deployment
Access Analyzer to Agent ServerTCPPredefinedWMI, used for Agent Deployment