Skip to main content

Ports

Configure appropriate firewall rules to allow these connections to Privilege Secure.

Dynamic Port Range

In Windows Server 2008 and later versions, and in Windows Vista and later versions, the default dynamic port range changed to the following range:

  • Start port: 49152
  • End port: 65535

Windows 2000, Windows XP, and Windows Server 2003 use the following dynamic port range:

  • Start port: 1025
  • End port: 5000

See Microsoft's article Service overview and network port requirements for Windows for additional information.

Application Server Firewall Rules

The requirements for the (Privilege Secure) application server are:

  • Make sure that you have configured the Antivirus exclusions according to the following Netwrix knowledge base article: SbPAM: Exclusions for Antivirus (AV) & Endpoint Software
  • The following ports must be open for communication between Privilege Secure and Active Directory domain controllers:
PortProtocolSourceDirectionTargetPurpose
135TCPPrivilege Secure serverarrowDomain ControllerMS-RPC
389 636TCP UDPPrivilege Secure serverarrowDomain ControllerLDAP/LDAPS
53TCP UDPPrivilege Secure serverarrowDNS ServiceDNS
137 138UDPPrivilege Secure serverarrowDomain ControllerNet BIOS related
9389TCPPrivilege Secure serversingle_direction_arrowDomain ControllerActive Directory Web Services Make sure that you have configured the Antivirus exclusions according to the following Netwrix knowledge base article: SbPAM: Exclusions for Antivirus (AV) & Endpoint Software
88UDPPrivilege Secure serverarrowDomain ControllerKerberos

NOTE: Privilege Secure must be able to reach the following URLs via HTTPS (port 443)

Proxy Firewall Rules

The following ports must be open for communication between the proxy and Privilege Secure.

Proxy Server Sizing for Windows/Linux/Docker

AdministratorsConcurrent SessionsMemoryCPU CoresDisk (max)
45015016 GB4 cores21 GB per day
90030032 GB8 cores42 GB per day
180060064 GB16 cores84 G per day

Additional Considerations for SSH and RDP Clients

The following ports must be open for communication between the Client and Privilege Secure:

PortProtocolSourceDirectionTargetPurpose
4422TCPSSH ClientarrowSbPAM serverSSH Proxy
4489TCPRDP ClientarrowSbPAM serverRDP Proxy

Target Environment Firewall Rules

The following ports must be open for communication between Privilege Secure and the platform:

PortProtocolSourceDirectionTargetPurpose
3389TCPPrivilege Secure serverarrowWindows HostsRDP Proxy
5985 5986TCPPrivilege Secure serverarrowWindows HostsPowerShell Remoting
5985 5986TCPPrivilege Secure serverarrowWindows HostsPassword Change via Powershell Remoting
22TCPPrivilege Secure serversingle_direction_arrowLinux HostsSSH Proxy / Password change
6520TCPPrivilege Secure serverarrowRemote ProxyRegister Proxy Service
6500TCPPrivilege Secure serverarrowRemote Action ServiceRegister Action Service
443HTTPS (TCP)Privilege Secure ServerarrowAzureAzure Graph API Access
6523TCPPrivilege Secure ServerarrowRemote ProxyLeaf Nodes
6524TCPPrivilege Secure ServerarrowRemote ProxyCluster Nodes