Skip to main content

Ports Requirements

Configure appropriate firewall rules to allow these connections to Privilege Secure.

Application Server Firewall Rules

The requirements for the (Privilege Secure) application server are:

  • Make sure that you have configured the Antivirus exclusions according to the following Netwrix knowledge base article: SbPAM: Exclusions for Antivirus (AV) & Endpoint Software
  • The following ports must be open for communication between Privilege Secure and Active Directory domain controllers:
PortProtocolSourceDirectionTargetPurpose
135TCPPrivilege Secure serverarrowDomain ControllerMS-RPC
389 636TCP UDPPrivilege Secure serverarrowDomain ControllerLDAP/LDAPS
53TCP UDPPrivilege Secure serverarrowDNS ServiceDNS
137 138UDPPrivilege Secure serverarrowDomain ControllerNet BIOS related
9389TCPPrivilege Secure serversingle_direction_arrowDomain ControllerActive Directory Web Services NOTE: Make sure that you have configured the Antivirus exclusions according to the following Netwrix knowledge base article: SbPAM: Exclusions for Antivirus (AV) & Endpoint Software
88UDPPrivilege Secure serverarrowDomain ControllerKerberos

NOTE: Privilege Secure must be able to reach the following URLs via HTTPS (port 443)

Proxy Firewall Rules

The following ports must be open for communication between the proxy and Privilege Secure.

Proxy Server Sizing for Windows/Linux/Docker

AdministratorsConcurrent SessionsMemoryCPU CoresDisk (max)
45015016 GB4 cores21 GB per day
90030032 GB8 cores42 GB per day
180060064 GB16 cores84 G per day

Additional Considerations

The following ports must be open for communication between the Client and Privilege Secure:

PortProtocolSourceDirectionTargetPurpose
4422TCPSSH ClientarrowSbPAM serverSSH Proxy
4489TCPRDP ClientarrowSbPAM serverRDP Proxy

Target Environment Firewall Rules

The following ports must be open for communication between Privilege Secure and the platform:

PortProtocolSourceDirectionTargetPurpose
3389TCPPrivilege Secure serverarrowWindows HostsRDP Proxy
5985 5986TCPPrivilege Secure serverarrowWindows HostsPowerShell remoting
5985 5986TCPPrivilege Secure serverarrowWindows HostsPassword Change via Powershell Remoting
22TCPPrivilege Secure serversingle_direction_arrowLinux HostsSSH Proxy / Password change
6520TCPPrivilege Secure serverarrowRemote ProxyRegister Proxy Service
6500TCPPrivilege Secure serverarrowRemote Action ServiceRegister Action Service
443HTTPS (TCP)Privilege Secure ServerarrowAzureAzure Graph API Access