Solution
- Client (ERA Agent) or Apache HTTP Proxy machine
- ERA Proxy machine
- ERA Web Console machine (if not the same as ERA Server machine)
- ERA Server machine
- ERA MDC machine
- MDM managed device
- ERA Agent – used for remote deployment of ERA Agent to a target computer with Windows OS
The table below lists all possible network communication ports used when ESET Remote Administrator and its components are installed in your environment. Another communication occurs via the native operating system processes (for example, NetBIOS over TCP/IP).
Client (ERA Agent) or Apache HTTP Proxy machine
Protocol | Port | Description | Open connections |
---|---|---|---|
TCP | 2222 | Communication between ERA Agents and ERA Server | Inbound and outbound |
UDP | 1237 | Wake-Up Call for IPv4 | Inbound |
UDP | 1238 | Wake-Up Call for IPv6 | Inbound |
TCP | 3128 | Listen to Apache HTTP Proxy | Inbound* |
ERA Proxy machine
Protocol | Port | Description | Open connections |
---|---|---|---|
TCP | 2222 | Communication between ERA Agents and ERA Server | Inbound and outbound |
ERA Web Console machine (if not the same as ERA Server machine)
Protocol | Port | Description | Open connections |
---|---|---|---|
TCP | 2223 | Communication between ERA Web Console and ERA Server, used for Assisted installation | Inbound and outbound |
TCP | 443 / 80 | Tomcat broadcasting the Web Console. | Inbound and outbound |
ERA Server machine
Protocol | Port | Description | Open connections |
---|---|---|---|
TCP | 2222 | Communication between ERA Agents and ERA Server | Inbound and outbound |
UDP | 1237 | Wake-Up Call for IPv4 | Inbound |
UDP | 1238 | Wake-Up Call for IPv6 | Inbound |
TCP | 3128 | Listen to Apache HTTP Proxy | Inbound* |
TCP | 1433/3306 | Connection to an external database (only if the database is on a another machine). | Outbound |
TCP | 389 | LDAP synchronization. Open this port also on your AD controller. | Inbound and outbound |
* at the Apache HTTP Proxy machine open the port 3128 inbound and outbound.
ERA MDC machine
Protocol | Port | Description | Open connections |
---|---|---|---|
TCP | 9977 | Internal communication between Mobile Device Connector and ERA Agent | – |
TCP | 9978 | Internal communication between Mobile Device Connector and ERA Agent | – |
TCP | 9980 | Mobile device enrollment | Inbound |
TCP | 9981 | Mobile device communication | Inbound |
TCP | 2195 | Sending notifications to Apple Push Notification services
(gateway.push.apple.com) |
Outbound |
TCP | 2196 | Apple Feedback service
(feedback.push.apple.com) |
Outbound |
TCP | 443 |
|
Outbound |
TCP | 2222 | Communication (replication) between ERA Agent, MDC and ERA Server | Outbound |
TCP | 1433 / 3306 | Connection to an external database (only if the database is on a another machine). | Outbound |
MDM managed device
Protocol | Port | Description | Open connections |
---|---|---|---|
TCP | 9980 | Mobile device enrollment | Outbound |
TCP | 9981 | Mobile device communication | Outbound |
TCP | 5223 | External communication with Apple Push Notification services (iOS) | Outbound |
TCP | 443 |
|
Outbound
Inbound and outbound (LiveGrid and Threat Lab) |
TCP | 5228, 5229, 5230 | Sending notifications to Google Cloud Messaging (Android) | Outbound |
TCP | 80 |
|
Inbound |
ERA Agent – used for remote deployment of ERA Agent to a target computer with Windows OS
Protocol | Port | Description | Open connections |
---|---|---|---|
TCP | 139 | Using the share ADMIN$ | Inbound and outbound |
TCP | 445 | Direct access to shared resources using TCP/IP during remote installation (an alternative to TCP 139) | Inbound and outbound |
UDP | 137 | Name resolution during remote install | Inbound and outbound |
UDP | 138 | Browse during remote install | Inbound and outbound |