| Control Service | 55933 | Web service port | ||
| Control Service | 55939 | Clustering port | ||
| Policy Broker | 6432 | Inbound | TCP | Policy Database connection (between components on same machine; does not need to be opened on firewalls) |
| Policy Broker | 7432 | Inbound | TCP | Policy Database connection (between components on same machine; does not need to be opened on firewalls) |
| Policy Broker | 55880 | Inbound | TCP | Used for communication with Policy Server, Filtering Service, Log Server, Usage Monitor, and TRITON - Web Security |
| Policy Server | 25 | Outbound | TCP | SMTP port |
| Policy Server | 162 | Outbound | TCP | SNMP port |
| Policy Server | 40000 | Inbound | TCP | Negotiate encryption port |
| Policy Server | 55806 | Inbound | TCP | Configuration information exchange port |
| Policy Server | 55807 | Outbound | TCP | Filtering Service |
| Policy Server | 55808 | Outbound | TCP | (v7.5 and v7.6) Integration Service |
| Policy Server | 55811 | Outbound | TCP | Network Agent |
| Policy Server | 55812 | Outbound | TCP | Log Server |
| Policy Server | 55813 | Outbound | TCP | Usage Monitor |
| Policy Server | 55815 | Outbound | TCP | User Service |
| Policy Server | 55817 | Outbound | TCP | Explorer Scheduler |
| Policy Server | 55818 | Outbound | TCP | Explorer Information Service |
| Policy Server | 55819 | Outbound | TCP | Logon Agent |
| Policy Server | 55821 | Outbound | TCP | eDirectory Agent |
| Policy Server | 55822 | Outbound | TCP | RADIUS Agent |
| Policy Server | 55823 | Outbound | TCP | DC Agent |
| Policy Server | 55824 | Outbound | TCP | TRITON - Web Security |
| Policy Server | 55826 | Outbound | TCP | Content Gateway |
| Policy Server | 55827 | Outbound | TCP | Download Server |
| Policy Server | 55810 | Inbound | UDP | Diagnostics |
| Policy Server | 55830 | Outbound | TCP | Sync Service |
| Policy Server | 55880 | Outbound | TCP | Policy Broker |
| Policy Server | 55900 | Outbound | TCP | Directory Agent |
| Policy Server | 55905 | UDP | UID broadcast | |
| Policy Server | Indeterminate | Outbound | TCP | (v7.7) Websense Multiplexer |
| Filtering Service | 80 | Outbound | TCP | Master Database download server |
| Filtering Service | 15868 | Inbound | TCP | WISP: Network Agent, Remote Filtering Server, Linking Service, filtering plug-ins (ISAPI and Citrix), integrations |
| Filtering Service | 15869 | UDP | Diagnostics | |
| Filtering Service | 15871 | Inbound | TCP | Block pages |
| Filtering Service | 15872 | Inbound | TCP | Secure manual authentication |
| Filtering Service | 30600 | Outbound | TCP | DC Agent |
| Filtering Service | 30602 | Outbound | TCP | Logon Agent |
| Filtering Service | 30700 | Outbound | TCP | eDirectory Agent |
| Filtering Service | 30800 | Outbound | TCP | RADIUS Agent |
| Filtering Service | 40000 | Outbound | TCP | Policy Server (negotiate encryption) |
| Filtering Service | 55805 | Outbound | TCP | Log Server |
| Filtering Service | 55806 | Outbound | TCP | Policy Server (configuration exchange) |
| Filtering Service | 55807 | Inbound | TCP | Policy Server, TRITON - Web Security toolbox |
| Filtering Service | 55809 | Outbound | TCP | Usage Monitor |
| Filtering Service | 55815 | Outbound | TCP | User Service |
| Filtering Service | 55828 | Outbound | TCP | (v7.7) State Server (track state information for time-based filtering options in multiple Filtering Service environments) |
| Filtering Service | 55833 | Outbound | TCP | Multiplexer (receives log records when SIEM integration is enabled) |
| Filtering Service | 55880 | Outbound | TCP | Policy Broker |
| User Service | 139 | Outbound | TCP | NetBIOS communication: Active Directory |
| User Service | 389 | Outbound | TCP | LDAP communication: Active Directory, Novell eDirectory, Sun Java System |
| User Service | 636 | Outbound | TCP | SSL port: Novell eDirectory, Sun Java System |
| User Service | 3268 | Outbound | TCP | Active Directory |
| User Service | 3269 | Outbound | TCP | SSL port: Active Directory |
| User Service | 15872 | Inbound | TCP | Secure manual authentication |
| User Service | 40000 | Outbound | TCP | Policy Server (negotiate encryption) |
| User Service | 55806 | Outbound | TCP | Policy Server (configuration exchange) |
| User Service | 55815 | Inbound | TCP | WIFFLE port: Filtering Service, Linking Service, Reporting, TRITON - Web Security |
| User Service | 55840 | UDP | Diagnostics | |
| User Service | 55880 | Outbound | TCP | Policy Broker |
| Log Server | 1433 | Outbound | TCP | Default SQL Server communication (ODBC port) |
| Log Server | 40000 | Outbound | TCP | Policy Server (negotiate encryption) |
| Log Server | 55805 | Inbound | TCP | Logging port |
| Log Server | 55806 | Outbound | TCP | Policy Server (configuration exchange) |
| Log Server | 55812 | Inbound | TCP | Policy Broker callback; Content Gateway logs |
| Log Server | 55815 | Outbound | TCP | User Service |
| Log Server | 55880 | Outbound | TCP | Policy Broker |
| Log Server | 55885 | Inbound | TCP | Sync Service (hybrid log records) |
| Network Agent | 15868 | Outbound | TCP | Filtering Service |
| Network Agent | 40000 | Outbound | TCP | Policy Server (negotiate encryption) |
| Network Agent | 55806 | Outbound | TCP | Policy Server (configuration exchange) |
| Network Agent | 55811 | Inbound | TCP | Listening (WIFFLE) |
| Network Agent | 55870 | UDP | Diagnostics | |
| Network Agent | 55880 | Outbound | TCP | Policy Broker |
| Usage Monitor | 25 | Outbound | TCP | Email alerts |
| Usage Monitor | 162 | Outbound | TCP | SNMP alerts |
| Usage Monitor | 40000 | Outbound | TCP | Policy Server (negotiate encryption) |
| Usage Monitor | 55806 | Outbound | TCP | Policy Server (configuration exchange) |
| Usage Monitor | 55809 | Inbound | TCP | Filtering Service |
| Usage Monitor | 55813 | Inbound | TCP | Policy Server |
| Usage Monitor | 55816 | UDP | Diagnostics | |
| Usage Monitor | 55835 | Outbound | TCP | Real-Time Monitor |
| Usage Monitor | 55880 | Outbound | TCP | Policy Broker |
| TRITON - Web Security | 1433 | TCP | Default SQL Server (ODBC), used to connect to the Log Database | |
| TRITON - Web Security | 1822 | TCP | Apache HTTP Server uses this port for HTTP communication | |
| TRITON - Web Security | 7191 | TCP | Apache Tomcat uses this port for HTTP communication | |
| TRITON - Web Security | 7443 | TCP | (v7.5) Linking port (for connection to TRITON - Data Security) | |
| TRITON - Web Security | 8080 | TCP | Management concole communication with administrator browsers | |
| TRITON - Web Security | 9009 | TCP | AJP: Apache Tomcat uses this port to communicate with Apache HTTP Server | |
| TRITON - Web Security | 9443 | TCP | Tomcat (management) port, used when administrators connect to the TRITON console | |
| TRITON - Web Security | 9444 | TCP | Apache (reporting) | |
| TRITON - Web Security | 9445 | TCP | HTTPS communication between the TRITON console and RTM Client | |
| TRITON - Web Security | 18445 | Inbound | TCP | Content Gateway (register with the forensics repository). Limit the port to allow connections only from Content Gateway machines. |
| TRITON - Web Security | 40000 | Outbound | TCP | Policy Server (negotiate encryption) |
| TRITON - Web Security | 55805 | Outbound | TCP | Log Server |
| TRITON - Web Security | 55806 | Outbound | TCP | Policy Server (configuration exchange) |
| TRITON - Web Security | 55807 | Outbound | TCP | Filtering Service |
| TRITON - Web Security | 55815 | Outbound | TCP | User Service |
| TRITON - Web Security | 55817 | Outbound | TCP | Explorer Scheduler |
| TRITON - Web Security | 55818 | Outbound | TCP | Explorer Information Service |
| TRITON - Web Security | 55824 | Inbound | TCP | Policy Server |
| TRITON - Web Security | 55880 | Outbound | TCP | Policy Broker |
| Real-Time Monitor | 9092 | TCP | RTM Server and Client communication with RTM Database (only used for components on the same machine) | |
| Real-Time Monitor | 9445 | TCP | HTTPS communication between the TRITON console and RTM Client | |
| Real-Time Monitor | 55809 | Outbound | TCP | Usage Monitor listening port |
| Real-Time Monitor | 55835 | Inbound | TCP | RTM Server listening port (receives data from Usage Monitor) |
| Real-Time Monitor | 55836 | Outbound | TCP | Policy Server (WIFFLE communication) |
| Real-Time Monitor | 55856 | Outbound | TCP | Policy Server (secure WIFFLE communication) |
| State Server | 55828 | Inbound | TCP | Filtering Service communication |
| Linking Service | 7443 | TCP | (Version 7.5) Linking port, used to connect TRITON - Web Security and TRITON - Data Security | |
| Linking Service | 15868 | Outbound | TCP | Filtering Service (Master Database information) |
| Linking Service | 56992 | Outbound | TCP | Used to communicate URL category and user information to Data Security components |
| Linking Service | 55815 | Inbound | TCP | User Service |
| Multiplexer | 514 | Outbound | TCP | SIEM integration (default TCP port) |
| Multiplexer | 515 | Outbound | UDP | SIEM integration (default UDP port) |
| Multiplexer | 40000 | Outbound | TCP | Policy Server (negotiate encryption) |
| Multiplexer | 55805 | Outbound | TCP | Passing log records to Log Server |
| Multiplexer | 55806 | Outbound | TCP | Policy Server (configuration exchange) |
| Multiplexer | 55833 | Inbound | TCP | Filtering Service (log records) |
| Multiplexer | Indeterminate | Outbound | TCP | Policy Server |
| Multiplexer | 56011 | UDP | Diagnostics | |
| Sync Service | 443 | Outbound | TCP | Hybrid filtering |
| Sync Service | 40000 | Outbound | TCP | Policy Server (negotiate encryption) |
| Sync Service | 55806 | Outbound | TCP | Policy Server (configuration exchange) |
| Sync Service | 55830 | Inbound | TCP | Listening (WIFFLE) |
| Sync Service | 55831 | Outbound | TCP | Policy Server security communication |
| Sync Service | 55832 | Outbound | TCP | Directory Agent, Tomcat (HTTP connection) |
| Sync Service | 55880 | Outbound | TCP | Policy Broker |
| Sync Service | 55885 | Outbound | TCP | Log Server |
| Directory Agent | 389 | Outbound | TCP | Active Directory, Novell eDirectory |
| Directory Agent | 3268 | Outbound | TCP | Active Directory |
| Directory Agent | 3269 | Outbound | TCP | SSL: Active Directory |
| Directory Agent | 686 | Outbound | TCP | SSL: Novell eDirectory |
| Directory Agent | 40000 | Outbound | TCP | Policy Server (negotiate encryption) |
| Directory Agent | 55806 | Outbound | TCP | Policy Server (configuration exchange) |
| Directory Agent | 55832 | Outbound | TCP | Sync Service |
| Directory Agent | 55900 | Inbound | TCP | Directory Agent (WIFFLE server) |
| Remote Filtering Server | 80/8080 | Inbound | TCP | Remote Filtering client (proxy port). Configured during installation. |
| Remote Filtering Server | 8800 | Inbound | TCP | Remote Filtering client (heartbeat port) |
| Remote Filtering Server | 15868 | Outbound | TCP | Filtering Service |
| Remote Filtering Server | 15871 | Outbound | TCP | Filtering Service (block pages) |
| Remote Filtering Server | 40000 | Outbound | TCP | Installation only: Policy Server (negotiate encryption) |
| Remote Filtering Server | 55806 | Outbound | TCP | Installation only: Policy Server (configuration exchange) |
| Remote Filtering Server | 55880 | Outbound | TCP | Policy Broker |
| DC Agent | 137 | Outbound | NetBIOS: domain controller (Active Directory) | |
| DC Agent | 138 | Outbound | NetBIOS: domain controller (Active Directory) | |
| DC Agent | 139 | Outbound | NetBIOS: domain controller (Active Directory) | |
| DC Agent | 445 | Outbound | NetBIOS: domain controller (Active Directory) | |
| DC Agent | 30600 | Inbound | TCP | Filtering Service |
| DC Agent | 30601 | UDP | Diagnostics | |
| DC Agent | 40000 | Outbound | TCP | Policy Server (negotiate encryption) |
| DC Agent | 55806 | Outbound | TCP | Policy Server (configuration exchange) |
| DC Agent | 55823 | Outbound | TCP | Policy Server |
| Logon Agent | 15880 | Outbound | TCP | Logon application |
| Logon Agent | 30602 | Inbound | TCP | Filtering Service |
| Logon Agent | 30603 | UDP | Diagnostics | |
| Logon Agent | 40000 | Outbound | TCP | Policy Server (negotiate encryption) |
| Logon Agent | 55806 | Outbound | TCP | Policy Server (configuration exchange) |
| Logon Agent | 55819 | Inbound | TCP | Policy Server |
| eDirectory Agent | 389 | Outbound | TCP | Novell eDirectory |
| eDirectory Agent | 686 | Outbound | TCP | SSL: Novell eDirectory |
| eDirectory Agent | 30700 | Inbound | TCP | Filtering Service |
| eDirectory Agent | 30701 | UDP | Diagnostics | |
| eDirectory Agent | 40000 | Outbound | TCP | Policy Server (negotiate encryption) |
| eDirectory Agent | 55806 | Outbound | TCP | Policy Server (configuration exchange) |
| RADIUS Agent | 1645 | Outbound | RADIUS server (authentication) | |
| RADIUS Agent | 1646 | Outbound | RADIUS server (account) | |
| RADIUS Agent | 12345 | Inbound | RAS/VPN (authentication) | |
| RADIUS Agent | 12346 | Inbound | RAS/VPN (account) | |
| RADIUS Agent | 30800 | Inbound | TCP | Filtering Service, RADIUS client |
| RADIUS Agent | 30801 | UDP | Diagnostics | |
| RADIUS Agent | 40000 | Outbound | TCP | Policy Server (negotiate encryption) |
| RADIUS Agent | 55806 | Outbound | TCP | Policy Server (configuration exchange) |
| RADIUS Agent | 55822 | Inbound | TCP | Policy Server |
| Content Gateway | *21 | Inbound | TCP | Transparent proxy FTP traffic |
| Content Gateway | 22 | Inbound | TCP | SSH port, used for command-line access |
| Content Gateway | 53 | |||
| Content Gateway | 5353 | Inbound | UDP | Used for DNS communication |
| Content Gateway | *80 | Inbound | TCP | Transparent proxy HTTP traffic |
| Content Gateway | 88 | Outbound | TCP/UDP | Kerberos |
| Content Gateway | 389 | Outbound | TCP/UDP | LDAP |
| Content Gateway | *443 | Inbound | TCP | Transparent proxy HTTPS traffic |
| Content Gateway | 445 | Outbound | TCP | IWA &NTLM |
| Content Gateway | 1080 | Inbound | TCP | SOCKS |
| Content Gateway | 1812 | Outbound | UDP | RADIUS |
| Content Gateway | 2048 | Inbound | UDP | Transparent proxy using WCCP |
| Content Gateway | 2121 | Inbound | TCP | Explicit proxy FTP traffic |
| Content Gateway | 3130 | Inbound | UDP | Internet Cache Protocol (ICP) port used to enable a cache hierarchy. |
| Content Gateway | 8070 | Inbound | TCP | Reserved for transparent Proxy HTTPS traffic |
| Content Gateway | 8071 | Inbound | TCP | Content Gateway Manager SSL port |
| Content Gateway | 8080 | Inbound | TCP | Explicit proxy HTTP and HTTPS traffic |
| Content Gateway | 8081 | Inbound | TCP | Content Gateway Manager HTTP port |
| Content Gateway | 8089 | Inbound | UDP | SNMP encapsulation |
| Content Gateway | 9447 | Outbound | TCP | Appliance Manager administrator access |
| Content Gateway | 15868 | Inbound | TCP | Filtering Service communication (WISP) |
| Content Gateway | 40000 | Inbound | TCP | Policy Server (negotiate encryption) |
| Content Gateway | 55806 | Inbound | TCP | Policy Server (configuration exchange) |
| Content Gateway | 55826 | Inbound | TCP | Policy Server (callback) |
| Content Gateway | 55829 | Inbound | TCP | WTG app |
| Content Gateway | 55880 | Inbound | TCP | Policy Broker (policy information exchange) |
| Content Gateway | 55905 | Inbound | UDP | UID broadcast |
| Content Gateway Clustering | 8082 | Inbound | Clustering statistics gathering | |
| Content Gateway Clustering | 8083 | Inbound | Autoconfiguration for clustering (PAC file) | |
| Content Gateway Clustering | 8084 | Inbound | Process manager for clustering | |
| Content Gateway Clustering | 8085 | Inbound | Logging server for clustering | |
| Content Gateway Clustering | 8086 | Inbound | Enables clustering | |
| Content Gateway Clustering | 8087 | Inbound | Reliable service for clustering | |
| Content Gateway Clustering | 8088 | Inbound | Multicast for clustering | |
| Content Gateway Data Security communication | 17500 | Both | TCP | Date Security configuration |
| Content Gateway Data Security communication | 17501 | Both | TCP | Reserved for Data Security configuration |
| Content Gateway Data Security communication | 17502 | Both | TCP | Reserved for Data Security configuration |
| Content Gateway Data Security communication | 17503 | Both | TCP | Data Security remote analysis |
| Content Gateway Data Security communication | 17504 | Both | TCP | Reserved for Data Security remote analysis |
| Content Gateway Data Security communication | 17505 | Both | TCP | Data Security fingerprint detection |
| Content Gateway Data Security communication | 17506 | Both | TCP | Reserved for Data Security fingerprint detection |
| Content Gateway Data Security communication | 17507 | Both | TCP | Reserved for Data Security configuration |
| Content Gateway Data Security communication | 17508 | Both | TCP | Reserved for Data Security configuration |
| Content Gateway Data Security communication | 17509 | Both | TCP | Reserved for Data Security configuration |
| Content Gateway Data Security communication | 17510 | Both | TCP | Reserved for Data Security |
| Content Gateway Data Security communication | 17511 | Both | TCP | Reserved for Data Security |
| Content Gateway Data Security communication | 17512 | Both | TCP | Data Security OCR |
| Content Gateway Data Security communication | 17513 | Both | TCP | Reserved for Data Security remote analysis |
| Content Gateway Data Security communication | 17514 | Both | TCP | Reserved for Data Security |
Lic. Matias Colli
Websense Engineer