Control Service | 55933 | Web service port | ||
Control Service | 55939 | Clustering port | ||
Policy Broker | 6432 | Inbound | TCP | Policy Database connection (between components on same machine; does not need to be opened on firewalls) |
Policy Broker | 7432 | Inbound | TCP | Policy Database connection (between components on same machine; does not need to be opened on firewalls) |
Policy Broker | 55880 | Inbound | TCP | Used for communication with Policy Server, Filtering Service, Log Server, Usage Monitor, and TRITON - Web Security |
Policy Server | 25 | Outbound | TCP | SMTP port |
Policy Server | 162 | Outbound | TCP | SNMP port |
Policy Server | 40000 | Inbound | TCP | Negotiate encryption port |
Policy Server | 55806 | Inbound | TCP | Configuration information exchange port |
Policy Server | 55807 | Outbound | TCP | Filtering Service |
Policy Server | 55808 | Outbound | TCP | (v7.5 and v7.6) Integration Service |
Policy Server | 55811 | Outbound | TCP | Network Agent |
Policy Server | 55812 | Outbound | TCP | Log Server |
Policy Server | 55813 | Outbound | TCP | Usage Monitor |
Policy Server | 55815 | Outbound | TCP | User Service |
Policy Server | 55817 | Outbound | TCP | Explorer Scheduler |
Policy Server | 55818 | Outbound | TCP | Explorer Information Service |
Policy Server | 55819 | Outbound | TCP | Logon Agent |
Policy Server | 55821 | Outbound | TCP | eDirectory Agent |
Policy Server | 55822 | Outbound | TCP | RADIUS Agent |
Policy Server | 55823 | Outbound | TCP | DC Agent |
Policy Server | 55824 | Outbound | TCP | TRITON - Web Security |
Policy Server | 55826 | Outbound | TCP | Content Gateway |
Policy Server | 55827 | Outbound | TCP | Download Server |
Policy Server | 55810 | Inbound | UDP | Diagnostics |
Policy Server | 55830 | Outbound | TCP | Sync Service |
Policy Server | 55880 | Outbound | TCP | Policy Broker |
Policy Server | 55900 | Outbound | TCP | Directory Agent |
Policy Server | 55905 | UDP | UID broadcast | |
Policy Server | Indeterminate | Outbound | TCP | (v7.7) Websense Multiplexer |
Filtering Service | 80 | Outbound | TCP | Master Database download server |
Filtering Service | 15868 | Inbound | TCP | WISP: Network Agent, Remote Filtering Server, Linking Service, filtering plug-ins (ISAPI and Citrix), integrations |
Filtering Service | 15869 | UDP | Diagnostics | |
Filtering Service | 15871 | Inbound | TCP | Block pages |
Filtering Service | 15872 | Inbound | TCP | Secure manual authentication |
Filtering Service | 30600 | Outbound | TCP | DC Agent |
Filtering Service | 30602 | Outbound | TCP | Logon Agent |
Filtering Service | 30700 | Outbound | TCP | eDirectory Agent |
Filtering Service | 30800 | Outbound | TCP | RADIUS Agent |
Filtering Service | 40000 | Outbound | TCP | Policy Server (negotiate encryption) |
Filtering Service | 55805 | Outbound | TCP | Log Server |
Filtering Service | 55806 | Outbound | TCP | Policy Server (configuration exchange) |
Filtering Service | 55807 | Inbound | TCP | Policy Server, TRITON - Web Security toolbox |
Filtering Service | 55809 | Outbound | TCP | Usage Monitor |
Filtering Service | 55815 | Outbound | TCP | User Service |
Filtering Service | 55828 | Outbound | TCP | (v7.7) State Server (track state information for time-based filtering options in multiple Filtering Service environments) |
Filtering Service | 55833 | Outbound | TCP | Multiplexer (receives log records when SIEM integration is enabled) |
Filtering Service | 55880 | Outbound | TCP | Policy Broker |
User Service | 139 | Outbound | TCP | NetBIOS communication: Active Directory |
User Service | 389 | Outbound | TCP | LDAP communication: Active Directory, Novell eDirectory, Sun Java System |
User Service | 636 | Outbound | TCP | SSL port: Novell eDirectory, Sun Java System |
User Service | 3268 | Outbound | TCP | Active Directory |
User Service | 3269 | Outbound | TCP | SSL port: Active Directory |
User Service | 15872 | Inbound | TCP | Secure manual authentication |
User Service | 40000 | Outbound | TCP | Policy Server (negotiate encryption) |
User Service | 55806 | Outbound | TCP | Policy Server (configuration exchange) |
User Service | 55815 | Inbound | TCP | WIFFLE port: Filtering Service, Linking Service, Reporting, TRITON - Web Security |
User Service | 55840 | UDP | Diagnostics | |
User Service | 55880 | Outbound | TCP | Policy Broker |
Log Server | 1433 | Outbound | TCP | Default SQL Server communication (ODBC port) |
Log Server | 40000 | Outbound | TCP | Policy Server (negotiate encryption) |
Log Server | 55805 | Inbound | TCP | Logging port |
Log Server | 55806 | Outbound | TCP | Policy Server (configuration exchange) |
Log Server | 55812 | Inbound | TCP | Policy Broker callback; Content Gateway logs |
Log Server | 55815 | Outbound | TCP | User Service |
Log Server | 55880 | Outbound | TCP | Policy Broker |
Log Server | 55885 | Inbound | TCP | Sync Service (hybrid log records) |
Network Agent | 15868 | Outbound | TCP | Filtering Service |
Network Agent | 40000 | Outbound | TCP | Policy Server (negotiate encryption) |
Network Agent | 55806 | Outbound | TCP | Policy Server (configuration exchange) |
Network Agent | 55811 | Inbound | TCP | Listening (WIFFLE) |
Network Agent | 55870 | UDP | Diagnostics | |
Network Agent | 55880 | Outbound | TCP | Policy Broker |
Usage Monitor | 25 | Outbound | TCP | Email alerts |
Usage Monitor | 162 | Outbound | TCP | SNMP alerts |
Usage Monitor | 40000 | Outbound | TCP | Policy Server (negotiate encryption) |
Usage Monitor | 55806 | Outbound | TCP | Policy Server (configuration exchange) |
Usage Monitor | 55809 | Inbound | TCP | Filtering Service |
Usage Monitor | 55813 | Inbound | TCP | Policy Server |
Usage Monitor | 55816 | UDP | Diagnostics | |
Usage Monitor | 55835 | Outbound | TCP | Real-Time Monitor |
Usage Monitor | 55880 | Outbound | TCP | Policy Broker |
TRITON - Web Security | 1433 | TCP | Default SQL Server (ODBC), used to connect to the Log Database | |
TRITON - Web Security | 1822 | TCP | Apache HTTP Server uses this port for HTTP communication | |
TRITON - Web Security | 7191 | TCP | Apache Tomcat uses this port for HTTP communication | |
TRITON - Web Security | 7443 | TCP | (v7.5) Linking port (for connection to TRITON - Data Security) | |
TRITON - Web Security | 8080 | TCP | Management concole communication with administrator browsers | |
TRITON - Web Security | 9009 | TCP | AJP: Apache Tomcat uses this port to communicate with Apache HTTP Server | |
TRITON - Web Security | 9443 | TCP | Tomcat (management) port, used when administrators connect to the TRITON console | |
TRITON - Web Security | 9444 | TCP | Apache (reporting) | |
TRITON - Web Security | 9445 | TCP | HTTPS communication between the TRITON console and RTM Client | |
TRITON - Web Security | 18445 | Inbound | TCP | Content Gateway (register with the forensics repository). Limit the port to allow connections only from Content Gateway machines. |
TRITON - Web Security | 40000 | Outbound | TCP | Policy Server (negotiate encryption) |
TRITON - Web Security | 55805 | Outbound | TCP | Log Server |
TRITON - Web Security | 55806 | Outbound | TCP | Policy Server (configuration exchange) |
TRITON - Web Security | 55807 | Outbound | TCP | Filtering Service |
TRITON - Web Security | 55815 | Outbound | TCP | User Service |
TRITON - Web Security | 55817 | Outbound | TCP | Explorer Scheduler |
TRITON - Web Security | 55818 | Outbound | TCP | Explorer Information Service |
TRITON - Web Security | 55824 | Inbound | TCP | Policy Server |
TRITON - Web Security | 55880 | Outbound | TCP | Policy Broker |
Real-Time Monitor | 9092 | TCP | RTM Server and Client communication with RTM Database (only used for components on the same machine) | |
Real-Time Monitor | 9445 | TCP | HTTPS communication between the TRITON console and RTM Client | |
Real-Time Monitor | 55809 | Outbound | TCP | Usage Monitor listening port |
Real-Time Monitor | 55835 | Inbound | TCP | RTM Server listening port (receives data from Usage Monitor) |
Real-Time Monitor | 55836 | Outbound | TCP | Policy Server (WIFFLE communication) |
Real-Time Monitor | 55856 | Outbound | TCP | Policy Server (secure WIFFLE communication) |
State Server | 55828 | Inbound | TCP | Filtering Service communication |
Linking Service | 7443 | TCP | (Version 7.5) Linking port, used to connect TRITON - Web Security and TRITON - Data Security | |
Linking Service | 15868 | Outbound | TCP | Filtering Service (Master Database information) |
Linking Service | 56992 | Outbound | TCP | Used to communicate URL category and user information to Data Security components |
Linking Service | 55815 | Inbound | TCP | User Service |
Multiplexer | 514 | Outbound | TCP | SIEM integration (default TCP port) |
Multiplexer | 515 | Outbound | UDP | SIEM integration (default UDP port) |
Multiplexer | 40000 | Outbound | TCP | Policy Server (negotiate encryption) |
Multiplexer | 55805 | Outbound | TCP | Passing log records to Log Server |
Multiplexer | 55806 | Outbound | TCP | Policy Server (configuration exchange) |
Multiplexer | 55833 | Inbound | TCP | Filtering Service (log records) |
Multiplexer | Indeterminate | Outbound | TCP | Policy Server |
Multiplexer | 56011 | UDP | Diagnostics | |
Sync Service | 443 | Outbound | TCP | Hybrid filtering |
Sync Service | 40000 | Outbound | TCP | Policy Server (negotiate encryption) |
Sync Service | 55806 | Outbound | TCP | Policy Server (configuration exchange) |
Sync Service | 55830 | Inbound | TCP | Listening (WIFFLE) |
Sync Service | 55831 | Outbound | TCP | Policy Server security communication |
Sync Service | 55832 | Outbound | TCP | Directory Agent, Tomcat (HTTP connection) |
Sync Service | 55880 | Outbound | TCP | Policy Broker |
Sync Service | 55885 | Outbound | TCP | Log Server |
Directory Agent | 389 | Outbound | TCP | Active Directory, Novell eDirectory |
Directory Agent | 3268 | Outbound | TCP | Active Directory |
Directory Agent | 3269 | Outbound | TCP | SSL: Active Directory |
Directory Agent | 686 | Outbound | TCP | SSL: Novell eDirectory |
Directory Agent | 40000 | Outbound | TCP | Policy Server (negotiate encryption) |
Directory Agent | 55806 | Outbound | TCP | Policy Server (configuration exchange) |
Directory Agent | 55832 | Outbound | TCP | Sync Service |
Directory Agent | 55900 | Inbound | TCP | Directory Agent (WIFFLE server) |
Remote Filtering Server | 80/8080 | Inbound | TCP | Remote Filtering client (proxy port). Configured during installation. |
Remote Filtering Server | 8800 | Inbound | TCP | Remote Filtering client (heartbeat port) |
Remote Filtering Server | 15868 | Outbound | TCP | Filtering Service |
Remote Filtering Server | 15871 | Outbound | TCP | Filtering Service (block pages) |
Remote Filtering Server | 40000 | Outbound | TCP | Installation only: Policy Server (negotiate encryption) |
Remote Filtering Server | 55806 | Outbound | TCP | Installation only: Policy Server (configuration exchange) |
Remote Filtering Server | 55880 | Outbound | TCP | Policy Broker |
DC Agent | 137 | Outbound | NetBIOS: domain controller (Active Directory) | |
DC Agent | 138 | Outbound | NetBIOS: domain controller (Active Directory) | |
DC Agent | 139 | Outbound | NetBIOS: domain controller (Active Directory) | |
DC Agent | 445 | Outbound | NetBIOS: domain controller (Active Directory) | |
DC Agent | 30600 | Inbound | TCP | Filtering Service |
DC Agent | 30601 | UDP | Diagnostics | |
DC Agent | 40000 | Outbound | TCP | Policy Server (negotiate encryption) |
DC Agent | 55806 | Outbound | TCP | Policy Server (configuration exchange) |
DC Agent | 55823 | Outbound | TCP | Policy Server |
Logon Agent | 15880 | Outbound | TCP | Logon application |
Logon Agent | 30602 | Inbound | TCP | Filtering Service |
Logon Agent | 30603 | UDP | Diagnostics | |
Logon Agent | 40000 | Outbound | TCP | Policy Server (negotiate encryption) |
Logon Agent | 55806 | Outbound | TCP | Policy Server (configuration exchange) |
Logon Agent | 55819 | Inbound | TCP | Policy Server |
eDirectory Agent | 389 | Outbound | TCP | Novell eDirectory |
eDirectory Agent | 686 | Outbound | TCP | SSL: Novell eDirectory |
eDirectory Agent | 30700 | Inbound | TCP | Filtering Service |
eDirectory Agent | 30701 | UDP | Diagnostics | |
eDirectory Agent | 40000 | Outbound | TCP | Policy Server (negotiate encryption) |
eDirectory Agent | 55806 | Outbound | TCP | Policy Server (configuration exchange) |
RADIUS Agent | 1645 | Outbound | RADIUS server (authentication) | |
RADIUS Agent | 1646 | Outbound | RADIUS server (account) | |
RADIUS Agent | 12345 | Inbound | RAS/VPN (authentication) | |
RADIUS Agent | 12346 | Inbound | RAS/VPN (account) | |
RADIUS Agent | 30800 | Inbound | TCP | Filtering Service, RADIUS client |
RADIUS Agent | 30801 | UDP | Diagnostics | |
RADIUS Agent | 40000 | Outbound | TCP | Policy Server (negotiate encryption) |
RADIUS Agent | 55806 | Outbound | TCP | Policy Server (configuration exchange) |
RADIUS Agent | 55822 | Inbound | TCP | Policy Server |
Content Gateway | *21 | Inbound | TCP | Transparent proxy FTP traffic |
Content Gateway | 22 | Inbound | TCP | SSH port, used for command-line access |
Content Gateway | 53 | |||
Content Gateway | 5353 | Inbound | UDP | Used for DNS communication |
Content Gateway | *80 | Inbound | TCP | Transparent proxy HTTP traffic |
Content Gateway | 88 | Outbound | TCP/UDP | Kerberos |
Content Gateway | 389 | Outbound | TCP/UDP | LDAP |
Content Gateway | *443 | Inbound | TCP | Transparent proxy HTTPS traffic |
Content Gateway | 445 | Outbound | TCP | IWA &NTLM |
Content Gateway | 1080 | Inbound | TCP | SOCKS |
Content Gateway | 1812 | Outbound | UDP | RADIUS |
Content Gateway | 2048 | Inbound | UDP | Transparent proxy using WCCP |
Content Gateway | 2121 | Inbound | TCP | Explicit proxy FTP traffic |
Content Gateway | 3130 | Inbound | UDP | Internet Cache Protocol (ICP) port used to enable a cache hierarchy. |
Content Gateway | 8070 | Inbound | TCP | Reserved for transparent Proxy HTTPS traffic |
Content Gateway | 8071 | Inbound | TCP | Content Gateway Manager SSL port |
Content Gateway | 8080 | Inbound | TCP | Explicit proxy HTTP and HTTPS traffic |
Content Gateway | 8081 | Inbound | TCP | Content Gateway Manager HTTP port |
Content Gateway | 8089 | Inbound | UDP | SNMP encapsulation |
Content Gateway | 9447 | Outbound | TCP | Appliance Manager administrator access |
Content Gateway | 15868 | Inbound | TCP | Filtering Service communication (WISP) |
Content Gateway | 40000 | Inbound | TCP | Policy Server (negotiate encryption) |
Content Gateway | 55806 | Inbound | TCP | Policy Server (configuration exchange) |
Content Gateway | 55826 | Inbound | TCP | Policy Server (callback) |
Content Gateway | 55829 | Inbound | TCP | WTG app |
Content Gateway | 55880 | Inbound | TCP | Policy Broker (policy information exchange) |
Content Gateway | 55905 | Inbound | UDP | UID broadcast |
Content Gateway Clustering | 8082 | Inbound | Clustering statistics gathering | |
Content Gateway Clustering | 8083 | Inbound | Autoconfiguration for clustering (PAC file) | |
Content Gateway Clustering | 8084 | Inbound | Process manager for clustering | |
Content Gateway Clustering | 8085 | Inbound | Logging server for clustering | |
Content Gateway Clustering | 8086 | Inbound | Enables clustering | |
Content Gateway Clustering | 8087 | Inbound | Reliable service for clustering | |
Content Gateway Clustering | 8088 | Inbound | Multicast for clustering | |
Content Gateway Data Security communication | 17500 | Both | TCP | Date Security configuration |
Content Gateway Data Security communication | 17501 | Both | TCP | Reserved for Data Security configuration |
Content Gateway Data Security communication | 17502 | Both | TCP | Reserved for Data Security configuration |
Content Gateway Data Security communication | 17503 | Both | TCP | Data Security remote analysis |
Content Gateway Data Security communication | 17504 | Both | TCP | Reserved for Data Security remote analysis |
Content Gateway Data Security communication | 17505 | Both | TCP | Data Security fingerprint detection |
Content Gateway Data Security communication | 17506 | Both | TCP | Reserved for Data Security fingerprint detection |
Content Gateway Data Security communication | 17507 | Both | TCP | Reserved for Data Security configuration |
Content Gateway Data Security communication | 17508 | Both | TCP | Reserved for Data Security configuration |
Content Gateway Data Security communication | 17509 | Both | TCP | Reserved for Data Security configuration |
Content Gateway Data Security communication | 17510 | Both | TCP | Reserved for Data Security |
Content Gateway Data Security communication | 17511 | Both | TCP | Reserved for Data Security |
Content Gateway Data Security communication | 17512 | Both | TCP | Data Security OCR |
Content Gateway Data Security communication | 17513 | Both | TCP | Reserved for Data Security remote analysis |
Content Gateway Data Security communication | 17514 | Both | TCP | Reserved for Data Security |
Lic. Matias Colli
Websense Engineer