WelcomeProducts & ServicesSecurity ResponseSupportSolutions & IndustriesLicensingTrainingStore
Enterprise
Symantec.com > Enterprise > Support > Knowledge Base


Which communication ports does the Symantec Endpoint Protection Manager 11.x use?

Question/Issue:
Which communication ports does the Symantec Endpoint Protection Manager 11.x use?


Solution:
Port NumberPort TypeInitiated byListening ProcessDescription
80, 8014TCPAgentssvchost.exe (IIS)Communication between the Protection Manager and Agents and Enforcers.
443TCPAgentssvchost.exe (IIS)Optional secured HTTPS communication between a Protection Manager and Agents and Enforcers.
1433TCPProtection Managersqlservr.exeCommunication between a Protection Manager and a Microsoft SQL Database Server if they reside on separate computers.
1812UDPEnforcerw3wp.exeRADIUS communication between a Protection Manager and Enforcers for authenticating unique ID information with the Enforcer.
2638TCPProtection Managerdbsrv9.exeCommunication between the Embedded Database and the Policy Manager.
8443TCPRemote Java or web consoleSemSvc.exeHTTPS communication between a remote Policy Management console and the Policy Manager. All login information and administrative communication takes place using this secure port.
9090TCPRemote web consoleSemSvc.exeInitial HTTP communication between a remote Protection Manager console and the Policy Manager (to display the login screen only).
8005TCPProtection ManagerSemSvc.exeThe Protection Manager listens on the Tomcat default port
39999UDPEnforcerCommunication between the Agents and the Enforcer. This is used to authenticate Agents by the Enforcer.

The Symantec Policy Manager uses two web servers: Internet Information Services (IIS) and Tomcat. IIS uses port 80/443 and Tomcat uses port 9090/8443. The communication between IIS and Tomcat uses the HTTP protocol. IIS uses port 9090 to talk to Tomcat, Tomcat uses port 80 to talk to IIS.

Client-Server Communication:
For IIS SEP uses HTTP or HTTPS between the agents or Enforcers and the server. For the client server communication it uses port 80/443 by default. In addition, the Enforcers use RADIUS to communicate in real-time with the Policy Manager for agent authentication. This is done on UDP port 1812.

Remote Console:
9090 is used by the remote console to download .jar files and display the help pages.
8443 is used by the remote console to communicate with Symantec Policy Manager and the Replication Partners to replicate data.

Client-Enforcer Authentication:
The agents communicate with the Enforcer using a proprietary communication protocol. This communication uses a challenge-response to authenticate the agents. The default port for this is UDP 39,999.



References:
This document is available in the following languages:



 

Available Translations:



Document ID: 2007090614430148
Last Modified: 11/03/2008
Date Created: 09/06/2007
Product(s): Endpoint Protection 11, Network Access Control 11, Symantec AntiVirus Advanced Protection 11.0
Release(s): Endpoint Protection 11 [All Releases], Endpoint Protection 11.0, Network Access Control 11.0, Network Access Control 11.0 [All Releases], Symantec AntiVirus Advanced Protection 11.0, Symantec AntiVirus Advanced Protection 11.0 [All Releases]


Site Index · Legal Notices · Privacy Policy · · Contact Us · Global Sites · License Agreements
©1995 - 2008 Symantec Corporation