Required ports, protocols, and services for the Edge SWG (ProxySG) appliance
search cancel

Required ports, protocols, and services for the Edge SWG (ProxySG) appliance

book

Article ID: 150987

calendar_today

Updated On:

Products

ProxySG Software - SGOS ISG Proxy Advanced Secure Gateway Software - ASG

Issue/Introduction

You want to know the required ports, protocols, and services for the Advanced Secure Gateway (ASG) and Edge Secure Web Gateway (Edge SWG) — formerly ProxySG — appliances.

Resolution

Depending on your Edge SWG appliance configuration, you must open certain ports and protocols on your firewalls for the appliance to function as intended, to use enabled features, or to allow connectivity to various components and data centers. This document presents basic configurations and some commonly used options. 

Note: This document also applies to the supported proxy components of the Advanced Secure Gateway appliance. For supported components related to Content Analysis, refer to the appropriate version of Content Analysis documentation.

Inbound-Only Connection

ComponentDefault PortProtocolConfigurableSourceDescription
HTTPS Management Console8082TCPYesClient browserProvides the secured Edge SWG web interface.
HTTP Management Console8081TCPYesClient browserProvides the non-secured Edge SWG web interface. It is recommended that it not be enabled, as administrative credentials and configuration data would be sent in plaintext. 
RIP520UDPNolocal server hosting RIP fileReceives the RIP configuration file download from a local server.
SSH22TCPNoSSH clientAllows for SSH management of the appliance.
SNMP161UDPYesSNMP clientEnables SNMP monitoring by an SNMP client.

Outbound-Only Connections 

ComponentDefault PortProtocolConfigurableSourceDescription
Appliance certificate443TCPNoSymantec serverSends mutually authenticated requests to Symantec servers.
BCAAA authentication with COREid, IWA, SSO, SitemInder, and XML realms16101TCPYesAuthentication Server

Submits authentication- and authorization-related queries to the configured Authentication Server.

For details, see What ports does BCAAA use.

DNS53TCP/UDPNoDNS serverUses this port for DNS queries to your DNS servers.
Diagnostics443TCPNoSymantec serverTransmits heartbeats and SysInfo uploads to the Symantec server.
Email notifications25, 465TCPNoSMTP server

Sends email notifications. This port is configurable. When TLS is not configured, the default is 25. When it is configured, the default is 465.

HTTP/HTTPS80/443TCPNoInternetEnables regular HTTP/HTTPS access to the internet.
ICAP (plain)1344TCPYesSymantec Content Analysis or other ICAP service

Forwards requests for content scanning to Symantec Content Analysis or other ICAP services. (Not applicable to Advanced Secure Gateway)

ICAP (secure)11344TCPYesContent Analysis or other ICAP service

Forwards requests for content scanning securely to Content Analysis or other ICAP services. (Not applicable to Advanced Secure Gateway)

IWA-Kerberos authentication88TCP/UDPYesDC/KDCPerforms Kerberos for IWA Direct authentication with the DC/KDC.
LDAP389TCP/UDPYesDC/KDC/LDAP ServerPerforms LDAP for IWA Direct authentication with the DC/KDC/LDAP Server.
Log client (custom)69TCPYesCustom log serverSends access logs to the configured custom log server.
Log client (FTP, plain and secure)21 TCPYesFTP/S log serverSends access logs to the configured FTP/S log server.
Log client (HTTP, plain and secure)80TCPYesHTTP/S log server

Sends access logs to the configured HTTP/S log server. The default is port 80, but you can change the default when configuring the primary and alternate hosts for the log server. When setting up secure (HTTPS) log uploads,  explciitly set the port to the secure port of the  log server, which is generally 443.

Log client (Kafka)9092TCPYesKafka brokerSends access logs to the configured Kafka broker cluster.
Log client (Symantec Reporter client)9081TCPYesReporterPerforms deprecated log streaming to Reporter version 9.
Log client (SCP)22TCPYesSCP log serverSends access logs to the configured SCP log server.
Symantec Management Center, Symantec Director 22TCPNoManagement Center, Director

Facilitates Management Center registration. (Not applicable to Advanced Secure Gateway)

Monitoring statistics to Management Center (plain)9009TCPNoManagement Center

Exports monitoring statistics to Management Center.

Monitoring statistics to Management Center (secure)9010TCPNoManagement Center

Exports monitoring statistics securely to Management Center.

NTP123UDPYesNTP server

Performs periodic time update from default or configured NTP servers.

RADIUS 1812TCPYesRADIUS serverPerforms RADIUS authentication with the RADIUS server.

SafeNet Java HSM

8443

TCP

Yes

SafeNet Java HSM

Manages communication with the SafeNet Java HSM. 

SOCKS1080TCP/UDPNoSOCKS serverForwards traffic to the SOCKS Gateway. 
Syslog514TCP/UDPNoSyslog server

Uploads Syslog entries to a remote Syslog server. This port is configurable.

WCCP2048

UDP

 

NoWCCP-compliant router or switchHandles traffic redirection from a WCCP-compliant router or switch to the appliance in out-of-path deployments.

URLs and IP Addresses for Symantec Services 

ComponentPortsProtocolsURLsIP AddressesDescription
Symantec Content Analysis

443

HTTPS

subscription.es.bluecoat.com

168.149.132.6

168.149.132.38

168.149.132.102

Downloads antivirus pattern updates from Content Analysis.

Content Analysis

443

HTTPS

contentanalysis-ma.es.bluecoat.com

168.149.132.18

168.149.132.50

Submits malware reports from Content Analysis.

Cloud Isolation

80

443

8080

HTTP

HTTPS

isolation-jump.prod.fire.glass

global-shared.fire.glass

docisolation.prod.fire.glass

docisolation-eu.prod.fire.glass

doc-isolation-prod.prod.fire.glass

doc-isolation-prod-eu.prod.fire.glass

shared.fire.glass

Web Isolation Cloud Tenant (This should be the custom domain for the created tenant per customer)

35.201.102.245

Connects to the Web Isolation Cloud Tenant service.

For more information, see Web Isolation Required Ports, Protocols, and Services.

Licensing443HTTPS device-services.es.bluecoat.com192.19.237.100Manages the appliance license.
Appliance License Management443HTTPS bto-services.es.bluecoat.com192.19.237.99Validates the license and performs updates to the appliance.
Subscription Services443HTTPSsubscription.es.bluecoat.com

168.149.132.6
168.149.132.38
168.149.132.102

Manages subscription services and downloads binary databases.
Licensing443HTTPS download.bluecoat.com/cgi-bin/license.cgi192.19.237.103Retrieves and updates the license key by POSTing serial number and credentials.
PKI - Appliance validation

80

443

444

HTTP

HTTPS 

http://abrca.bluecoat.com/cgi-bin/device-authentication/sign-automatic (Port 80)

https://abrca.bluecoat.com:444/cgi-bin/device-authentication/verify (Port 444)
192.19.237.69Manages appliance identity and validation by submitting a CSR to the Symantec Certificate Authority.
PKI - CA certificates

80 (default)

443

HTTP

HTTPS 

appliance.bluecoat.com/sgos/trust_package.bctp

34.117.186.24Downloads trust packages to fetch trusted CA root certificates for SSL inspection.

NTP

123

UDP

ntp.bluecoat.com 

ntp2.bluecoat.com

216.239.35.0
216.239.35.4
216.239.35.8
216.239.35.12

Synchronize the appliance clock with a verified time reference server.

Diagnostics443HTTPShb.bluecoat.com 192.19.145.20Transmits a periodic appliance heartbeat, uploading the appliance health status and statistics to Symantec for proactive support and license compliance.

Diagnostics

(Uploads)

443HTTPS

upload.bluecoat.com

supportftp.broadcom.com

192.19.232.162
141.202.253.54

Hosts the Broadcom endpoint for support case file uploads. 

Note: upload.bluecoat.com/support/upload/ is officially retired and should no longer be used.

Content filtering443HTTPSlist.bluecoat.com

168.149.132.5
168.149.132.37
168.149.132.101

Downloads databases for legacy Blue Coat WebFilter, IWF, Optenet, Proventia, and other filter databases.
Symantec Cloud Secure Web Gateway (SWG, formerly known as WSS)443HTTPSportal.threatpulse.com39.49.9.67Provides the Cloud SWG administration portal for management and proxy registration/sync. For more information, see Cloud SWG Required Locations, Ports, and Protocols.

Policy Updates

443

HTTPS

bto.bluecoat.com

192.19.237.112

Provides updates to security and threat protection policies and downloads VPM policy classification metadata and threat protection policy modules.

Threat protection443HTTPS

webpulse.es.bluecoat.com

sp.cwfservice.net
(version 6.5.x)

 

 

168.149.132.1
168.149.132.2
168.149.132.32
168.149.132.33
168.149.132.64
168.149.132.65
168.149.132.80
168.149.132.81
168.149.132.96
168.149.132.97
168.149.132.112
168.149.132.113
168.149.132.128
168.149.132.129
168.149.132.144
168.149.132.145
168.149.132.160
168.149.132.161
168.149.132.176
168.149.132.177

 

Performs real-time URL categorization lookups for Symantec Global Intelligence Network / WebPulse.

Timezone Updates

443

HTTPS

download.bluecoat.com

192.19.237.102

Fetches the IANA timezone archive periodically.

Trust Package Updates

80

443

HTTPS

appliance.bluecoat.com/sgos/trust_package.bctp

 

Fetches trust package updates.

Virtual Appliance Validation443HTTPS

validation.es.bluecoat.com

192.19.237.101

Performs virtual appliance license validation by POSTing appliance identity periodically to validate entitlement and CPU usage.

Telemetry443HTTPS

telemetry.broadcom.com/login (custom auth headers)

telemetry.broadcom.com/loaddata (Bearer token auth)

 

Uploads a daily report containing a JSON payload of product, license, and performance metrics.

 

Additional Information

For an index of ports and protocols articles, refer to the following article: Required ports, protocols, and services for Broadcom appliances.

For details about earlier versions and legacy products, see the PDF document Required Ports, Protocols, and Services for Symantec Enterprise Security Products.