Ports used by Symantec DLP
search cancel

Ports used by Symantec DLP

book

Article ID: 160297

calendar_today

Updated On:

Products

Data Loss Prevention Endpoint Prevent Data Loss Prevention Data Loss Prevention Enforce Data Loss Prevention Discover Suite Data Loss Prevention Endpoint Discover Data Loss Prevention Endpoint Suite Data Loss Prevention Enterprise Suite Data Loss Prevention Sensitive Image Recognition

Issue/Introduction

The following table is a list of standard network ports that are used in Symantec DLP. Some of them can be changed to custom ports if required, however we recommend leaving them at their defaults whenever possible. Some of these details are in the DLP Guides as well.

Resolution

 

PurposeProtocolDefault PortBi-Directional / Uni-DirectionalNotes
Enforce Server Console (Windows)TCP443Uni-Directional
How to change the Enforce console port in DLP
Enforce Server Console (Linux)TCP8443Uni-DirectionalHow to change the Enforce console port in DLP
Enforce to Oracle DatabaseTCP1521Uni-Directional 
Enforce to Detection ServersTCP8100Uni-DirectionalHow to change the MonitorController port
Endpoint Agents to Endpoint ServersTCP10443Uni-DirectionalWhat Port is used by the Endpoint Agent to communicate with the Endpoint Server?
Network Discover Crawlers and ScannersSee notes  What ports are used by Discover?
Network Prevent for Email: MTAResubmitPort
TCP10026Uni-Directional

Is a SMTP Email Client installed with Network Prevent for SMTP?

Network Prevent for Email: ServerSocketPortTCP10025Uni-DirectionalIs a SMTP Email Client installed with Network Prevent for SMTP?
Network Prevent for WebTCP1344Uni-DirectionalHow to test ICAP connectivity to DLP Web Prevent
Kerberos port for Enforce AD AuthenticationUDP88 Configure Active Directory Authentication for DLP
SMTP server for system alerts and response rule email notificationsTCP25Uni-Directional 
Syslog server integration; Events, Response Rules
TCP514Uni-DirectionalGenerating Syslog messages from Data Loss Prevention
Directory Connection for LDAP (Unsecure)
TCP389Uni-Directional 
Directory Connection for LDAP (Secure)TCP636Uni-DirectionalDoes Live LDAP Lookup support Secure LDAP / LDAPS Symantec Data Loss Prevention
Enforce to Data Insight ServerTCP443  
OCR Server PortTCP8555Uni-Directional 
Network Discover Grid Leader Port (16.1)
TCP39990Bi-Directional 
Network Discover Grid Leader Port (16.0)
TCP61616  
Enforce to DLP appliance (Management Port)
TCP8080 Symantec Data Loss Prevention uses port 8080 to manage virtual and hardware appliances
Enforce and Domain Controller AgentTCP443Uni-Directional 
Discover Cluster Discovery igniteTCP47500-47520  
Discover Cluster client rangeTCP10800-10820  
Outlook on-send AddinTCP
4631,
4641,
4651
    Uni-DirectionalBest Practices for Deploying the Web Add-in for Outlook for Windows and macOS Endpoints