Ports and Protocols for Symantec IT Management Suite (ITMS) 8.x
search cancel

Ports and Protocols for Symantec IT Management Suite (ITMS) 8.x

book

Article ID: 184952

calendar_today

Updated On:

Products

IT Management Suite Client Management Suite Server Management Suite

Issue/Introduction

This article contains information about the Ports and Protocols used by components of IT Management Suite (ITMS) 8.x

Environment

ITMS 8.x

Resolution

Symantec Installation Manager

ComponentProtocolDirectionPortConnectionsIs configurable?
Symantec Installation ManagerTCP 80/443SIM uses ports to download files only. It does not open any ports.
SIM accesses the following URLs. Your firewall should allow these URLs in order to use SIM properly.
https://www.solutionsam.com


 
SIM to MS SQL DBTCPOutbound1433Standard port for connection to remote MS SQL DB using TCP/IP transport. Note that MS SQL can be configured to custom or dynamic port usage.Yes, in MS SQL configuration.
SIM to MS SQL DBUDPOutbound1434Used to determine dynamic or custom port used by MS SQL instance. Also used for SQL server discovery.No
Symantec Installation ManagerTCP/UDP(DNS)Outbound53Used to resolve SQL server name.No

 

Notification Server and Symantec Management Console

ComponentProtocolDirectionPortConnectionsService NameIs configurable?
NS ConsoleTCPInbound80/443When using a remote console, Notification Server uses HTTP (port 80) to connect to the server and download the client application / admin console content.W3SVCYes
Cloud-enabled managementTCPInbound/Outbound4726This is the default port for Cloud-enabled Management Agent IIS Website. It handles the incoming/outgoing connections from the Internet Gateway to the Notification Server.W3SVCYes, you can configure it in Settings > Notification Server > Cloud-enabled Management > Setup > Cloud enabled Management Agent IIS Website Settings.
NS (agent install)UDP (NETLOGON)Outbound138Initial connection Notification Server to client.AexSvcNo
NS (agent install)TCP (MS DS/CIFS/SMB)Outbound445Initial connection Notification Server to client.AexSvcNo
Agent (initial connection)TCPOutbound80/443Initial connection Client to Notification Server (after Service Starts).AltirisAgentInstSvcYes
Agent (initial connection)ICMP Type 8 (PING)Outbound ICMP Type 8 (PING) package server speed check.AltirisAgentInstSvcNo
Agent (policy update and post event)TCPOutbound80/443The Agent establishes a connection to server port TCP 80 for HTTP and server port TCP 443 for SSL. This port is configurable by the user, however, and can be set to any free port.AeXNSClientYes
HierarchyTCPInbound/Outbound80/443Hierarchy uses the ports that individual Notification Servers have been set up and configured to use.

 

To join Notification Servers in a hierarchy, you must correctly enter the port numbers or HTTPS prefix inside the Add Hierarchy Node Wizard. In Step 1 of the wizard, in the URL field, you enter either HTTPS or the IIS port.

For example, to add a child node called example.com using port 30000, enter http://example.com:30000/Altiris/Console in the URL field. This means that your child Notification is configured to use port 30000, and you are instructing the local Notification Server to connect to it for hierarchy communications using that port.

To add a child node called example.com using HTTPS, enter https://example.com/Altiris/Console in the URL field.

Notification Servers within the hierarchy may not all use the same HTTP port for communication. As long as the hierarchy connection is configured correctly inside the Add Hierarchy Node Wizard, they will all work correctly.

AexSvc, W3SVCYes
NS to MS SQL DBTCPOutbound1433Standard port for connection to remote MS SQL DB using TCP/IP transport. Note that MS SQL can be configured to custom or dynamic port usage.AexSvc, AltirisClientMsgDispatcher, AltirisReceiverService, W3SVCYes, in MS SQL configuration.
NS to MS SQL DBUDPOutbound1434Used to determine dynamic or custom port used by MS SQL instance.AexSvc, AltirisClientMsgDispatcher, AltirisReceiverService, W3SVCNo
NSTCP/UDPOutbound389Active Directory data import using AD import rules or Data Connector LDAP data source.AexSvc, W3SVCNo
NSTCPOutbound25Optional connection to mail server using SMTP, required for sending notifications to configured recipients using automation policies or tasks.AexSvcYes, NS console.
NSUDPOutbound137Optional WINS import for computers.AexSvcNo
NS Data ConnectorTCP/UDPOutbound1024-65536In case data sources like ODBC or OLEDB are used, outgoing connection may be required to specific services defined by driver used.AexSvc, W3SVCNo
NS Software package accessTCP (SMB)Outbound445Optional access to software pacakges which are accessible only via UNC.AexSvc, W3SVCNo
Computer discoveryTCP/UDP (DNS)Outbound53Resolving computer hostname/fully qualified domain name(FQDN).AexSvc, W3SVCNo
Computer discoveryUDP (NetBIOS)Outbound137, 138Optional findout computer's NetBIOS name, or discover computer by NetBIOSname.AexSvc, W3SVCNo
Computer discoveryTCP (NetBIOS)Outbound139Optional findout computer's NetBIOS name, or discover computer by NetBIOSname.AexSvc, W3SVCNo
Computer discoveryTCP (RPC/WMI)Outbound135, 49152-65535Optional get computer's details(e.g. OS type) during discovery.AexSvc, W3SVCNo
NSTCPInbound9086, 9988Ports used to access Service Framework. Not utilized by SMP itself, but may be required by certain utilities like NSDiag. No

 

Task Management

ComponentProtocolDirectionPortConnectionsService NameIs configurable?
Task Server (atrshost.exe)TCPInbound/Outbound80/443Task Server downloads tasks from NS and sends task-result xml to NS.AtrsHost, W3SVCYes. Either through IIS, or with Altiris HTTP; use the Altiris.Http.config file.
Task Server (atrshost.exe)TCPInbound/Outbound50123Tickle port. Opened by TS on NS during TS registration on NS after install.
Used to receive real-time notifications when some new tasks are to be executed.
NS sends tickle to TS when a new task is available.
AtrsHostYes. Altiris.ClientTask.TickleService.config
Client Task AgentTCPInbound/Outbound80/443Obtains the list of Task Servers and TS properties from the NS part of TS.AeXNSClient, W3SVCYes. Either through IIS, or with Altiris HTTP; use the Altiris.Http.config file.
Client Task AgentTCPInbound/Outbound80/443CTA checks for the new task and sends the task-result xml to TS.AeXNSClient, W3SVCYes. Either through IIS, or with Altiris HTTP; use the Altiris.Http.config file.
Client Task AgentTCPInbound/Outbound50124Tickle port. Opened by CTA on TS during registration.
Used to receive real-time notifications when some new tasks are to be executed.
TS send tickle to client if new task is available.
AeXNSClientYes. Altiris.ClientTask.Server.config

 

Package Server

ComponentProtocolDirectionPortConnectionsService NameIs configurable?
Package ServerTCPInbound80/443From client computers HTTP/HTTPS.W3SVCYes, depends on the port used by the website Package Server is residing on.
Package ServerTCPInbound445From client computers UNC.SystemNo
Package ServerTCP Outbound 445To Notification Server UNC.AeXNSClientNo
Package ServerTCPOutbound52030Package MulticastingAeXNSClientYes, in Symantec Management Console.
Package ServerUDPOutbound52030Package MulticastingAeXNSClientYes, in Symantec Management Console.
Package ServerTCP/UDPInbound135From client computers UNC.RpcSs (svchost.exe)No
Package ServerTCP/UDPInbound139From client computers UNC.SystemNo
Package ServerUDPInbound137From client computers UNC.SystemNo

 

Symantec Management Agent for Windows

ComponentProtocolDirectionPortConnectionsService NameIs configurable?
Notification ServerTCPInbound80/443From client computers.W3SVCYes, depends on the port used by the website Notification Server is residing on.
Symantec Management AgentTCPOutbound80/443To Notification Server.AeXNSClientYes, depends on the port used by the website Notification Server is residing on.
Symantec Management AgentTCPInbound445Push install from Notification Server.SystemNo
Symantec Management AgentTCPInbound52028Tickle / Power Management.AeXNSClientYes, in Symantec Management Console.
Symantec Management AgentUDPInbound52028Tickle / Power Management.AeXNSClientYes, in Symantec Management Console.
Symantec Management AgentTCPInbound52029Tickle / Power Management multicast.AeXNSClientYes, in Symantec Management Console.
Symantec Management AgentUDPInbound52029Tickle / Power Management multicast.AeXNSClientYes, in Symantec Management Console.
Symantec Management AgentTCP/UDPOutbound56118Peer-to-peer (P2P) local HTTP server.AeXNSClientYes, in Symantec Management Console.

 

Symantec Management Agent for ULM

ComponentProtocolDirectionPortConnectionsIs configurable?
Notification ServerTCPInbound80/443From client computersYes, depends on the port used by the website the Notification Server is residing on.
UNIX, Linux or Mac client computerTCPOutbound80/443To the Notification ServerYes, depends on the port used by the website the Notification Server is residing on.
UNIX, Linux or Mac client computerTCPOutbound80/443To Package and Task ServersYes, depends on the ports used by the website the Package Server Agent is integrated with.
UNIX, Linux or Mac client computerTCPOutboundSource ports 1024 and aboveTo the Notification Server, Package, and Task Servers.No, the ports are randomly selected when the connection is established.
UNIX, Linux or Mac client computerTCPInbound22 (SSH)Push install from the Notification Server.Yes, depends on the port used by SSHD.
UNIX, Linux or Mac client computerTCPInbound52028Tickle / Power Management messages.Yes, in the SM Console.
UNIX, Linux or Mac client computerUDPInbound52028Tickle / Power Management messages.Yes, in the SM Console.
UNIX, Linux or Mac client computerUDPInbound52029Multicast (default group is 224.0.255.135)Yes, in the SM Console.

 

Activity Center

ComponentProtocolDirectionPortConnectionsIs configurable?
Activity Center UITCP Inbound 80/443 HTTP/HTTPSYes

 

Asset Management Solution

N/A

 

Client Management Suite Portal Page

The portal page contains web parts of other solutions - i.e. covered with specifications for other solutions, no special ports used.

 

CMDB Solution

N/A

 

Deployment Solution

For storing images on the Package Server and for communication from preOS with SMP infrastructure, Deployment Solution uses SMP ports and protocols.

ComponentProtocolDirectionPortConnectionsService NameIs configurable?
HTTP/HTTPS imagingHTTP/HTTPSOutbound80/443Creating and Deploying images.W3SVCYes
PXE ServerPXE over UDPInbound/Outbound67-68/4011Network boot using PXE, Port 67 is used when PXE Server is not on DHCP Server machine.SymantecNetworkBootServicePxeNo
PXE ServerPXE over UDPInbound/OutboundTCP 4433Network boot using PXE, TCP port 4433 is used for both communication and file transfer.SymantecNetworkBootServicePxeNo
TFTP ServerTFTP over UDPInbound69TFTP requests for file download.SymantecNetworkBootServiceTftpNo
TFTP ServerTFTP over UDPInbound/Outbound1024-65535TFTP file download port. TFTP Server uses the first available free port for TFTP file download.SymantecNetworkBootServiceTftpNo

 

Event Console

ComponentProtocolDirectionPortConnectionsService NameIs configurable?
Event ReceiverTCPInbound8500Alert PortEventReceiverYes, in the Global Settings Item configuration XML.
Event EngineTCPInbound8501Alert PortEventEngineYes, in the Global Settings Item configuration XML.
Event ReceiverTCPInbound8502Receiver Refresh PortEventReceiverYes, in the Global Settings Item configuration XML.
Event EngineTCPInbound8503Engine Refresh PortEventEngineYes, in the Global Settings Item configuration XML.
Event EngineUDP 64522, 64523, 64527, 64528 EventEngineNo
Event ReceiverUDPInbound162SNMP trapEventReceiverNo
Event ReceiverUDP 64524, 64525, 64526, 64529 EventReceiverNo

 

First-Time Setup Portal

ComponentProtocolDirectionPortConnectionsIs configurable?
FTSP UITCPInbound 80/443 HTTP/HTTPSYes 

 

Internet Gateway

ComponentProtocolDirectionPortConnectionsService NameIs configurable?
GatewayTCPInbound443*Gateway accepts connections from CEM agents to route them to NS on CEM port (default 4726).SymantecManagementPlatformInternetGatewayYes
GatewayTCPOutboundSystem-defined range*Ports that are used by apache service to perform calls to NS on CEM port.SymantecManagementPlatformInternetGatewayYes

* You might need to open more ports to let the name resolution work correctly. For example, for the NetBIOS name resolution you must open UDP port 137 (TCP, UDP).

 

Inventory Solution

Inventory Solution works through the Symantec Management Agent. There is no difference from that of the Symantec Management Agent for Windows ports.

 

Inventory Solution - ULM

Inventory Solution - ULM works through the Symantec Management Agent. There is no difference from that of the Symantec Management Agent for ULM ports.

 

Inventory Rule Management

Inventory Rule Management works through the Altiris Agent. There is no difference from that of the Altiris Agent for Windows ports.

 

Inventory for Network Devices

ComponentProtocolDirectionPortConnectionsIs configurable?
SNMP Protocol Plug-inUDP Outbound/Inbound161Predefined IANA network port for SNMP protocol for agents to listen to SNMP requests.
In addition to above, we need to run Network discovery first(as a pre-requisite) and which uses the ports as configured through the Pluggable Protocols Architecture.
No
SNMP TrapListener Protocol Plug-inUDPInbound162Predefined IANA network port for SNMP protocol for listening to SNMP traps.No

 

ITMS Admin App (iPad)

ComponentProtocolDirectionPortConnectionsIs configurable?
Tablet ServiceTCP/IPInbound/Outbound80/443 HTTP/HTTPS for ITMS management and status.Yes

 

Mobile Device Management (MDM)

The MDM configuration requires TCP port 443 to be opened (Inbound/Outbound) to allow communication between the MDM server, the Notification Server, the MDM-managed MacOS endpoints, and Apples's APNS server as documented in the following: Setting up and Configuring the MDM Server

Monitor Solution (Monitor Solution for Servers)

Monitor solution also uses the ports as configured through the Pluggable Protocols Architecture (PPA).

ComponentProtocolDirectionPortConnectionsService NameIs configurable?
Metric ProviderTCPInbound/Outbound1011 Real-Time Performance Viewer, Metric Provider.MetricProvider (Windows)
altirisSM (Linux/UNIX)
Yes, in Symantec Management Console.
Metric ProviderUDP Inbound/Outbound RandomPPA opened dynamic ports for SNMP metrics, agentless monitoring.MetricProvider (Windows)
altirisSM (Linux/UNIX)
No
Metric ProviderTCPInbound/OutboundRandomPPA opened dynamic ports for agentless monitoring connections.MetricProvider (Windows)
altirisSM (Linux/UNIX)
No

 

Network Discovery

Network Discovery uses the ports as configured through the Pluggable Protocols Architecture (PPA).

 

Network Topology Viewer

Viewer just uses the visualization webpart containing data gathered by other solutions (Network Discovery, PPA), no special ports are used.

 

Patch Management Solution for Windows

Patch Management solution for Windows works through the Symantec Management Agent (and Client Task Agent for vulnerability assessment task). There is no difference from that of the Symantec Management Agent for Windows ports.
Requires access from Notification Server to SolutionSam and vendor sites to download patch data and patches from vendor sites. See Detailed Import Patch Management for Windows access to SolutionSam and Vendor Download Sites for more information.

 

Patch Management Solution for Linux

Patch Management Solution for Linux works through the Symantec Management Agent. There is no difference from that of the Symantec Management Agent for ULM ports.
Requires access from Notification Server to RedHat, SUSE, and CentOS sites to download patch data and patches from vendor sites.

 

Patch Management Solution for MAC

Patch Management Solution for MAC works through the Symantec Management Agent. There is no difference from that of the Symantec Management Agent for ULM ports.
Requires access from Mac endpoint to Apple site to communicate with Apple Update Server to make assessments and download patch data.

 

Pluggable Protocol Architecture

PPA is a component that can be loaded to any service/process, but is mostly used by MetricProvider, AtrsHost, and AMTRedirectionService.

ComponentProtocolDirectionPortConnectionsService NameIs configurable?
AMT Protocol PluginTCP/UDPOutbound/Inbound16992Predefined IANA network port for Intel AMT to send and receive data (SOAP/HTTP).MetricProvider, AtrsHost, AMTRedirectionService, etc. (can be loaded by any process using PPA SDK)No
AMT Protocol PluginTCP/UDPOutbound/Inbound16993Predefined IANA network port for Intel AMT to send and receive data (SOAP/HTTPS).MetricProvider, AtrsHost, AMTRedirectionServiceNo
AMT Protocol PluginTCP/UDPOutbound/Inbound16994Predefined IANA network port for Intel AMT to send and receive data (Redirection/TCP).MetricProvider, AtrsHost, AMTRedirectionServiceNo
AMT Protocol PluginTCP/UDPOutbound/Inbound16995Predefined IANA network port for Intel AMT to send and receive data (Redirection/TLS).MetricProvider, AtrsHost, AMTRedirectionServiceNo
ASF Protocol PluginUDPOutbound/Inbound623Predefined IANA network port for ASF protocol to send and receive data. (RMCP - Remote Management and Control Protocol).MetricProvider, AtrsHostNo
ASF Protocol PluginUDPOutbound/Inbound664Predefined IANA network port for ASF protocol to send and received data. (RSP - RMCP Security Extensions Protocol).MetricProvider, AtrsHostNo
EMC Protocol PluginTCPOutbound443 MetricProvider, AtrsHostYes
HTTP Protocol PluginTCPOutbound/Inbound80Predefined IANA network port for HTTP protocol to send and receive data.MetricProvider, AtrsHostNo
IPMI Protocol PluginTCPOutbound/Inbound623 MetricProvider, AtrsHostYes
SNMP Protocol PluginUDPOutbound/Inbound161Predefined IANA network port for SNMP protocol for agents to listen to SNMP requests.MetricProvider, AtrsHostNo
SNMP TrapListener Protocol PluginUDPInbound162Predefined IANA network port for SNMP protocol for listening to SNMP traps.MetricProvider, AtrsHostNo
SNMP TrapListener ProtocolUDP 1024-65536Four additional UDP ports are opened by net-SNMP open-source library used by our code.MetricProvider, AtrsHost 
SSH Protocol PluginTCP/UDPInbound/Outbound22Predefined network port for SSH protocol.MetricProvider, AtrsHostYes
VMware Protocol PluginTCPInbound/Outbound80/443Default port for communication.MetricProvider, AtrsHostYes
WMI Protocol PluginTCPInbound/Outbound135Default port for communication.MetricProvider, AtrsHostNo
WS-MAN Protocol PluginTCPInbound/Outbound623Predefined IANA network port for WS-MAN protocol.MetricProvider, AtrsHostYes
WS-MAN Protocol PluginTCPInbound/Outbound664Predefined IANA network port for WS-MAN protocol.MetricProvider, AtrsHostYes
WMI Protocol PluginTCP/UDPInbound/Outbound1025-5000Dynamic ports for communication. No
WMI Protocol PluginTCP/UDPInbound/Outbound49152-65535Dynamic ports for communication. No

 

Power Scheme

Power Scheme solution works through the Symantec Management Agent. There is no difference from that of the Symantec Management Agent for Windows ports.

 

Real-Time System Management (RTSM\RTCI)

Real-Time System Management works through the Pluggable Protocol Architecture. There is no difference from that of the Pluggable Protocol Architecture component ports..

 

Server Management Suite Portal Page

The portal page contains web parts of other solutions or tasks from other solutions - i.e. covered with specifications for other solutions (Monitor, Discovery, PPA, Event Console, RTCI,  Task Management, NS Server, etc).

 

Symantec Endpoint Protection Integration Component

Symantec Endpoint Protection Integration Component (SEPIC) relies on the ports configured for the Notification Server. 

 

Software Management Framework

Software Management Framework works through the Symantec Management Agent. There is no difference from that of the Symantec Management Agent for Windows ports.

 

Software Management Solution - ULM

Software Management Solution - ULM works through the Symantec Management Agent. There is no difference from that of the Symantec Management Agent for ULM ports.

 

Software Management Solution - Windows

Software Management Solution for WIndows - works through the Symantec Management Agent. Software Portal works through the HTTP(s) port, configured for the Notification Server (80/443 by default).

 

Symantec Workflow

ComponentProtocolDirectionPortConnectionsService NameIs configurable?
Workflow ServerTCP/IPInbound/Outbound80/443HTTP/HTTPS for ProcessManager Portal, etc.SWFSVRYes
Server ExtensionsTCP/IPInbound/Outbound11434Publishing from Workflow Designer. Yes, but not recommended.
Enterprise Management/DeploymentTCP/IPInbound/Outbound11436Deployment and registration from Workflow Enterprise Manager. No
Workflow ComponentsVarious Inbound/Outbound Various Workflow Designer is a development tool that allows the use of components to integrate with myriad systems and protocols. Ports will vary based on customers' designs and requirements. Yes

 

Virtual Machine Management

ComponentProtocolDirectionPortConnectionsIs configurable?
VMware Protocol PluginTCP Inbound/Outbound 443Default port for communication.Yes
MSHyperV Protocol PluginTCP Inbound/Outbound135 Default port for communication.No

 

Power Control Task

ComponentProtocolDirectionPortConnectionsIs configurable?
Wake on LanTCP Outbound 50200Default port for communication.Yes

Additional Information

169520 TCP/UDP ports required in Ghost Solution Suite 3.X