Communication & Port Requirements
search cancel

Communication & Port Requirements

book

Article ID: 286607

calendar_today

Updated On: 03-28-2025

Products

Carbon Black App Control (formerly Cb Protection)

Issue/Introduction

What ports and addresses are required for Agent and Server communication?

Environment

  • App Control Server: All Supported Versions
  • App Control Agent: All Supported Versions

Resolution

Between Server & Agents

URL & Port Used For Configurable?
Server Address via 41002

General communication between Agent & Server, examples:

  • Incremental Configlist updates
  • Connection Status
  • Events generated by Agent
Resource Download Location via 443
  • Console access (not configurable)
  • File transfers between Agent & Server, examples:
    • Agent Upgrades
    • Agent Diagnostics
    • Full Configlist

File transfers can be changed using either:

 

Between Server & External Services

URL & Port Used For Configurable?
services.bit9.com via 443
TLS 1.2 is currently required
  • Reputation Synchronization
  • Updater/Rapid Config updates
  • Health Indicators
No
Optional: Outbound 514 access Exporting Events via SYSLOG Yes
Two Tier Environments: 1433 to SQL Server SQL Server connections Yes, during Server install

 

Publisher Validation (CRL Checks)

  • The URL and Port combination for the Certificate Revocation List Distribution Point is determined by the issuing Certificate Authority.
  • The Agent and Server will rely on the Operating System to validate these certificates via the CRL Distribution Point.
  • If using a Proxy for Internet Access this information must be set at the OS Layer to allow the Agent generated CRL Traffic to follow the Proxy settings.

Additional Information

  • The endpoints and application server must posses a matching Cipher Suite & Protocol.
    • SSL Inspection is not supported for communication between the Agents and Server.
    • The Agent does not officially support communication with the Server through a Proxy.
  • HTTP Session Sharing (Ex: F5 OneConnect) is not supported.
  • The source port opened by the Agent will be determined by the OS ephemeral port configuration and is not determined by the App Control Agent.
  • Further detail about the ports, and communication requirements can be found on Tech Docs > Server > Server OER > Communication Requirements.