Default ports

Prev Next

Trellix DLP – SaaS uses several ports for network. Configure any intermediary firewalls or policy-enforcing devices to allow the required ports where needed.

All listed protocols use TCP only, unless noted otherwise.

Trellix DLP Discover – SaaS default ports

Port, protocol

Use

  • 137, 138, 139 — NetBIOS

  • 445 — SMB

SMB/CIFS scans

Any standard NFS port.

NFS scans

  • 80 — HTTP

  • 443 — SSL

Evidence storage service might be configured to use non-standard HTTP or SSL ports. If needed, configure firewalls to allow the non-standard ports.

53 — DNS (UDP)

DNS queries

80, 443 — HTTP and HTTPS

ePO - SaaS server communication and evidence copy operations.

  • 1801 — TCP

  • 135, 2101*, 2103*, 2105 — RPC

  • 1801, 3527 — UDP

* Indicates that the port numbers might be incremented by 11 depending on the available ports at initialization.

For more information, see Microsoft KB article 178517.

Microsoft Message Queuing (MSMQ)



Trellix DLP EndpointTrellix DLP Endpoint - SaaS default port

Port

Use

Direction

514

Syslog

Outbound



Trellix DLP Network Prevent – SaaS and Trellix DLP Network Monitor – SaaS default ports

Port

Use

Direction from the appliance

22 — SSH

SSH (when enabled)

Inbound

88 — KERBEROS5 (UDP)

Kerberos5 user authentication

Outbound

161 (UDP)

SNMP (when enabled)

Inbound

162 (UDP)

SNMP traps (when enabled)

Outbound

8081 — ePO - SaaS

ePO - SaaS agent service

Inbound

10443 — HTTPS

HTTPS traffic to download, for example, the Minimum Escalation Report (MER) and MIB files

Inbound

53 — DNS (UDP)

DNS queries

Outbound

123 — NTP (UDP)

NTP requests

Inbound and outbound

389 — LDAP

636 — LDAP over SSL

3268 — (LDAP) Active Directory Global Catalog

3269 — (LDAP) Active Directory Global Catalog over SSL

Obtaining groups for rule evaluation

Outbound

80, 443 — HTTP and HTTPS

ePO - SaaS server communication and evidence copy operations

Outbound

61613

Trellix Logon Collector

Outbound

514

Syslog

Outbound



Trellix DLP Network Prevent – SaaS default ports

Port

Use

Direction

25 — SMTP

SMTP traffic with the MTA

Inbound and outbound

587 — SMTP AUTH

SMTP AUTH traffic with the MTA

Inbound and outbound

1344, 11344 — ICAP and ICAP over SSL

ICAP traffic with the web proxy

Inbound



Trellix DLP Network Monitor – SaaS default port

Port

Use

Direction

941 — over SSL

Receives scanning requests from the packet acquisition device

Inbound