Default Trellix DLP ports

Prev Next

Trellix DLP uses several ports for network communication. Configure any intermediary firewalls or policy-enforcing devices to allow these ports where needed.

All listed protocols use TCP only, unless noted otherwise.

For information about ports that communicate with ePO - On-prem, see KB66797.

Trellix DLP Discover default ports

Port, protocol

Use

  • 137, 138, 139 — NetBIOS

  • 445 — SMB

SMB/CIFS scans

Any standard NFS port.

NFS scans

  • 80 — HTTP

  • 443 — SSL

  • Box and SharePoint scans

  • Evidence storage service

  • DLP Server REST API for registered documents fingerprint matching

SharePoint servers and evidence storage service might be configured to use non-standard HTTP or SSL ports. If needed, configure firewalls to allow the non-standard ports.

53 — DNS (UDP)

DNS queries

80, 443 — HTTP and HTTPS

ePO - On-prem server communication, evidence copy operations via DLP Server, and queries to registered documents services.

  • 1801 — TCP

  • 135, 2101*, 2103*, 2105 — RPC

  • 1801, 3527 — UDP

* Indicates that the port numbers might be incremented by 11 depending on the available ports at initialization.

For more information, see Microsoft KB article 178517.

Microsoft Message Queuing (MSMQ)

1433

Microsoft SQL

1521

Oracle

3306

MySQL

50000

DB2



Trellix DLP Endpoint default port

Port

Use

Direction

514

Syslog

Outbound



Trellix DLP Network Prevent and Trellix DLP Network Monitor default ports

Port

Use

Direction from the appliance

22 — SSH

SSH (when enabled)

Inbound

88 — KERBEROS5 (UDP)

Kerberos5 user authentication

Outbound

161 (UDP)

SNMP (when enabled)

Inbound

162 (UDP)

SNMP traps (when enabled)

Outbound

445 — SMB, 137, 138, 139 — NetBIOS

Evidence copy

Outbound

8081 — ePO - On-prem

ePO - On-prem agent service

Inbound

10443 — HTTPS

HTTPS traffic to download, for example, the Minimum Escalation Report (MER) and MIB files

Inbound

53 — DNS (UDP)

DNS queries

Outbound

123 — NTP (UDP)

NTP requests

Inbound and outbound

389 — LDAP

636 — LDAP over SSL

3268 — (LDAP) Active Directory Global Catalog

3269 — (LDAP) Active Directory Global Catalog over SSL

Obtaining groups for rule evaluation

Outbound

80, 443 — HTTP and HTTPS

ePO - On-prem server communication, evidence copy operations via DLP Server, and queries to registered documents services

Outbound

61613

Trellix Logon Collector

Outbound

514

Syslog

Outbound



Trellix DLP Network Prevent default ports

Port

Use

Direction

25 — SMTP

SMTP traffic with the MTA

Inbound and outbound

587 — SMTP AUTH

SMTP AUTH traffic with the MTA

Inbound and outbound

1344, 11344 — ICAP and ICAP over SSL

ICAP traffic with the web proxy

Inbound



Trellix DLP Network Monitor default port

Port

Use

Direction

941 — over SSL

Receives scanning requests from the packet acquisition device

Inbound