Default ports used in Intelligent Sandbox communication

Prev Next

Intelligent Sandbox uses many ports for network communications.

Client

Server

Default port

Configurable

Description

Any (desktop and REST API client)

Intelligent Sandbox

TCP 443 (HTTPS)

No

Access the Intelligent Sandbox web interface and REST API client.

Any (desktop)

Intelligent Sandbox

TCP 6080 (HTTPS)

No

For VM activation process and X-mode.

Any (FTP client)

Intelligent Sandbox

TCP 21 (FTP)

No

Access the FTP servers on Intelligent Sandbox

Any (SFTP client)

Intelligent Sandbox

TCP 22 (SFTP)

No

Access the SFTP servers on Intelligent Sandbox

Sensor

Intelligent Sandbox

TCP 8505

No

Communication channel between a Sensor and Intelligent Sandbox

Manager

Intelligent Sandbox

TCP 443 (HTTPS)

No

Communication between the Manager and Intelligent Sandbox through the RESTful APIs.

Intelligent Sandbox

ePolicy Orchestrator - On-premises

TCP 8443

Yes

Host information queries.

Intelligent Sandbox

atd.repl.gti.trellix.com

TCP 443 (HTTPS)

No

File Reputation queries.

Intelligent Sandbox

List.smartfilter.com

TCP 80 (HTTP)

No

URL updates.

Intelligent Sandbox

All DXL Brokers in your environment

TCP 8883 (HTTP)

No

DXL connection from TIS to DXL broker

Intelligent Sandbox

All Trellix ePO in your environment

TCP 443 (HTTP)

No

Trellix Agent on TIS gets DXL certificates from Trellix ePO

Intelligent Sandbox (DAT updates)

tau.skyhigh.cloud

tau-02.tau.skyhigh.cloud

tau-03.tau.skyhigh.cloud

tau-04.tau.skyhigh.cloud

cdn.tau.skyhigh.cloud

europe.tau.skyhigh.cloud

usa.tau.skyhigh.cloud

asia.tau.skyhigh.cloud

rpns.skyhigh.cloud

mwg-update.skyhigh.cloud (Akamai CDN)

tau-manual.skyhigh.cloud

TCP 443 (HTTPS)

No

Updates for Trellix Gateway Anti-Malware Engine and Trellix Anti-Malware Engine.

Intelligent Sandbox (Software updates)

atdupdate.trellix.com

TCP 443 (HTTPS)

No

Updates for the Intelligent Sandbox software. The update includes new detection and application package.

Intelligent Sandbox Telemetry

atd.rest.gti.trellix.com

TCP 443 (HTTPS)

No

Sends telemetry data to Trellix. For information on what data is sent, see Configure telemetry in Intelligent Sandbox Installation Guide.

Any (SSH client)

Intelligent Sandbox

TCP 2222 (SSH)

No

CLI access.

Intelligent Sandbox

update.nai.com

TCP 80 (HTTP)

Trellix Agent internal task (ma.cert.update.task ), see KB85552.

Intelligent Sandbox

 trustedsource.org

ICMP (echo)

GTI/cloud services connection tests during support bundle generation.

Intelligent Sandbox

 tau.mcafee.com

ICMP (echo)

DAT connection tests during support bundle generation.