The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Set the desktop firewall

Prev Next

It is recommended that a desktop firewall operate on the Manager server. The following ports are required for Manager-Sensor communication.

Note

Ensure that there are no other open ports using a scanning tool.

Port

Source

Destination

Description

Comments

443

Client

Manager

HTTPS

Communication from client to Manager

Note

The Manager is accessible via https://< hostname or host-IP>.

443

Manager

NTBA Appliance

Command Channel (TCP)

Manager to NTBA Appliance. Communication is bidirectional

3306

Internal

Manager

Manager Database (MySQL or MariaDB)

Internal to Manager; can be used externally to connect to the database

4166

Manager

Sensor

Command Channel (UDP)

Source port for IPv6 Manager to Sensor Communication (Manager Java 1.7u45 and later). Communication between Sensor and Manager is bidirectional.

4167

Manager

Sensor

Command Channel (UDP)

Source port for IPv4 Manager to Sensor Communication. Communication between Sensor and Manager is bidirectional.

8005

Internal

Manager

Tomcat Shutdown Port (TCP)

Tomcat uses this port to listen for shutdown hook

8007

Internal

Manager

Tomcat AJP 12 Port (TCP)

Internal to Manager

8009

Internal

Manager

Tomcat AJP 13 Port (TCP)

Internal to Manager

8500

Manager

Sensor

Command Channel (UDP)

Communication between Sensor and Manager is bidirectional

8501

Sensor

Manager

Install Port/Channel (TCP - Self-Signed)

Communication between Sensor and Manager is bidirectional

8502

Sensor

Manager

Alert Channel (Control Channel) (TCP - Self-Signed)

Communication between Sensor and Manager is bidirectional

8503

Sensor

Manager

Packet Log Channel (TCP - Self-Signed)

Communication between Sensor and Manager is bidirectional

8504

Sensor

Manager

File Transfer Channel (TCP)

Communication between Sensor and Manager is bidirectional

8506

Sensor

Manager

Install channel (TCP - CA-Signed)

Communication between Sensor and Manager is bidirectional

8507

Sensor

Manager

Alert channel (TCP - CA-Signed)

Communication between Sensor and Manager is bidirectional

8508

Sensor

Manager

Packet log channel (TCP - CA-Signed)

Communication between Sensor and Manager is bidirectional

8509

Sensor

Manager

Bulk file transfer channel for certificates (TCP - CA-Signed)

Communication between Sensor and Manager is bidirectional

8510

Sensor

Manager

Bulk file transfer channel for certificates (TCP - Self-Signed)

Communication between Sensor and Manager is bidirectional

8551

Internal

Manager

Lumos Nameserver (TCP)

Internal to Manager (RMI/IIOP)

8552

Internal

Manager

JONAS Nameserver (TCP)

Internal to Manager (RMI)

Note

  • Ports 8501 to 8503, 8510 use SHA256 signed 2048-bit or 4096-bit key length Self-Signed certificates.

  • Ports 8506 to 8509 use SHA256 signed 2048-bit or 4096-bit key length CA-Signed certificates.

If you configure Email Notification or SNMP Forwarding on the Manager, and have a firewall between the Manager and SMTP or SNMP Server, allow the following ports:

Port

Description

Communication

25

SMTP port

Communication from Manager to SMTP server

162

SNMP forwarding

Communication from Manager to SNMP server

Important

You must disable other web services before you install the Manager. The Manager server must integrate with the Apache server that's shipped with the Manager installation package. If other web services that use port 80 and 443 aren't disabled, the Manager installation fails. The failure happens because the Manager isn't able to run the Apache server.

Ports used for lookups and updates

Port

Source

Destination

Comments

80 TCP

Manager

download.nai.com

For downloading Botnet Detectors

443 TCP

Sensor

nsp.rest.gti.trellix.com

Trellix GTI File Reputation query

443 TCP

Manager/Sensor

nsp.repl.gti.trellix.comlist.smartfilter.com

Trellix GTI IP/URL reputation query

443 TCP

Manager (MLOS only)

download.nai.com

For downloading Antivirus DAT Signatures

443 TCP

Manager

nspupdate.trellix.com

IPS updates (can also be downloaded out-of-band and applied manually)

443 TCP

Manager

ips.repm.gti.trellix.com

Trellix GTI botnet detectors update; GTI participation information

443 TCP

Manager

tau.skyhigh.cloud

cdn.tau.skyhigh.cloud

europe.tau.skyhigh.cloud

usa.tau.skyhigh.cloud

asia.tau.skyhigh.cloud

For more information, see KB59342

Gateway Anti-Malware engine (GAM) downloads

443 TCP

Sensor

tau.skyhigh.cloud

cdn.tau.skyhigh.cloud

europe.tau.skyhigh.cloud

usa.tau.skyhigh.cloud

asia.tau.skyhigh.cloud

For more information, see KB59342

Gateway Anti-Malware engine (GAM) downloads

443 TCP

Manager

iam.cloud.trellix.com

iam-rs.cloud.trellix.com

telemetry.trellix.com

up-cloud.fireeye.com/fenet/notification

IPS Manager Product Registration, Activation, and Telemetry

443 TCP

Manager/Sensor

feapi.marketplace.apps.fireeye.com

For IVX Cloud communication

Third-party communications

In addition to the communication channels between the components of Trellix IPS, other communications can take place with third-party systems. These third-party systems include external syslog servers, SNMP monitoring systems, and authentication services.

Port/Protocol

Source

Destination

Purpose

25 TCP

Manager

$smtp-mta-server

Email notifications

49 TCP

Sensor

$tacacs+-server

TACACS+ based authentication to Sensor for command-line interface

69 UDP

Sensor

$tftp-server

TFTP server used for loadimage/netboot to install/update Sensor software

162 UDP

Manager

$snmp-server

SNMP trap notifications

389 TCP

Manager

$ldap-server

LDAP-based authentication to IPS Manager for GUI client

514 TCP/UDP

Manager

$syslog-server

Notifications via syslog, standard UDP, or optionally TCP

636 TCP

Manager

$ldaps-server

LDAPS-based authentication to IPS Manager for GUI client

1812 UDP

Manager

$radius-server

RADIUS-based authentication to IPS Manager for GUI client

Ports used for Network Threat Behavior Analysis (NTBA) communications

NTBA Appliances are similar to Sensors. However, they provide functionality focused on analyzing network flows which support overall analysis

Port

Source

Destination

Purpose

22 TCP

Any

NTBA

SSH connection for command-line access to Sensor

22 TCP

NTBA

$netflow-exporter

Router ACL channel

53 UDP

NTBA

$dns-server

DNS queries

80 TCP

NTBA

tunnel.web.trustedsource.org list.smartfilter.com

GTO database download

111 TCP/UDP

NTBA

$backup-server

NFS (optional) portmapper, for backups

137 UDP

NTBA

<any>

NetBIOS lookups

161 UDP

NTBA

$netflow-exporter

SNMP queries (2c/3)

443 TCP

NTBA

tunnel.web.trustedsource.org

Trellix GTI IP reputation query

443 TCP

NTBA

tau-usa.mcafee.com

Gateway Anti-Malware engine (GAM) downloads

443 TCP

NTBA

tau.mcafee.com

Antimalware downloads

445 TCP

NTBA

$backup-server

CIFS backups (optional)

2049 TCP

NTBA

$backup-server

NFS (optional) for backups

8444 TCP

NTBA

ePO

For certificate signing

8501 TCP

NTBA

Manager

Install/control channel

8502 TCP

NTBA

Manager

Alert channel

8504 TCP

NTBA

Manager

File transfer channel

8505 TCP

Sensor

NTBA

IPS channel (SSL AES-128 SHA-1)

9008 UDP

EIA

NTBA

EIA service (DTLS)

9996 UDP

$netflowexporter

NTBA

NetFlow channel

Note

Some of the ports and protocols listed are optional; their use depends on your specific configuration.

Ports used for ePolicy Orchestrator communications

Port

Source

Destination

Comments

3306 TCP

ePO

Manager

[Manager to ePO integration] Database connection to enable Maanger-related dashboards in ePO console

8443 TCP

Manager

ePO

[ePO to Manager integration] Manager pull/query of host information from ePO; requires Trellix IPS extension installation on ePO

Ports used for Trellix IPS Central Manager communications

Port

Source

Destination

Comments

443 TCP

Manager

Central Manager

Uses HTTPS protocol

443 TCP

Central Manager

Manager

Uses HTTPS protocol

Ports used for SIEM Enterprise Security Manager (ESM) communications

Port

Source

Destination

Comments

443 TCP

ESM

Manager

Access to Manager data

3306 TCP

ESM

Manager

MariaDB queries

Ports used for Trellix Intelligent Sandbox communications

Port

Source

Destination

Comments

443 TCP

Manager

Intelligent Sandbox

REST API communication

8505 TCP

Sensor

Intelligent Sandbox

Communication channel for Sensor data

Ports used for IVX communications

Port

Source

Destination

Comments

443 TCP

Manager

IVX/IVX Cloud

IVX REST API communication

443 TCP

Sensor

IVX/IVX Cloud

IVX REST API communication

Ports used for Trellix Network Investigator communications

Port

Source

Destination

Comments

443 HTTPS

Manager

Network Investigator appliance or cluster

Export alerts to Network Investigator

443 HTTPS

Sensor

Network Investigator appliance or cluster

Export flow and metadata to Network Investigator

Ports used for TIE/DXL communications

Port

Source

Destination

443 TCP

Sensor

ePO

8081 TCP

ePO

Sensor

8443 TCP

Sensor

ePO

8883 TCP

Sensor

DXL Broker

Note

If you have multiple DXL brokers, the Sensor connects to each of them on 8883 TCP. If the DXL broker is deployed on the ePO server, the Sensor connects to the ePO server on 8883 TCP.

Ports used for Trellix Logon Collector communications

Port

Source

Destination

Comments

61641

Manager

TLC Server

JMS communications between the Logon Collector and Manager

Note

For more information on the ports and traffic destinations used by Trellix IPS, refer to KB59342.