This article provides a reference of commonly used inbound ports, outbound service ports, and external URLs that may be required for SMA1000 deployments. These requirements can be used when configuring firewalls, access control policies, and network security rules.
The following inbound ports may be required to allow users and administrators to access SMA1000 services.
|
Service |
Protocol / Port |
Description |
|
Connect Tunnel / Mobile Connect |
TCP 443 |
VPN tunnel service. When enabled, the tunnel can optionally use UDP encapsulation (ESP mode) to improve performance.
|
|
Connect Tunnel / Mobile Connect (ESP) |
UDP 4500 |
UDP transport for Connect Tunnel / Mobile Connect traffic.
|
|
Workplace |
TCP 443 |
End-User Web portal access |
|
Management Console (AMC/CMC) |
TCP 8443 |
Web administration access |
|
SSH |
TCP 22 |
Command-line administration |
|
Health check service |
TCP 1888 |
For use with external load balancers (not required for GTO) |
|
SNMP |
UDP 161 |
Access can be restricted on a per-interface basis. |
Note: Access to management services such as AMC/CMC and SSH should not be exposed to the public internet; rather they should be restricted to trusted administrative networks whenever possible.
The SMA1000 may initiate outbound connections for authentication, directory services, notifications, logging, and identity provider integrations.
The SMA1000 may initiate outbound connections for authentication, directory services, notifications, logging, and identity provider integrations.
|
Service |
Protocol / Port |
Description |
|
SMTP |
TCP 25 |
Email notifications |
|
SNMP |
UDP 162 |
SNMP traps |
|
DNS |
UDP/TCP 53 |
DNS services (CMS/GTO deployments) |
|
NTP |
UDP 123 |
Time synchronization |
|
LDAP |
TCP/UDP 389 |
Active Directory / LDAP authentication |
|
LDAPS |
TCP 636 |
Secure LDAP authentication |
|
Kerberos |
TCP/UDP 88 |
Active Directory authentication |
|
Global Catalog |
TCP 3268 |
Active Directory lookups |
|
Global Catalog SSL |
TCP 3269 |
Secure Active Directory lookups |
|
RADIUS |
UDP 1812/1813 |
Authentication and accounting |
|
SAML / Entra ID / Okta |
TCP 443 |
Identity provider communication |
|
CRL / OCSP |
TCP 80 / 443 |
Certificate validation |
|
Syslog |
UDP/TCP 514 |
External logging |
The following SonicWall services may require outbound HTTPS access for licensing, updates, registration, and geographic lookup functionality.
lm2.sonicwall.com
software.sonicwall.com
wsdl.mysonicwall.com
maxmind.sonicwall.com
geows.global.sonicwall.com