Security Services (GAV, Network AV, IPS, CFS, Firewall Registration) Ports and Protocol Usage
03/26/2020 355 People found this article helpful 487,545 Views
Description
The SonicWall Security Services require the use of various ports and protocols to function properly:
• Content Filtering Service
• Network Anti-Virus
• Gateway Anti-Virus
• Intrusion Prevention Service
• Firewall Registration
Resolution
Content Filtering
The Content Filtering Service equips SonicWall Internet security appliances to monitor usage and control access to objectionable Web content according to established Acceptable Use Policies.
The Content Filtering service uses DNS (Port 53 UDP & TCP) to look up the rating of any visited website.
If a site has numerous ratings (i.e. different directories on the server have different ratings), the firewall will send the lookup request to the CFS servers to port 2257 UDP.
Network Anti-Virus
SonicWall Network Anti-Virus is a distributed, gateway-enforced solution that ensures always-on, always-updated anti-virus software for every client on the network.
There are multiple components that make up the Network Anti-Virus service.
When the Network Anti-Virus service is activated, the firewall will connect to the Anti-Virus servers to check for the latest version of Virus Definitions and to see if any Virus Alerts have been issued. This is done via a secure HTTP connection to port 443 TCP (HTTPS). This is done once an hour. It is also possible for SonicWall to “push” a Virus Alert message to the SonicWall firewall. The anti-virus servers record the WAN IP address of the firewall that is connecting to our servers. The push is answered by the firewall on port 59155 UDP.
When an Anti-Virus enforced node attempts to access the internet, the firewall will send a request to the Network Anti-Virus client on port 59152 UDP. This is a request to the Network Anti-Virus software to make sure that the client has the latest Virus Definition file.
- Network Anti-Virus Software Client
The Network Anti-Virus software client resides on each workstation in the network. This provides the client computer with an on-access and on-demand file scanner. This is the component that downloads and stores the Virus Definition files.
The software client gets installed and does it’s Virus Definition updates all via a web based connection on Port 80 TCP to virusscanasap.mcafeeasap.com. The client will also try to update itself 6 minutes after a user logs into the machine, and then every 24 hours after the first successful update.
When an Anti-Virus enforced node attempts to access the internet, the firewall will send a request to the Network Anti-Virus client to port 59152 UDP. This is a request to the Network Anti-Virus software to make sure that the client has the latest
Gateway Anti-Virus:
Gateway Anti-Virus integrates a high performance Real-Time Virus Scanning Engine and dynamically updated signature database to deliver continuous protection from malicious virus threats at the gateway.
When the Gateway Anti-Virus service is activated, the firewall will connect to the Anti-Virus servers to check for the latest version of the Anti-Virus Signature Database. This is done via a secure HTTP connection to port 443 TCP (HTTPS). This is done once an hour.
Intrusion Prevention:
Intrusion Prevention integrates a high-performance Deep Packet Inspection architecture and dynamically updated signature database to deliver complete network protection from application exploits, worms and malicious traffic. In addition, Intrusion Prevention provides access control for Instant Messenger (IM) and Peer-to-Peer (P2P) applications.
When the Intrusion Prevention service is activated, the firewall will connect to the IPS database servers to check for the latest version of the Intrusion Prevention Signature Database. This is done via a secure HTTP connection to port 443 TCP (HTTPS).
Firewall Registration:
The firewall needs to be registered and have a connection to the internet at all times. The firewall connects to SonicWall’s registration server via a secure HTTPS connection to port 443 TCP (HTTPS).
Related Articles
Categories