Use | Application Protocol | Transport Protocol | Port Number | Destination | Direction | Note |
Admin UI / onbox quarantine digest (EWS) | SSL | TCP | 443 | Your EWS appliance | Inbound | |
Admin UI / onbox quarantine digest (MEG) | SSL | TCP | 10443 | Your MEG appliance | Inbound | |
Anti Virus updates | FTP | TCP | 21 | ftp.nai.com | Outbound | Uses PASV. |
Anti Virus updates | HTTP | TCP | 80 | update.nai.com | Outbound | |
2nd Anti-Virus Engine/signature updates | SSL | TCP | 443 | tau.mcafee.com mwg-update.mcafee.com | Outbound | |
Anti-Spam Engine | FTP | TCP | 21 | ftp.nai.com | Outbound | Uses PASV. |
Anti-Spam Rules and Streaming updates | HTTP | TCP | 80 | http://su3.mcafee.com/su3 http://sav-su3-1.mcafee.com 208.69.152.139 192.187.128.17 | Outbound | Packet types: X-SU3X-SU3-Component-Name X-SU3-Component-Type X-SU3-Status |
Directory Service (and Active Directory) | LDAP | TCP | 389 | Your directory server | Outbound | |
Domain Name System (DNS) | DNS | TCP/UDP | 53 | Your DNS server | Outbound | Used for various name resolution, for example McAfee update servers, email delivery, RBL lookup. |
Email Hybrid | Proprietary | TCP | 25 | Your MEG appliance | Inbound | SaaS Control Console to appliance for inbound email. |
Email Hybrid | SSL | TCP | 443 | 208.65.144.0/21 208.81.64.0/21 | Outbound | Appliance to the SaaS API web service URLs (hybridapi.mxlogic.com). |
Global Threat Intelligence (GTI) Feedback | SSL | TCP | 443 | gtifeedback.trustedsource.org | Outbound | GTI feedback uses port 443, but they are not HTTPS. Using HTTPS proxy will break the GTI protocol. See KB78732. |
Global Threat Intelligence (GTI) File Reputation (Artemis) | DNS | UDP | 53 | Your DNS server | Outbound | |
Global Threat Intelligence (GTI) Message Reputation (TrustedSource) | SSL | TCP | 443 | tunnel.web.trustedsource.org | Outbound | GTI lookups use port 443, but they are not HTTPS. Using HTTPS proxy will break the GTI protocol. See KB78732. |
LDAP (and Active Directory) Global Catalog | LDAP | TCP | 3268 | Your directory server | Outbound | Available on MEG 7.x. |
MQM legacy communication port | Proprietary | TCP | 49500 | Your MQM server | Bidirectional | Available on EWS 5.6 and MEG 7.0. |
MQM communication port | HTTP | TCP | 80 | Your MQM server | Bidirectional | Condition applies if your firewall sits between MQM server and the appliance. |
MQM communication port | HTTPS | TCP | 443 | Your MQM server | Bidirectional | Available on MEG 7.5 or later. |
Secure LDAP (and Active Directory) | Secure LDAP | TCP | 636 | Your directory server | Outbound | Available on MEG 7.x. |
Secure LDAP (and Active Directory) Global Catalog | Secure LDAP | TCP | 3269 | Your directory server | Outbound | Available on MEG 7.x. |
Secure Web Mail client | SSL | TCP | 443 | Your MEG appliance | Inbound | Available on MEG 7.x. |
Software package updates, for example patches | FTP | TCP | 21 | ftp.nai.com | Outbound | Uses PASV. |
URL reputation database update | HTTP | TCP | 80 | list.smartfilter.com | Outbound | |
URL reputation lookup | SSL | TCP | 443 | tunnel.web.trustedsource.org | Outbound | GTI lookups use port 443, but they are not HTTPS. Using HTTPS proxy will break the GTI protocol. |