Firewall Consideration and Ports Availability
Internal (Local) Ports
On each server, the following ports should be opened for internal communication:
On each server, all outbound ports should be opened, to allow communicating with other servers as needed.
On each server, the following inbound ports should be opened according to the installed services. The BriefCam application listens for incoming traffic from these ports. The installer will create the relevant Windows firewall rules for these ports.
Component | Port # |
BI Face Recognition Service | TCP 2556, TCP 13004 |
Face Recognition Matching Service | TCP 2553, TCP 13002 |
Filtering Service | TCP 2555, TCP 13001 |
License Service | TCP 1947 |
Lighthouse Service | TCP 2557 |
LPR Matching Service | TCP 2554, TCP 13003 |
MilestoneSSOProvider | TCP 8030 |
Notification Service | TCP 7080 |
PostgreSQL | TCP 5432 |
Rabbit MQ | TCP 5672, TCP 15672 |
Storage | TCP 139, TCP 445 |
Storage Gateway Service | TCP 5012 |
Video Streaming Gateway Service | TCP 5010 |
VSServer Service | TCP 1112, TCP 1113 |
Web Services (BOA, ProWebApi, AdminWebApi) | HTTP (80) |
Hub | |
BI Hub Export Gateway | TCP 5007 |
Outbound API Gateway | TCP 5005 |
Hub SSO Gateway (for future versions) | TCP 5008 |
RESEARCH (BI) Ports
RESEARCH (Qlik) | Port # | |
HTTP | TCP 8090 | Inbound / Outbound |
HTTPS | TCP 443 | Inbound / Outbound |
API ports | TCP 4242, TCP 4243 | Inbound / Outbound |
Qlik Sense Engine Service | TCP 4747 | Inbound / Outbound |
Broker Service | TCP 4900 | Inbound / Outbound |
Qlik Sense Repository Database (QRD) | TCP 4432 | Inbound |
Qlik Sense Printing Service (QPR Listen Port) | TCP 4899 | Inbound / Outbound |
Qlik Sense Logging Service | TCP 7070 | Outbound |
License Service | TCP 9200 | Outbound |
External Ports
Note
The following ports should be opened to traffic coming from the end users’ browsers.
Component | Port # | Comment |
Web Services | HTTP (80) | |
RESEARCH | HTTP (8090) | Not needed when using a load balancer |
Video Streaming Gateway Service | TCP 5010 | |
Notification Service | TCP 7080 | |
Storage Gateway Service | TCP 5012 |
To work with HTTPS and port 443, you need to use a load balancer. For more information, see Installing and Configuring NGINX.
Note
Some ports can be changed if they are not allowed on the customer’s network. For detailed instructions, see Changing Default Ports Configuration.