Ports used by the system
The VMS consists of server and client components that communicate with each other over the network. Each component has a defined role and uses specific ports to provide or consume services.
-
Server components expose services that other components connect to, while client components initiate outbound connections to retrieve data, send requests, or receive events.
-
A single computer can host multiple components. To determine which ports must be opened on a specific machine, you must consider all components installed on that machine and how they communicate with other parts of the system.
-
Some connections use only local communication on the same computer. These ports do not require firewall rules for external traffic but are listed for completeness.
Server components (inbound connections)
Server components provide services that other components, clients, or external systems connect to. The tables below list the ports these server components listen on, which must be available for inbound connections on the computer where the service is installed.
When certificates are installed and the system is configured in secure mode, ports listed with the HTTP protocol will automatically switch to using HTTPS.
The Management Server service is an exception: it permanently exposes both port 80 (HTTP) and port 443 (HTTPS) for different purposes regardless of security mode.
For ports listed as TCP, see the note on TLS encryption below.
Management Server service and related processes
When encryption is enabled, communication on TCP ports is protected using TLS where supported.The port number does not change.
|
Port number |
Protocol |
Process |
Connections from... |
Purpose |
|---|---|---|---|---|
| 80 |
HTTP |
IIS | All servers and the XProtect Smart Client and the Management Client |
Used when communication is not secured with certificates. When certificates are installed, client communication uses HTTPS instead on port 443. Communication from the event server to the management server still uses port 80 and is secured using Windows Secured Framework (WCF) with Windows authentication. |
| 443 |
HTTPS |
IIS | All servers and the XProtect Smart Client and the Management Client | Used when communication is secured with certificates |
| 445 |
TCP |
Management Server service |
Management Server Manager. |
Enable Windows Active Directory users to be added to roles. |
| 6473 |
TCP |
Management Server service |
Management Server Manager tray icon, local connection only. |
Showing status and managing the service. |
| 8080 |
TCP |
Management server |
Local connection only. |
Communication between internal processes on the server. |
| 9000 | HTTP | Management server | Recording Server services | Web service for internal communication between servers. |
| 12345 |
TCP |
Management Server service |
XProtect Smart Client |
Communication between the system and Matrix recipients. You can change the port number in the Management Client. |
| 12974 |
TCP |
Management Server service |
Windows SNMP Service |
Communication with the SNMP extension agent. Do not use the port for other purposes even if your system does not apply SNMP. |
SQL Server service
When encryption is enabled, communication on TCP ports is protected using TLS where supported.The port number does not change.
|
Port number |
Protocol |
Process |
Connections from... |
Purpose |
|---|---|---|---|---|
| 1433 |
TCP |
SQL Server |
Management Server service |
Storing and retrieving configurations via the Identity Provider. |
| 1433 |
TCP |
SQL Server |
Event Server service |
Storing and retrieving events via the Identity Provider. |
Data Collector service
|
Port number |
Protocol |
Process |
Connections from... |
Purpose |
|---|---|---|---|---|
| 7609 |
HTTP |
IIS |
On the management server computer: Data Collector services on all other servers. On other computers: Data Collector service on the Management Server. |
Collect and provide data for System Monitor. |
Event Server service
When encryption is enabled, communication on TCP ports is protected using TLS where supported.The port number does not change.
|
Port number |
Protocol |
Process |
Connections from... |
Purpose |
|---|---|---|---|---|
| 1234 |
TCP/UDP |
Event Server Service |
Any server sending generic events to your XProtect system. |
Listening for generic events from external systems or devices. Only if the relevant data source is enabled. |
| 1235 |
TCP |
Event Server service |
Any server sending generic events to your XProtect system. |
Listening for generic events from external systems or devices. Only if the relevant data source is enabled. |
| 9090 |
TCP |
Event Server service |
Any system or device that sends analytics events to your XProtect system. |
Listening for analytics events from external systems or devices. Only relevant if the Analytics Events feature is enabled. |
| 22331 |
TCP |
Event Server service |
XProtect Smart Client and the Management Client |
Configuration, events, alarms, and map data. |
| 22332 |
WS/WSS HTTP/HTTPS* |
Event Server service |
API Gateway and the Management Client |
Event/State Subscription, Events REST API, Websockets Messaging API, and Alarms REST API. |
| 22333 |
TCP |
Event Server service |
MIP Plug-ins and applications. |
MIP messaging. |
*A 403 error will be returned when accessing HTTP to access an HTTPS-only endpoint.
Recording Server service
When encryption is enabled, communication on TCP ports is protected using TLS where supported.The port number does not change.
|
Port number |
Protocol |
Process |
Connections from... |
Purpose |
|---|---|---|---|---|
| 5210 |
TCP |
Recording Server Service |
Failover recording servers. |
Merging of databases after a failover recording server had been running. Accessing archived camera video on the original recording server after the camera has been transferred to another recording server. If the port is not open, archived camera video will be inaccessible. |
| 7563 |
TCP |
Recording Server Service |
XProtect Smart Client, Management Client |
Retrieving video and audio streams, PTZ commands. |
| 8966 |
TCP |
Recording Server Service |
Recording Server Manager tray icon, local connection only. |
Showing status and managing the service. |
| 9001 | HTTP | Recording Server Service | Management server |
Web service for internal communication between servers. If multiple Recording Server instances are in use, every instance needs its own port. Additional ports will be 9002, 9003, etc. |
| 11000 |
TCP |
Recording Server Service |
Failover recording servers |
Polling the state of recording servers. |
| 12975 |
TCP |
Recording Server Service |
Windows SNMP service |
Communication with the SNMP extension agent. Do not use the port for other purposes even if your system does not apply SNMP. In XProtect 2014 systems or older, the port number was 6474. In XProtect 2019 R2 systems and older, the port number was 7474. |
| 65101 |
UDP |
Recording Server service |
Local connection only |
Listening for event notifications from the drivers. |
In addition to the inbound connections to the Recording Server service listed above, the Recording Server service establishes outbound connections to:
- Cameras
- NVRs
- Remote interconnected sites (Milestone Interconnect ICP)
Failover Server service and Failover Recording Server service
When encryption is enabled, communication on TCP ports is protected using TLS where supported.The port number does not change.
|
Port number |
Protocol |
Process |
Connections from... |
Purpose |
|---|---|---|---|---|
| 5210 |
TCP |
Failover Recording Server Service |
Failover recording servers |
Merging of databases after a failover recording server had been running. Accessing archived camera video on the original recording server after the camera has been transferred to another recording server. If the port is not open, archived camera video will be inaccessible. |
| 7474 |
TCP |
Failover Recording Server Service |
Windows SNMP service |
Communication with the SNMP extension agent. Do not use the port for other purposes even if your system does not apply SNMP. |
| 7563 |
TCP |
Failover Recording Server Service |
XProtect Smart Client |
Retrieving video and audio streams, PTZ commands. |
| 8844 |
UDP |
Failover Recording Server Service |
Communication between failover recording server services. |
Communication between the servers. |
| 8966 |
TCP |
Failover Recording Server Service |
Failover Recording Server Manager tray icon, local connection only. |
Showing status and managing the service. |
| 8967 |
TCP |
Failover Server Service |
Failover Server Manager tray icon, local connection only. |
Showing status and managing the service. |
| 8990 |
HTTP |
Failover Server Service |
Management Server service |
Monitoring the status of the Failover Server service. |
| 9001 | HTTP | Failover Server Service | Management server | Web service for internal communication between servers. |
In addition to the inbound connections to the Failover Server / Failover Recording Server service listed above, the Failover Server / Failover Recording Server service establishes outbound connections to the regular recorders, cameras, and for Video Push.
Mobile Server service
When encryption is enabled, communication on TCP ports is protected using TLS where supported.The port number does not change.
|
Port number |
Protocol |
Process |
Connections from... |
Purpose |
|---|---|---|---|---|
| 8000 |
TCP |
Mobile Server service |
Mobile Server Manager tray icon, local connection only. |
SysTray application. |
| 8081 |
HTTP |
Mobile Server service |
Mobile clients, Web clients, and Management Client. |
Sending data streams; video and audio. |
| 8082 |
HTTPS |
Mobile Server service |
Mobile clients and Web clients. |
Sending data streams; video and audio. |
| 40001 - 40099 | HTTP | Mobile Server service | Recording server service |
Mobile Server Video Push. This port range is disabled by default. |
LPR Server service
When encryption is enabled, communication on TCP ports is protected using TLS where supported.The port number does not change.
|
Port number |
Protocol |
Process |
Connections from... |
Purpose |
|---|---|---|---|---|
| 22334 |
TCP |
LPR Server Service |
Event server |
Retrieving recognized license plates and server status. In order to connect, the Event server must have the LPR plug-in installed. |
| 22334 |
TCP |
LPR Server Service |
LPR Server Manager tray icon, local connection only. |
SysTray application |
Milestone Open Network Bridge service
When encryption is enabled, communication on TCP ports is protected using TLS where supported.The port number does not change.
|
Port number |
Protocol |
Process |
Connections from... |
Purpose |
|---|---|---|---|---|
| 580 |
TCP |
Milestone Open Network Bridge Service |
ONVIF clients |
Authentication and requests for video stream configuration. |
| 554 |
RTSP |
RTSP Service |
ONVIF clients |
Streaming of requested video to ONVIF clients. |
XProtect Incident Manager service
|
Port number |
Protocol |
Process |
Connections from... |
Purpose |
|---|---|---|---|---|
| 80 |
HTTP |
IIS |
XProtect Smart Client and the Management Client |
The purpose of port 80 and port 443 is the same. However, which port the VMS uses depends on whether you have used certificates to secure the communication.
|
| 443 |
HTTPS |
IIS |
Server components (outbound connections)
Server components also initiate outbound connections to other servers, services, and external resources.
Management Server service
|
Port number |
Protocol |
Connections to... |
Purpose |
|---|---|---|---|
| 443 |
HTTPS |
The License server that hosts the License Management service. Communication is via [[[Undefined variable flvar-url.URL_CompanyCom_LicActivationService]]] |
Activating licenses. |
Recording Server service
When encryption is enabled, communication on TCP ports is protected using TLS where supported.The port number does not change.
|
Port number |
Protocol |
Connections to... |
Purpose |
|---|---|---|---|
| 80 | HTTP |
Cameras, NVRs, encoders Interconnected sites |
Authentication, configuration, data streams, video, and audio. |
| 443 | HTTPS |
Cameras, NVRs, encoders |
Authentication, configuration, data streams, video, and audio. |
| 554 | RTSP | Cameras, NVRs, encoders | Data streams, video, and audio. |
| 7563 | TCP | Interconnected sites | Data streams and events. |
| 11000 | TCP | Failover recording servers | Polling the state of recording servers. |
| 40001 – 40099 | HTTP | Mobile Server service |
Mobile Server Video Push. This port range is disabled by default. |
Failover Server service and Failover Recording Server service
When encryption is enabled, communication on TCP ports is protected using TLS where supported.The port number does not change.
|
Port number |
Protocol |
Connections to... |
Purpose |
|---|---|---|---|
| 11000 | TCP | Failover recording servers | Polling the state of recording servers. |
Event Server service
|
Port number |
Protocol |
Connections to... |
Purpose |
|---|---|---|---|
| 80 | HTTP | API Gateway and the Management Server | Access the Configuration API from the API Gateway |
| 443 | HTTPS | API Gateway and the Management Server | Access the Configuration API from the API Gateway |
| 443 | HTTPS |
Milestone Customer Dashboard via |
Send status, events and error messages from the XProtect system to Milestone Customer Dashboard. |
API Gateway
|
Port number |
Protocol |
Connections to... |
Purpose |
|---|---|---|---|
| 443 |
HTTPS |
Management Server |
RESTful API |
| 22332 | WS/WSS HTTP/HTTPS* | Management Client | Event/State Subscription, Events REST API, Websockets Messaging API, and Alarms REST API. |
Client components (outbound connections)
Client components do not listen for incoming connections. They initiate outbound connections to server components based on system configuration.
XProtect Smart Client and XProtect Management Client
These clients initiate outbound connections only to the following ports directly. All additional ports required by enabled server components and functionality are communicated to the client by the management server at login. Ensure that the client computers can reach all ports listed in the Server components (outbound connections) section.
|
Port number |
Protocol |
Connections to... |
Purpose |
|---|---|---|---|
| 80 |
HTTP |
API Gateway and Management Server service |
Authentication and access to APIs when communication is not secured with certificates. |
| 443 |
HTTPS |
API Gateway and Management Server service |
Authentication of users when encryption is enabled and access to APIs in the API Gateway. |
XProtect Web Client, XProtect Mobile client
|
Port number |
Protocol |
Connections to... |
Purpose |
|---|---|---|---|
| 8081 |
HTTP |
XProtect Mobile server |
Retrieving video and audio streams. |
| 8082 |
HTTPS |
XProtect Mobile server |
Retrieving video and audio streams. |
API Gateway
|
Port number |
Protocol |
Connections to... |
Purpose |
|---|---|---|---|
| 80 |
HTTP |
Management Server |
RESTful API |
| 443 |
HTTPS |
Management Server |
RESTful API |
Cameras, encoders, and I/O devices (inbound connections)
When encryption is enabled, communication on TCP ports is protected using TLS where supported.The port number does not change.
|
Port number |
Protocol |
Connections from... |
Purpose |
|---|---|---|---|
| 80 |
TCP |
Recording servers and failover recording servers |
Authentication, configuration, and data streams; video and audio. |
| 443 |
HTTPS |
Recording servers and failover recording servers |
Authentication, configuration, and data streams; video and audio. |
| 554 |
RTSP |
Recording servers and failover recording servers |
Data streams; video and audio. |