Ports used by the system
The VMS consists of server and client components that communicate with each other over the network. Each component has a defined role and uses specific ports to provide or consume services.
Server components expose services that other components connect to, while client components initiate outbound connections to retrieve data, send requests, or receive events.
A single computer can host multiple components. To determine which ports must be opened on a specific machine, you must consider all components installed on that machine and how they communicate with other parts of the system.
Some connections use only local communication on the same computer. These ports do not require firewall rules for external traffic but are listed for completeness.
For CAPSS environments, Milestone recommends using HTTPS/TLS with certificates for all supported components and devices.
Cameras, encoders, and I/O devices (inbound connections)
Note
When encryption is enabled, communication on TCP ports is protected using TLS where supported.The port number does not change.
Port number | Protocol | Connections from... | Purpose |
|---|---|---|---|
80 | TCP | Recording servers and failover recording servers | Authentication, configuration, and data streams; video and audio. |
443 | HTTPS | Recording servers and failover recording servers | Authentication, configuration, and data streams; video and audio. |
554 | RTSP | Recording servers and failover recording servers | Data streams; video and audio. |
Client components (outbound connections)
Client components do not listen for incoming connections. They initiate outbound connections to server components based on system configuration.
XProtect Smart Client and XProtect Management Client
These clients initiate outbound connections only to the following ports directly. All additional ports required by enabled server components and functionality are communicated to the client by the management server at login. Ensure that the client computers can reach all ports listed in the Server components (outbound connections) section.
Port number | Protocol | Connections to... | Purpose |
|---|---|---|---|
80 | HTTP | API Gateway and Management Server service | Authentication and access to APIs when communication is not secured with certificates. |
443 | HTTPS | API Gateway and Management Server service | Authentication of users when encryption is enabled and access to APIs in the API Gateway. |
XProtect Web Client, XProtect Mobile client
Port number | Protocol | Connections to... | Purpose |
|---|---|---|---|
8081 | HTTP | XProtect Mobile server | Retrieving video and audio streams. |
8082 | HTTPS | XProtect Mobile server | Retrieving video and audio streams. |
API Gateway
Port number | Protocol | Connections to... | Purpose |
|---|---|---|---|
80 | HTTP | Management Server | RESTful API |
443 | HTTPS | Management Server | RESTful API |
Server components (inbound connections)
Server components provide services that other components, clients, or external systems connect to. The tables below list the ports these server components listen on, which must be available for inbound connections on the computer where the service is installed.
When certificates are installed and the system is configured in secure mode, ports listed with the HTTP protocol will automatically switch to using HTTPS.
The Management Server service is an exception: it permanently exposes both port 80 (HTTP) and port 443 (HTTPS) for different purposes regardless of security mode.
For ports listed as TCP, see the note on TLS encryption below.
XProtect Incident Manager service