Port Access Requirements
On-Premises
Open the following ports between your N-central server, probes, agents, and managed devices so that N-central services work correctly.
For the external domains and URLs these ports connect to, see Firewall Requirements.
| Port Number | Port Location | Description | |||||
|---|---|---|---|---|---|---|---|
| N-able N-central Server | Managed Device | ||||||
| Inbound | Outbound | Inbound | Outbound | ||||
| 20 |
|
Ö |
|
|
Used for FTP connections, particularly when configured for backups. |
||
|
21 |
|
Ö |
|
|
Used for FTP connections, particularly when configured for backups. | ||
|
22* |
Ö |
|
|
Ö |
SSH - used for remote control sessions. The firewall must be configured to allow access from the Internet to this port on the N-able N-central server. (*OPTIONAL) |
||
|
25 |
|
Ö |
|
|
SMTP - used for sending mail. |
||
|
53 |
|
Ö |
|
|
Used for DNS. |
||
|
80 |
Ö |
Ö |
|
Ö |
HTTP - used for communication between the N-able N-central and agents or probes. N-able N-central recommends that you block all access from the internet to this port on the N-able N-central server, unless it is absolutely required. This port may be closed in a future release. This port must also be open for outbound traffic if the N-able N-central server is monitoring HTTP services on remote managed devices. |
||
|
123 |
|
Ö |
|
|
Used by the NTP Date service which keeps the server clock synchronized. Normally using UDP (although some servers can use TCP). |
||
|
135 |
|
|
Ö |
|
Used by Agents and Probes for WMI queries to monitor various services. Inbound from the Windows Probe to the Windows Agent. |
||
|
139 |
|
|
Ö |
|
Used by Agents and Probes for WMI queries to monitor various services. Inbound from the Windows Probe to the Windows Agent. |
||
|
443 |
Ö |
Ö |
|
Ö |
HTTPS - used for communication between N-able N-central and Agents or Probes (including MSP Connect and MSP Anywhere). Your firewall must be configured to allow access from the Internet to this port on the N-able N-central server. This port must be open for outbound traffic if the N-able N-central server is monitoring HTTPS services on remote managed devices. Backup Manager on endpoint devices uses Port 443 TCP outbound. It is almost always open on workstations but may be closed on servers. Used by Agents and Probes as a failover for XMPP traffic when they cannot reach N-centralon port 5280. To activate EDR the N-able N-central server needs outbound HTTPS access to port 443 and the following domains:
Pendo allows us to provide in-UI messaging and guides when there are important changes, new features onboarding, or other critical messages that we need to tell you about. You can gain access to these important messages, and help us make important design decisions from usage data, by allowing outbound HTTPS/443 access from your N-central server to the following URLs: Only windows agents will send data to the app.pendo.io URL.
|
||
|
445 |
|
|
Ö |
|
Used by Agents and Probes for WMI queries to monitor various services. |
||
|
1234 |
Ö |
Ö |
Used by MSP Connect in UDP mode. |
||||
|
1235 |
Ö |
Ö |
|||||
|
1433 |
|
* |
* |
* |
Outbound on the N-able N-central server, port 1433 is used by Report Manager for data export. On managed devices, it is also used by Agents (inbound) and Probes (out- bound) to monitor Backup Exec jobs. Inbound from the local LAN and not the Internet. |
||
|
|||||||
|
5000 |
Ö |
Backup Manager will use local port 5000. If this port is unavailable, Backup Manager will detect a free port automatically (starting from 5001, 5002 and up). |
|||||
|
5280 |
Ö | Ö |
Used by Agents and Probes for XMPP traffic. Outbound access to port 5280 for Managed Devices is recommended but not required. |
||||
|
8014 |
|
|
Ö |
|
Backup Manager requires access to port 8014. This value cannot be modified. Inbound from the local LAN and not the Internet. |
||
| 8088 | Ö | HTTPS – Used for communications to the N-able event communication system to enable communications between N-able cloud and N-central server. | |||||
|
8443 |
Ö |
Ö |
|
Ö |
The default port for the N-central UI. TCP port 8443 is used for TLS (HTTPS) connections to the N-central Web UI. Your firewall may be configured to allow access from the internet to this port on the N-able N-central server, if you require Web UI access outside of the network N-central is deployed to. You can change this port number in the N-central Administrator menu, under "Network Setup". |
||
| 8800 | Ö |
The Feature Flag System in N-able N-central needs to talk to mtls.api.featureflags.prd.sharedsvcs.system-monitor.com. Used by N-able – generally during Early Access Preview and Release Candidate testing – to enable and disable features within N-able N-central.
|
|||||
|
10000 |
Ö |
|
|
|
Deprecated. N-central no longer uses this port in versions after 2025.4. This requirement applies only to N-central 2025.4 and earlier. HTTPS - used for access to the N-able N-central Administration Console (NAC). The firewall must be configured to allow access from the Internet to this port on the N-able N-central server. N-able recommends excluding all other inbound traffic to port 10000 except from N-able Ports for Support section below. |
||
|
10004 |
|
|
Ö |
Ö |
N-able N-central Agents must be able to communicate with a Probe on the network over port 10004 in order for Probe caching of software updates to function properly. Inbound from the local LAN and not the Internet. |
||
|
15000 |
|
|
Ö |
Ö |
For downloading software patches, port 15000 must be accessible for inbound traffic on the Probe device while it must be accessible for outbound traffic on devices with Agents. Inbound from the local LAN and not the Internet. |
||
See Also
Probe to N-N-central
| Port / Protocol | Direction | Purpose |
|---|---|---|
| TCP 443 | Outbound from probe | Probe-to-server communication. |
Agent to N-N-central
| Port / Protocol | Direction | Purpose |
|---|---|---|
| TCP 443 | Outbound from agent | Agent check-in and command channel. |
| TCP 8088 | Outbound from Modern Agent | Modern Agent feature endpoints. See Firewall Requirements for domains. |
| Port / Protocol | Direction | Purpose |
|---|---|---|
| TCP 443 (HTTPS) | Outbound from agent | Core communications. Agent check-in and command channel. |
| TCP 8088 (Ecoverse) | Outbound from Modern Agent | Required for Modern Agent features. See Firewall Requirements for domains. |
| TCP 5228 / 5280 (XMPP) | Outbound Conditional | Real-time signaling (XMPP) |
Feature-specific ports
Configure the following ports when you use Remote Desktop for remote connections.
Operator machine
| Port / Protocol | Direction | Purpose |
|---|---|---|
| TCP 443 | Outbound to N-central | Required. |
| TCP 22 | Outbound to N-central | Recommended for best remote control experience. |
Target Machine and Probe
| Port / Protocol | Direction | Purpose |
|---|---|---|
| TCP 443 | Outbound to N-central | Required. |
| TCP 22 | Outbound to N-central | Recommended for best remote control experience. |
| TCP 3389 (or custom port) |
Probe to target on local network | Required when a probe is used as the connecting device. The probe must be able to reach the Target Machine on port 3389 (or custom port if specified) on the local network (and N-central). |
Port 443 TCP outbound. It is almost always open on workstations but may be closed on servers.
Local port 5000 . If this port is unavailable, the Backup Manager detects a free port automatically (starting from 5001, 5002 and up).
In most cases, no firewall configuration is required.
MDM uses the standard outbound ports listed below. For MDM domains, see Firewall Requirements.
| Port Number | Port Location | Description | |||
|---|---|---|---|---|---|
| N-able N-central Server | Target Network Server | ||||
| Inbound | Outbound | Inbound | Outbound | ||
|
80 |
|
Ö |
Ö |
|
|
|
443 |
|
Ö |
Ö |
|
|
|
2195 |
Ö |
Access to ports 2195 and 2196 must be granted to gateway.push-apple.com.akadns.net. |
|||
|
2196 |
Ö |
||||
|
5222 |
Ö |
||||
|
5223 |
Ö |
||||
|
5228 |
Ö |
TCP and UDP mode. |
|||
Ports used for AV Defender and other services include:
| Port | Source/Destination | Description |
|---|---|---|
| 80 |
submit.bitdefender.com |
Port used for submitting endpoint dumps in case of crashes. |
| https://custom-update-server.logicnow.us | Bitdefender update server. | |
| upgrade.bitdefender.com | Bitdefender upgrade server. | |
| lv2.bitdefender.com | License validation. | |
| 53 | *.v1.bdnsrt.org | DNS requests for signature update checks. |
| 7074 | Update Server | Downloading updates from local Update Server. An update server cannot acquire updates from another local Update Server; it is not possible to cascade them. |
| 443 | avc-fu.nimbus.bitdefender.net | Antimalware behavior scanning with Bitdefender Cloud servers. |
| nimbus.bitdefender.net/elam/blob | Early Launch Anti-Malware (ELAM) cloud server. | |
| elam-fu.nimbus.bitdefender.net/submission | Submission to Bitdefender cloud servers of unrecognized applications by Early Launch Anti-Malware (ELAM) module. | |
| nimbus.bitdefender.net | Antimalware, antiphishing and content control scanning with Bitdefender Cloud servers. |
The Probe automatically creates firewall rules for these ports.
To ensure signature updates and minor updates to AV Defender can occur, ensure that DNS and outbound TCP port 80 access to http://upgrade.bitdefender.com are available through the firewall.
You can also configure N-able N-central to communicate with Report Manager over port 80 or 443.
If you choose 443, you must setup the proper SSL certificate.
Configure the external and internal addresses by opening the Report Manager administration console and clicking System setup and logs > Server IP Configuration and setting the External and Internal IP address.
The internal address or FQDN must be accessible from N-able N-central over port 1433 and either port 80 or 443.
Port 443 TCP outbound. It is almost always open on workstations but may be closed on servers.
Local port 5000. If this port is unavailable, the Backup Manager detects a free port automatically (starting from 5001, 5002 and up).
In most cases, no firewall configuration is required.
