Firewall Ports
Version Control
Version Date Prepared by Changes e@mail
V0.1 08/22/2k4 Vinay Tiwari - agnideewar@yahoo.com
V0.2-1 08/24/2k4 Dieter Watchguard Auth dsr@ascure.com
Sarrazyn Port
V0.2-2 08/25/2k4 Oliver Karow Adding Symantec Oliver@greyhat.de
Enterprise FW
Ports
V0.2-3 08/26/2k4 Dieter Added some dsr@ascure.com
Sarrazyn more Symantec
Enterprise FW
ports
SONICWALL
Service Port Listening Service Identified Available To Comments
TCP/UDP 23 TELNET private
TCP 67 BOOTPS private
UDP 69 TFTP private
TCP 80 HTTP private
TCP/UDP 137 NETBIOS Private
UDP 500 ISAKMP Private
Nokia
Service Port Listening Service Identified Available To Comments
TCP, 23 Telnet
TCP, 80 HTTP
TCP, 256 FWl-1 Management
TCP, 259 FWl-1 Management
TCP, 262 FWl-1 Management
TCP, 900 FWl-1 Management
TCP, 1149 FWl-1 Management
TCP, 1150 FWl-1 Management Management
Communication Purpose
TCP, 1151 FWl-1 Management
between Nokia Open
TCP, 1152 FWl-1 Management By default
Appliance and
TCP, 1153 FWl-1 Management Management server.
TCP, 1154 FWl-1 Management
TCP, 18183 FWl-1 Management
TCP, 18184 FWl-1 Management
UDP, 161 FWl-1 Management
UDP, 259 FWl-1 Management
UDP, 514 FWl-1 Management
Firewall Ports
Zywall
Service Port Listening Service Identified Available To Comments
TCP 21 FTP Private
TCP 23 Telnet Private
NetASQ
Service Port Listening Service Identified Available To Comments
NETASQ Firewall
TCP 1300 Private
Manager
NETASQ Firewall
TCP 1302 Private
Monitor
Watchguard SOHO
Service Port Listening Service Identified Available To Comments
TCP 21 FTP Private
TCP 53 DNS Private
UDP 53 DNS Private Ports Open by
UDP 67 bootps Private default
TCP 80 HTTP Private
TCP 1080 Socks Private
Lucent Access Point 300
Service Port Listening Service Identified Available To Comments
TCP 22 SSH Private & Public
TCP 23 Telnet Private & Public
TCP 80 HTTP Private & Public
UDP 123 NTP Private & Public
UDP 161 SNMP Private & Public
TCP 443 HTTPS Private & Public
UDP 500 ISAKMP Private & Public
UDP 514 SYSLOG Private & Public
UDP 520 RIP Private & Public
UDP 1701 L2TP Private & Public
UDP 8127 AP SLA Probe Private & Public
Firewall Ports
UDP 65534 Loop back Address Private & Public
Watchguard VClass
Service Port Listening Service Identified Available To Comments
TCP 22 SSH Private
TCP 23 Telnet Private
UDP 161 SNMP Private
TCP 443 SSL Private
UDP 500 IKE Private
Centralized Policy
UDP 1024 Private
Manager (CPM) Ports Open by
Heart Beat to default
UDP 1850 centralized Private
managers
Used by HA modules
to hot synch
TCP 6789 configuration Private
between two HA
units
Zywall
Service Port Listening Service Identified Available To Comments
SSL Web based
TCP 443 Private
administration Used for
SSL Web based administration
TCP 443 Public
administration
Cisco IOS Firewall
Service Port Listening Service Identified Available To Comments
TCP 23 Telnet Private
UDP 67 DHCP Private
Open by default
UDP 68 DHCP Private
TCP 80 HTTP Private
UDP 1985 HSRP Private Management
Cisco PIX Firewall
Service Port Listening Service Identified Available To Comments
Administration/Open
TCP 443 HTTPS Private
by default
ICMP/8 Echo request Private Open by default
Firewall Ports
BroadCom Firewall
Service Port Listening Service Identified Available To Comments
UDP 53 DNS Private Open by default
TCP 80 HTTP Private Administration/open
ICMP/8 Echo Request Private Open by default
ICMP/13 Timestamp Request Private Open by default
Fortigate Firewall
Service Port Listening Service Identified Available To Comments
SSL Web based
TCP 443 Private Administration/open
administration
Microsoft ISA Firewall
Service Port Listening Service Identified Available To Comments
RPC Endpoint
TCP/UDP 135 Private
Mapper
UDP 137 NetBios name Private
UDP 138 NetBios Datagram Private
TCP 139 NetBios Session Private
TCP/UDP 445 MS directory service Private
UDP 500 ISAKMP Private
TCP 1025 Windows internal Private Open by Default
TCP 1080 Socks Private
Firewall client
TCP/UDP 1745 Private
control session
TCP 8080 ISA Web proxy Private
ICMP/8 Echo request Private
TCP/UDP range 3000
ISA NAT port pool Private
to 3700
Netscreen Firewall
Service Port Listening Service Identified Available To Comments
TCP 23 Telnet Private
TCP 80 HTTP Private Administration/open
TCP 443 HTTPS Private
ICMP/8 Echo Request Private Open by default
Firewall Ports
Nortel ASF
Service Port Listening Service Identified Available To Comments
TCP 18264 FW1_ICS_Service Private Management/open
Novell Border Manager
Service Port Listening Service Identified Available To Comments
TCP, 80 HTTP Private
Administration/open
TCP, 81 Web based Mgmt Private
UDP 123 NTP Private
UDP 161 SNMP Private
TCP 389 LDAP Private
Storage Mgmt
TCP 413 Private
Service protocol
TCP 427 Storage Location Private
UDP 427 Storage Location Private
Open by default
Web based
TCP 443 Private
administration
UDP 520 RIP Private
TCP 524 NCP Private
UDP 524 NCP Private
TCP 636 LDAP Over SSL Private
TCP 2000 CS Audit Proxy Private
Web based
TCP 2200 Private
administration
Administration/open
Web based
TCP 2211 Private
administration
TCP 3351 B treive Private
TCP 6000 X windows Private Open by default
TCP 6901 Jet Stream Private
Web based
TCP 8008 Private
administration
Administration/open
Web based
TCP 8009 Private
administration
Novell Licensing
TCP 21571 Private
Service
Storage Open by default
TCP 40193 Private
management Req.
ICMP/8 Echo Request Private
Netgear Prosafe
Service Port Listening Service Identified Available To Comments
TCP 80 HTTP Private Administration/open
Firewall Ports
TCP 443 HTTPS Private
Watchguard Firebox
Service Port Listening Service Identified Available To Comments
ICMP/8 Echo Request Private
TCP 21 FTP proxy Private
TCP 113 Auth Private
TCP 3053 Management Control Private
Management Control
TCP 4105 Private Management/Open
connection
by default
TCP 4110 DVCP VPN manager Private
TCP 4111 High availability Private
TCP 9001 Management Control Private
TCP 4100 Authentication Private Needs to configure
Checkpoint Firewall
Service Port Listening Service Identified Available To Comments
256 /tcp FW1 Private
257 /tcp FW1_log Private
258 /tcp FW1_mgmt Private
259 /tcp FW1_clntauth
Private
FW1_clntauth_telnet
259 /udp RDP Private
260 /udp FW1_snmp Private
261 /tcp FW1_snauth Private
264 /tcp FW1_topo Private
265 /tcp FW1_key Private
900 /tcp FW1_clntauth
Private
FW1_clntauth_http Management
981 /tcp - not predefined - Private
2746 /udp VPN1_IPSEC_encapsulation Private
5004 /udp MetaIP-UAT Private
8116 /udp - not predefined - Private
9281 /udp SWTP_Gateway Private
9282 /udp SWTP_SMS Private
18182 /tcp FW1_ufp Private
18183 /tcp FW1_sam Private
18184 /tcp FW1_lea Private
18185 /tcp FW1_omi Private
18186 /tcp FW1_omi-sic Private
Firewall Ports
18187 /tcp FW1_ela Private
18190 /tcp CPMI Private
18191 /tcp CPD Private
Checkpoint Firewall
Service Port Listening Service Identified Available To Comments
18192 /tcp CPD_amon Private
18193 /tcp FW1_amon Private
18202 /tcp CP_rtm Private
18205 /tcp CP_reporting Private
18207 /tcp FW1_pslogon Private
18208 /tcp FW1_CPRID Private
18209 /tcp - not predefined - Private
18210 /tcp FW1_ica_pull Private
18211 /tcp FW1_ica_push Private
18212 /udp FW1_load_agent Private Management
18221 /tcp CP_redundant Private
18231 /tcp FW1_pslogon_NG Private
18232 /tcp FW1_sds_logon Private
18233 /udp FW1_scv_keep_alive Private
Private
18234 /udp tunnel_test
18241 /udp E2ECP Private
18262 /tcp CP_Exnet_PK Private
18263 /tcp CP_Exnet_resolve Private
18264 /tcp FW1_ica_services Management/
Private
Open by default/
18265/tcp FW1_ica_mgmt_tools Private
19190 /tcp FW1_netso Private
19191 /tcp FW1_uaa Private
Management
19194 /udp CP_SecureAgent-udp Private
19195 /udp CP_SecureAgent-udp Private
65524 /tcp FW1_sds_logon_NG Private
Symantec Enterprise Firewall
Service Port Listening Service Identified Available To Comments
TCP 21 FTP Private & Public
TCP 23 TELNET Private & Public
TCP 25 SMTP Private & Public
TCP 80 HTTP Private & Public
TCP 416 Firewall Mgmt Port Private & Public
TCP 417 Firewall Mgmt Port Private & Public
TCP 418 FW Remote Mgmt Private & Public
Firewall Ports
Port
UDP 500 ISAKMP Private & Public
TCP 888 OOB-Daemon
Web based
TCP 2456
Management Port
TCP 1344 AV scan engine Bind to local host