Port Guide

Why ports need to be opened and how to check if they are?

A port is a virtual point through which programs running on different computers exchange data. Ports need to be open to allow this data exchange. Microsoft's PortQryUI displays the status of ports on a computer, and can be installed and run on the machine in which ADAudit Plus is installed.

PortQryUI download link:

https://www.microsoft.com/en-in/download/details.aspx?id=24009

Products Ports

The table below lists the default ports used by ADAudit Plus. These ports can be changed during or after installation.

Note: To change port: Open the ADAudit Plus console → Admin tab, which can be found in the top panel → Connection tab, which can be found in the left panel → Change port.


 

PortProtocolPurpose
8081HTTPProduct web server
8444HTTPSProduct web server
33307TCPDatabase port
29118TCPDataEngine port

System Ports

The table below lists the ports that should be opened, on the destination computers. These ports can be opened on Windows/third-party firewalls.

PortProtocolDirectionServicePurpose
135TCPInboundRPC

For Windows log collection

Source: ADAudit Plus server

Destination: Monitored computers

137TCP and UDPInboundNetBIOS name resolution RPC/named pipes (NP)

For Windows log collection

Source: ADAudit Plus server

Destination: Monitored computers

138UDPInboundNetBIOS datagram

For Windows log collection

Source: ADAudit Plus server

Destination: Monitored computers

139TCPInboundNetBIOS session RPC/NP

For Windows log collection

Source: ADAudit Plus server

Destination: Monitored computers

445TCP and UDPInboundSMB RPC/NP

For Windows log collection

Source: ADAudit Plus server

Destination: Monitored computers

389TCP and UDPInboundLDAP

For syncing AD objects with product

Source: ADAudit Plus server

Destination: Domain Controllers

636TCPInboundLDAP over SSL

For syncing AD objects with product

Source: ADAudit Plus server

Destination: Domain Controllers

3268TCPInboundGlobal catalog

For syncing AD objects with product

Source: ADAudit Plus server

Destination: Domain Controllers

3269TCPInboundGlobal catalog over SSL

For syncing AD objects with product

Source: ADAudit Plus server

Destination: Domain Controllers

88TCPInboundKerberos

For authentication when accessing a domain resource

Source: ADAudit Plus server

Destination: Domain Controllers

25TCPInboundSMTP

To send emails

Source: ADAudit Plus server

Destination: SMTP servers

465TCPInboundSSL

To send emails

Source: ADAudit Plus server

Destination: SMTP servers

587TCPInboundTLS

To send emails

Source: ADAudit Plus server

Destination: SMTP servers

49152- 65535*TCPInboundRPC randomly allocated high TCP ports

For Windows log collection

Source: ADAudit Plus server

Destination: Monitored computers

*Note: If you are using Windows Firewall you can open dynamic ports, 49152-65535, on the monitored computers by enabling the inbound rules listed below.

  • Remote Event Log Management (NP-In)
  • Remote Event Log Management (RPC)
  • Remote Event Log Management (RPC-EPMAP)


 

To enable the above rules: Open Windows Firewall → Advanced settings → Inbound Rules → Right click on respective rule → Enable Rule.

In case you are deploying agents, please refer to the Agent guide and open the corresponding ports.

我们的客户