Configuration Manager Firewall Ports Requirement

The below listed Firewall ports are required to allow in Microsoft Endpoint Manager infrastructure during the implementation in order to get Site communication, client communication, Distribution Point and WSUS/SUP communication . I gathered this information from TechNet articles

Reference Link https://docs.microsoft.com/en-us/mem/configmgr/core/plan-design/hierarchy/ports?redirectedfrom=MSDN

SourceDestinationUDPTCPDescriptionDirection
ClientManagement Point 10123/80/443Client Notification/http/httpsUni
ClientSoftware Update Point 80/8530/443/8531http/httpsUni
ClientState Migration Point 80/443/445http/https/SMBUni
ClientNDES 80/443http/httpsUni
ClientDistribution Point 80/443http/httpsUni
ClientDP with Multi Cast63000-64000445Multi Cast/SMBUni
ClientDP with PXE67/68/69/4011 DHCP/TFTP/BINLUni
ClientFallback Status Point 80httpUni
ClientApp Catalog Website Point 80/443http/httpsUni
ClientState Migration Point 80/443/445http/https/SMBUni
Distribution PointManagement Point 80/443http/httpsUni
Site ServerSQL Server 1433SQL Over TCPUni
Reporting pointSQL Server 1433SQL Over TCPUni
Asset Intelligence Sync PointSQL Server 1433SQL Over TCPUni
App Catalog Web Serv PointSQL Server 1433SQL Over TCPUni
Management PointSQL Server 1433SQL Over TCPUni
SMS ProviderSQL Server 1433SQL Over TCPUni
State Migration PointSQL Server 1433SQL Over TCPUni
Management PointSite Server 135/RPC Dyn/445RPC EPM/RPC Dynamic/SMBBi
Software Update PointUpstream WSUS Server 80-8530/443-8531http/httpsUni
SQL ServerSQL Server 4022/1433SQL Over TCP/SQL SSBUni
Site ServerSoftware Update Point 445/80/8530/443/8531http/https/SMBBi
Site ServerSite Server 445SMBBi
Site ServerApp Catalog Web Serv point135445/135/RPC DynRPC EPM/RPC Dynamic/SMBBi
Site ServerApp Catalog Website Point135445/135/RPC DynRPC EPM/RPC Dynamic/SMBBi
Site ServerAsset Intelligence Sync Point135445/135/RPC DynRPC EPM/RPC Dynamic/SMBBi
Site ServerDistribution Point135445/135/RPC DynRPC EPM/RPC Dynamic/SMBUni
Site ServerCertificate Registration Point135445/135/RPC DynRPC EPM/RPC Dynamic/SMBBi
Site ServerEnd Point Protection135445/135/RPC DynRPC EPM/RPC Dynamic/SMBBi
Site ServerEnrollment Point135445/135/RPC DynRPC EPM/RPC Dynamic/SMBBi
Site ServerEnrollment Proxy Point135445/135/RPC DynRPC EPM/RPC Dynamic/SMBBi
Site ServerFallback Status Point135445/135/RPC DynRPC EPM/RPC Dynamic/SMBBi
Site ServerReporting Service Point135445/135/RPC DynRPC EPM/RPC Dynamic/SMBBi
Site ServerSQL Server135445/135/RPC DynRPC EPM/RPC Dynamic/SMBUni
Site ServerSMS Provider135445/135/RPC DynRPC EPM/RPC Dynamic/SMBUni
Site ServerState Migration Point135445/135RPC EPM/SMBBi
Site ServerSite System135135/RPC DynRPC EPM/RPC DynamicUni

Thank You!

Published by Tamilkovan

My name is Tamil Kovan and I work as a Technical Manager at PCCW Solutions. This is my blog where I will share tips and stuff for my own on System Center related topics.

Leave a Reply

Fill in your details below or click an icon to log in:

WordPress.com Logo

You are commenting using your WordPress.com account. Log Out /  Change )

Facebook photo

You are commenting using your Facebook account. Log Out /  Change )

Connecting to %s

%d bloggers like this: