CSN Number: 04082001 Date: Aug 20, 2004
Submitted by: Gordon Daugherty
   
 

Ports Used by the SecureConnect Encryption Client

 
Emblaze-VCON Product: SecureConnect
Non-Emblaze-VCON Product:  
 
Problem Description:
Which ports are used by the SecureConnect Encryption Client, and what support is needed in the firewall?
 

Resolution:
The Encryption Client uses the following ports:

TCP 443 - HTTPS protocol used for the command channel. This port will likely be opened already in the firewall for outbound-initiated traffic, since it facilitates HTTPS (SSL) based browsing capabilities.

UDP 2061 - IANA registered NetMount port. If the firewall does not allow outbound-initiated connections on this port, then the client will retry using TCP port 80. If you discover that this is not happening automatically, then open the Network Assistant application and go to the Tools/Options menu. Under the Advanced Settings button, you will see settings for the Override Port. You can set to TCP port 80.

If TCP port 80 is used instead of the default UDP port 2061, then you should expect performance to be ~5 times slower. Therefore, UDP port 2061 is strongly preferred.

If even the alternate TCP port 80 does not allow the Encryption Client to operate, then it is possible that the firewall (or networking environment) has some kind of packet inspection mechanism that blocks non-HTTP traffic over port 80. Consult with your network administrator.

The SecureConnect Encryption Client does not require that the firewall have opened ports for inbound-initiated connections.

 

Related Notes or Documents:
none

 
Back