12
Requirement
Direction Protocol
Local
port
Application
Remote port
Remote
address
Note
Enable updates
for client
computers with
ESS
Out
TCP
ekrn.exe
80, 2221
port 80 for
Internet
updates, port
2221 if updating
from local
update server
(e.g., from ERA)
Enable
communication
of ESS with
ERA Server
(client-side rule)
Out
TCP
ekrn.exe
2222, 2224
port 2224 can be
used for remote
installation /
uninstallation.
Enable
communication
of ERA Console
with ERA Server
Out
TCP
console.exe
2223
console side
rule, if ESS is
present on the
same PC.
Send and
receive email
Out
TCP
Process of
your email
client
25 (SMTP), 110
(POP3), 143
(IMAP)
IP
addresses
of your
servers
remote address
can be filled in
if you want very
strict protection
Web browsing
Out
TCP
Web
browser
process
80 (HTTP),
443 (HTTPS),
or proxy
server port
FTP client -
server
Out
TCP
FTP client
21 (FTP),
1024 to 65535
passive
FTP mode
(recommended)
FTP client -
server (active)
Out
TCP
FTP client
21 (FTP)
Alternative to
the previous
rule
In
TCP &
UDP
FTP client
20 (FTP-data)
IP address
of FTP
server
the IP address
of the FTP
server must be
specified!
Remote
desktop access
to other PC
Out
TCP
mstsc.exe
3389
browse the
process
Microsoft Live
Messenger
Out
TCP
msnmsgr.
exe
1863
browse the
process
Local Apache
Web Server –
visible from the
Internet
In
TCP
80
apache.exe
in Remote
address you
can specify
IP addresses
from which the
web should be
accessible (or
specify them in
Trusted zone)