Neverfail Continuous Engine — Ports Required for Communications

Neverfail Continuous Engine — Ports Required for Communications

Neverfail Continuous Engine — Ports Required for Communications

Summary

Neverfail Continuous Engine requires specific TCP ports to be open between Primary and Secondary servers and its Advanced Management Client console and the EMS web console. Connections to vCenter and to the Neverfail Licensing Server are optional and apply only to virtual deployments and online licensing.


Solid blue = required. Dashed orange = deployment only. Thick green = the replication Channel.

Ports

Port Used for Required
TCP 135–139 RPC endpoint mapper and NetBIOS Deployment only
TCP 445 SMB, used to push the Engine installation Deployment only
TCP 443 HTTPS to vCenter Optional — virtual deployments only
TCP 9727 / 9728 Neverfail WebServices — EMS portal and management API (HTTPS, sha256RSA) Always
TCP 9729 EMS to the Neverfail Licensing Server Optional — online licensing only
TCP 52267 Client connection to the Active server (encrypted) Always
TCP 57348 Channel — replication between Primary and Secondary Always
TCP 49152–65535 Ephemeral ports for return traffic Always

Direction

From To Open TCP
EMS Protected virtual machine 445, 135–139, 9727, 9728, ephemeral
Protected virtual machine EMS 445, 135–139, 9727, 9728, ephemeral
Primary Secondary / Tertiary 57348, 52267, ephemeral
Secondary / Tertiary Primary 57348, 52267, ephemeral
EMS Neverfail Licensing Server 443, 9727, 9729 optional
EMS vCenter Server 443, 9727, 9728, ephemeral optional
vCenter Server EMS 443, 9727, 9728, ephemeral optional
vCenter Server Protected virtual machine 443, ephemeral optional
Protected virtual machine vCenter Server 443, ephemeral optional

Notes

  • vCenter connectivity is only required for virtual deployments. On physical servers, or where Engine does not manage the virtual infrastructure, TCP 443 to vCenter is not needed.
  • Licensing Server connectivity is only required for online license activation. If licenses are activated offline, TCP 9729 outbound from EMS is not needed.
  • TCP 445 and 135–139 are only needed while Engine is being deployed. SMB v1 must be enabled during deployment and can be disabled once Engine is installed.
  • Where vCenter is used, TCP 443 must be open in both directions on all nodes (Primary, Secondary, EMS) and vCenter.
  • Ephemeral ports are temporary ports Windows assigns for the duration of a connection; the default range on Windows Server 2008 and later is 49152–65535. Stateful firewalls allow this return traffic automatically.
  • 57348 and 52267 are defaults and are configurable in the Configure Server Wizard — confirm the values used on your cluster.
  • Channel traffic (57348) is not encrypted, but the replication format is proprietary. Encryption is not applied because of the CPU cost on Active servers; over a WAN, carry the Channel over a VPN or a dedicated private circuit.
  • EMS installs with a self-signed certificate, which can be replaced with one issued by your own Certificate Authority.

    • Related Articles

    • Engine & EMS used ports details

      See Neverfail Engine Management Server Ports Required for Communications.
    • Neverfail Continuity Engine Recloning limitations when static routes are configured

      Summary This Knowledgebase article provides details about the supported use cases of Recloning feature when persistent static routes are configured on the Neverfail Continuity Engine cluster. It also offers details about the known limitations and ...
    • Continuity Engine Troubleshooting - Channel Drops

      This article discusses unexpected channel drops. Under normal operations, Neverfail Continuity Engine maintains continuous communications between servers using the Neverfail Channel. When communications between servers fail, the condition is referred ...
    • Reference: Continuity Engine Product Architecture

      Summary This Quick Reference provides an overview of the key concepts and components of Neverfail Continuity Engine product architecture: More Information Key Concepts and Components Component / Concept Description Active-Passive Server Pair ...
    • Continuity Engine Product Architecture

      Learning objectives At the completion of this session, you should be able to: Identify major components of the Neverfail Continuity Engine product architecture. Describe major component configuration. Identify advantages of the Neverfail Continuity ...