Firewall Configuration: Open Port Numbers on Firewall

Prev Next

OneSpan Authentication Server Appliance uses several different ports to communicate (see Table: Incoming ports used by OneSpan Authentication Server Appliance and Table: Outgoing ports used by OneSpan Authentication Server). If these are blocked by a firewall, some features will not work correctly.

We recommend using a software firewall on OneSpan Authentication Server and segmenting the OneSpan Authentication Server network with a hardware firewall.

Incoming ports

Table:  Incoming ports used by OneSpan Authentication Server Appliance
Port descriptionDefaultProtocolConfigurationSource
SOAP8888TCP

Not configurable

  • SOAP client
  • Digipass Authentication for Windows Logon 2.x
  • Digipass Authentication Module products
  • Administration Web Interface
RADIUS authentication1812UDP

Configuration Tool:
Authentication Server > RADIUS Communicator > Authentication Port

  • RADIUS client
  • RADIUS back-end server
RADIUS accounting1813UDP

Configuration Tool:
Authentication Server > RADIUS Communicator > Accounting Port

  • RADIUS client
  • RADIUS back-end server
SEAL without SSL20003TCP

Not configurable

  • Tcl Command-Line Administration tool
  • Replication from other OneSpan Authentication Server instances
SEAL with SSL20004TCP

Not configurable


Net-SNMP agent161UDP

Not configurable

OneSpan Authentication Server

Net-SNMP trap handler162UDP

Not configurable

OneSpan Authentication Server

Audit replication5444TCPNot configurableOneSpan Authentication Server Appliance in replication setup
Configuration replication20014TCPNot configurableOneSpan Authentication Server Appliance in replication setup
Replication Wizard20101TCPNot configurableOneSpan Authentication Server Appliance Replication Wizard

Outgoing ports

Table:  Outgoing ports used by OneSpan Authentication Server
Port descriptionDefaultProtocolConfigurationDestination
RADIUS Authentication1812UDPAdministration Web Interface: Back-end server records > Authentication PortRADIUS back-end server
RADIUS Accounting1813UDPAdministration Web Interface: Back-end server records > Accounting PortRADIUS back-end server

LDAP

389TCPAdministration Web Interface: Back-end server records > PortIBM Security Directory Server, or Active Directory back-end servers
LDAPS636TCPAdministration Web Interface: Back-end server records > PortIBM Security Directory Server, or Active Directory back-end servers
HTTPS443TCPNot configurableOneSpan Customer Portal
(https://cp.onespan.com/)
Audit replication5444TCPNot configurableOneSpan Authentication Server Appliance in replication setup
Configuration replication20014TCPNot configurableOneSpan Authentication Server Appliance in replication setup
Replication Wizard20101TCPNot configurableOneSpan Authentication Server Appliance Replication Wizard
SNMP trap162UDPNot configurable

Alerts sent by OneSpan Authentication Server Appliance SNMP trap server