You are on page 1of 3

Doc Type Tech Notes

Doc Id TN10402

Last Modified Date 02/19/2020

Ports required for System Platform 2017 Update 3


SUMMARY

This Tech Note describes the ports required for production environments utilizing hardware firewall-separated networks.

Application Version
System Platform 2017 Update 3

Note: This Tech Note is intended for use by a Network Administrator, or by an equivalent-level technical administrator. Do not attempt to configure
ports without thorough knowledge of your particular systems and networks.

SITUATION

In this example, a hardware firewall separates the Office Network from the Supervisory Network (Figure 1 below):

The Office Network includes the GR-Node, IDE and the Historian.
The Supervisory Network includes application object server and clients.

For communication between both networks, various ports must be open in the hardware firewall.

Figure 1: Office- and Supervisory Network topology

Note: This is just one example of an Office/Supervisory network topology.

ACTION

Terms of Use| Privacy Policy


© 2020 AVEVA Group plc and its subsidiaries.All rights reserved.
The following ports are required for cross-network communication between the Office and Supervisory networks (as outlined in the example
above). The table provides complete details.

Ports required for System Platform

Port Protocol SubSystem Used For Configurable


53 TCP/UPD DNS
80 TCP Licensing License Manager web application
88 TCP Kerboros
135- DCOM,
TCP/UPD Bootstrap
139 NetBios
443 TCP Security System Certificate Manager X
DCOM,
Bootstrap, Content distribution at
445 TCP/UPD NetBios,
deployment
SMB
808 TCP ASB Service bus primary port
1041 TCP Logging Logging (aaLogger)
1087 TCP Logging Logger (Alg.exe)
SQL Server database engine, If changed,
1433 TCP SQL Server restart the aaGR.exe service to apply X
changes
1434 UPD SQL Server SQL Browser UPD 1434, Send/Receive
3575 TCP WSP Event Service X
3586 TCP WSP EventHistorian Service X
5026 TCP NMX Real-time data subscriptions X
5413 TCP WSP Suitelink
6000- Bi-directional communication between al
TCP WSP
6050 ArchestrA-enabled nodes
8090 TCP WSP Galaxy
9876 TCP aaSystemAuthenticationService
27000-
TCP License ArchestrA License Server TCP-[PORT]
27009
30000 TCP Synchronization of a redundant pair X
30001 TCP Synchronization of a redundant pair x
Inbound port for data ingestion from
32568 TCP HCAL Application Server or replication from X
another Historian
HTTP/HTTPS Inbound port for web server endpoint.
32569 API X
over TCP Serves Insight as well as OData API
51218 TCP Alarms Distributed Alarm Manager
49152- Port range allocated dynamically by
TCP DCOM
65000 DCOM
55555 TCP Licensing License Server Core Service X
59200 TCP Licensing License Server Agent HAL X

SUPPORTING INFORMATION

References:

Tech Note 470, Wonderware System Platform for IT Professionals


Tech Note 556, Port Configuration List for System Platform 2012R2 Multi-Galaxy Environment
Tech Note 464, Port Considerations for Wonderware Historian
IDE User Guide for Application Server: 2017 Update 3 - Configure ArchestrA Service TCP Ports
System Platform Installation Guide: 2017 Update 3

ATTACHMENTS
http://okmgcs.km.invensys.com/resources/sites/KPKA/content/live/TN/10000/TN10402/en_US/~secure/{ "SECUREDRESOURCE": "Y" }

Terms of Use| Privacy Policy


© 2020 AVEVA Group plc and its subsidiaries.All rights reserved.
Terms of Use| Privacy Policy
© 2020 AVEVA Group plc and its subsidiaries.All rights reserved.

You might also like