Skip to main content

Port Communication Requirements

Active Directory

For EmpowerID to communicate with Active Directory environments, the following ports must be open:

PortProtocolService
135TCPRPC
137UDPNetBIOS
138UDPNetBIOS
139TCPNetBIOS
389TCP/UDPLDAP
636TCPLDAP SSL
3268TCPLDAP GC
3269TCPLDAP GC SSL
53TCP/UDPDNS
88TCP/UDPKerberos
445TCPSMB
123UDPNTP

Internal EmpowerID Communications

Server to Server Communications

EmpowerID server to server communications require the following ports be open:

PortProtocolPurpose
443TCPHTTPS/TLS

Server to SQL Database Communications

EmpowerID server to SQL Database communications require the following ports be open:

PortProtocolPurpose
1433TCPMicrosoft SQL Server
🔄Reverse Proxy Note

The EmpowerID WAM/Reverse Proxy does not require any communication with the Microsoft SQL database. The Reverse Proxy retrieves all of its configuration data by calling the EmpowerID REST API on any front-end servers.

EmpowerID Communications Architecture

The below two images depict the EmpowerID Communications and Connectivity architecture. The first shows the architecture without EmpowerID WAM/Reverse Proxy, while the second shows the architecture with EmpowerID WAM/Reverse Proxy.

Figure 1: EmpowerID Communications and Connectivity Architecture

Additional Port Requirements

🔑Password Reset Ports

In addition to the above, for password resets you may need to open TCP/UDP 135, as well as all RPC dynamic ports. For more information, see the following Microsoft topics: