Connection
Protocol
Service
Function
Port
Outbound from Web Appliance to
Management Appliance (if
collocated)
TCP
SSH
Central configuration, status and
reporting
22
Outbound from Appliance to LAN
UDP
DNS
DNS queries
53
Inbound from LAN to appliance
TCP
HTTP
administrative web interface
80
Inbound/outbound between
appliance and AD server
TCP/UDP
KERBEROS
Kerberos authentication
88
Inbound/outbound between
appliance and AD server
TCP/UDP
NETBIOS-SSN
MS NetBIOS session
139
Inbound/outbound between
appliance and AD server
TCP/UDP
LDAP
Directory services synchronization
389
Inbound from LAN to appliance
TCP
HTTPS
administrative web interface
443
Inbound/outbound between
appliance and AD server
TCP/UDP
SMB
MS server message block
445
Inbound/outbound between
appliance and eDirectory server
TCP
LDAPS
LDAP synchronization
636
Inbound/outbound between
appliance and AD server
TCP/UDP
MSGC
MS AD Global Catalog
synchronization
3268
Inbound/outbound between LAN and
appliance
TCP
HTTP/HTTPS
Proxy (end user web browsing)
8080
New Web Appliance join produces an AD integration alert and blocks
all users’ web access
Problem: When you join a new Web Appliance to a configured Management Appliance, the Web
Appliance raises an Active Directory integration alert, and web access is blocked for all of the
Web Appliance’s users.
Cause: The configuration data downloaded from the Management Appliance includes Active
Directory access configuration, but the firewall between the new Web Appliance and the Active
Directory server has not been configured to open the required ports.
Solution: You can either configure your firewall to provide access to the ports and services listed
in the preceding tables, or you can configure the new Web Appliance to use a local Active Directory
212 | Appliance Behavior and Troubleshooting | Sophos Web Appliance