> ## Documentation Index
> Fetch the complete documentation index at: https://docs.levelblue.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Firewall Permissions

|                         |                    |                      |
| ----------------------- | ------------------ | -------------------- |
| **Applies to Product:** | **USM Appliance™** | **LevelBlue OSSIM®** |

USM Appliance components must use particular URLs, protocols, and ports to function correctly.

<Note>
  **Note:** If deploying USM Appliance All-in-One, you only need to open the ports associated with the monitored assets, because All-in-One includes both USM Appliance Server and USM Appliance Sensor, therefore the communication between them becomes internal.
</Note>

If your company operates in a highly secure environment, you must change some permissions on your firewall(s) for USM Appliance to gain access.

**External URLs and port numbers used by USM Appliance features**

| Server URL                                                                                                                                                                                                 | Port Number | LevelBlue Features in Use                                                                                                                                                                                                                                               | Applicable Release |
| ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------ |
| data.alienvault.com                                                                                                                                                                                        | 80          | USM Appliance product and feed update                                                                                                                                                                                                                                   | All                |
| maps-api-ssl.google.com <br />maps.googleapis.com                                                                                                                                                          | 443         | <Tooltip tip="An IP-addressable host, including but not limited to network devices, virtual servers, and physical servers.">Asset</Tooltip> Location                                                                                                                    | All                |
| maps.google.com <br />maps.gstatic.com                                                                                                                                                                     | 80          | Asset Location                                                                                                                                                                                                                                                          | All                |
| messages.alienvault.com                                                                                                                                                                                    | 443         | <Tooltip tip="Inbox in the USM Appliance Web UI which lists messages publicizing availability of various LevelBlue product updates plus other messages such as system errors and warnings.">Message Center</Tooltip>                                                    | All                |
| otx.alienvault.com<Tooltip tip="Due to the way that OTTX™ is managed, ottc.alienvault.com has not been fixed a static IP address and LevelBlue cannot provide the IP range."><sup>1</sup></Tooltip>        | 443         | Open Threat Exchange®                                                                                                                                                                                                                                                   | 5.1+               |
| reputation.alienvault.com                                                                                                                                                                                  | 443         | USM Appliance IP Reputation                                                                                                                                                                                                                                             | All                |
| tractorbeam.alienvault.com                                                                                                                                                                                 | 22, 443     | <Tooltip tip="Secure, encrypted connection to LevelBlue Support Server through the USM Appliance Web UI or the console, allowing LevelBlue Support staff to access, diagnose, and resolve any problems occurring in a USM Appliance instance.">Remote Support</Tooltip> | All                |
| [www.google.com](http://www.google.com)<Tooltip tip="The USM Appliance API tries to access www.google.com every five minutes to ensure that the system has an Internet connection."><sup>2</sup></Tooltip> | 80          | USM Appliance API                                                                                                                                                                                                                                                       | All                |
| cybersecurity.att.com/product/help/ping.php<Tooltip tip="USM Appliance assumes the component to be offline if no response is received from ping."><sup>3</sup></Tooltip>                                   | 443         | Detects if the USM Appliance component is online                                                                                                                                                                                                                        | All                |

The following diagram shows the port numbers used by the USM Appliance components to communicate with each other and with the monitored assets. The direction of the arrows indicate the direction of the network traffic.

<Frame>
  <img src="https://mintcdn.com/levelblue-5324744e/7iFYnn5doK0RP_h7/images/usm-appliance/portsgraph.webp?fit=max&auto=format&n=7iFYnn5doK0RP_h7&q=85&s=c532ff7c4ccaca4129382a107e7c63c0" alt="" width="1150" height="481" data-path="images/usm-appliance/portsgraph.webp" />
</Frame>

Port numbers used between USM Appliance components

<Warning>
  **Important:** Ports labeled with \* are optional.

  * On the hosts you plan to deploy the LevelBlue HIDS agents, to allow for initial deployment, you must open TCP port 135, either TCP port 139 or TCP port 445, and high TCP ports (1024 or above). See Microsoft's documentation on port requirements for Distributed File System Namespaces (DFSN).
  * You also need to open UDP port 1514 for ongoing communication between the LevelBlue HIDS agent and the USM Appliance Sensor. For assistance on deployment, see Deploy LevelBlue HIDS Agents.
  * To use SNMP in USM Appliance, you need to open UDP port 161 on the SNMP agent and UDP port 162 on the USM Appliance Sensor. For more details, see SNMP Configuration in USM Appliance.
  * If running USM Appliance versions prior to 5.6.5, you also need to open TCP port 9391 on the Sensor for the vulnerability scanner. But starting from version 5.6.5, vulnerability scans are conducted using the UNIX domain sockets, so port 9391 is no longer used.
</Warning>

## About the Use of VPN

Port 33800 shown in the diagram is a default and only used when VPN is enabled. You may use a different port for VPN, if desired.

<Note>
  **Note:** When enabling the VPN, you do not need to open the other ports between the USM Appliance Sensor and the USM Appliance Server, because all communication goes through the VPN tunnel.
</Note>

If you enable VPN, in addition to having port 33800/TCP open for the VPN tunnel, you also need to allow TLS transport for that port in case you use a firewall/security device that can perform inspection or interception of TLS traffic.
