CCURE v2.60 iSTAR Ports - 8200 1413 01 - A0
CCURE v2.60 iSTAR Ports - 8200 1413 01 - A0
Port Assignments
The port assignments in this document are valid for C·CURE 9000 2.60, iSTAR Ultra family firmware v6.5.0, iSTAR Pro
firmware v5.2.x, and the iSTAR Edge/eX firmware v6.2.x.
8200-1413-01 A0
Table of Contents
IP-ACM .............................................................................................................................................................................. 17
ICU .................................................................................................................................................................................... 18
2
C•CURE 9000 Server (victor Application Server)
vAS 80 TCP Bidirectional Client IIS Port for IIS, C·CURE web client.
vAS 80 TCP Bidirectional VideoEdge VideoEdge NVR Admin/Alarm VideoEdge NVR Admin/Alarm Port
Port
vAS 80 TCP Bidirectional everRun everRun IIS everRun IIS port (required to be open)
vAS 123 UDP Bidirectional vAS/Client Time Synchronization For time synchronization
vAS 135 UDP Bidirectional everRun/ArcServe ArcServe RHA Control service Used by many programs and protocols. RHA
server and the engine server specifically uses it for the remote installer. This is also
used by the Microsoft EPMAP (End Point Mapper)
which is the DCE/RPC locator service used to remotely
manage services such as DHCP servers.
vAS 137 UDP Bidirectional everRun/ArcServe ArcServe RHA Control service NetBIOS Name Service - Windows CIFS/SMB protocol
server and the engine server family – used by RHA remote installer
vAS 138 UDP Bidirectional everRun/ArcServe ArcServe RHA Control service NetBIOS Datagram Service - Windows CIFS/SMB
server and the engine server protocol family – used by RHA remote installer
vAS 389 TCP Outbound LDAP Server LDAP LDAP which is used to synchronize C·CURE database
with other databases (non-C·CURE ). It allows other
databases, such as human resources information, to
download information
vAS 443 TCP Bidirectional Web everRun HTTPS HTTPS Port for SSL connections with C·CURE Go Stratus
Communications (everRun) communication
vAS 445 TCP Bidirectional Web Microsoft-DS Part of Windows operating system, used for MS
networking access without the need for a NetBIOS
3
C•CURE 9000 Server (victor Application Server)
Source Port/ Protocol Direction Destination Process/ Description
System Range System Service
layer. This port should be closed.
vAS 500 UDP Bidirectional Web IKEEXT svchost.exe Windows service for IKE and AuthIP IP sec Keying
modules. Required for operation of C·CURE.
vAS 554 TCP Bidirectional VideoEdge RTSP stream VideoEdge NVR Live Port
vAS 1025 TCP Bidirectional ARCServe ARCSERVE RHA Control service Windows active directory port, RHA connects to AD to
center Windows DNS discover some Windows domain configuration/settings
and resources to be replicated (Exchange servers, DNS
server, etc.)
vAS 1025 TCP Bidirectional Sur-Guard Sur-Guard Sur-Guard communication
vAS 1433 UDP and Bidirectional SQL Server SQL Server Traffic Direction from 9000 server outbound;
TCP Connection Initiate from 9000 server to SQL server.
Communication from C·CURE to SQL for database
writing, reading and modifying.
vAS 1434 UDP Bidirectional SQL Server SQL Server Traffic Direction from 9000 server outbound;
Connection Initiate from 9000 server to SQL server.
Communication from C·CURE to SQL for database
writing, reading and modifying.
vAS 2001 UDP Bidirectional iSTAR ICU.exe ICU discovery and communication with iSTAR panels.
vAS 2188-2189 TCP Bidirectional everRun everRun quorum service everRun quorum service computers and XenServer
computers and XenServer hosts
hosts
vAS 2006 TCP Bidirectional apC apC Controller Communication apC Controller Communication
vAS 2800 UDP and Transmit iSTAR Host port for iSTAR driver Host port for incoming non-encrypted iSTAR (Pro and
TCP Ultra) connections
vAS 2801 TCP Transmit iSTAR iSTAR Fast personnel HOST port for non-encrypted fast personal download
download host port - to iSTAR (Pro and Ultra) panels
vAS 2802 TCP Transmit iSTAR Fast image download host port location = vAS, Traffic Direction from vAS = inbound,
(iSTAR Pro only) Connection Initiate from iSTAR panels. Non-encrypted
4
C•CURE 9000 Server (victor Application Server)
Source Port/ Protocol Direction Destination Process/ Description
System Range System Service
image download for iSTAR Pro.
vAS 3001 TCP Bidirectional apC apC Network Comm Port Comm port on Lantronix device used by apC panel
vAS 5000-5003 TCP Bidirectional apC Lantronix Terminal Server Lantronix Terminal Server
vAS 5000 TCP Bidirectional ISC ISC Controller communication ISC Controller communication, alternative 6000 port.
ISC is not supported in C·CURE 9000 v2.30 or later.
vAS 5001 TCP Bidirectional ISC ISC Controller communication ISC Controller communication, alternative 6001 port.
ISC is not supported in C·CURE 9000 v2.30 or later.
vAS 5002 TCP Bidirectional ISC ISC Controller communication ISC Controller communication, alternative 6002 port.
ISC is not supported in C·CURE 9000 v2.30 or later.
vAS 5003 TCP Bidirectional ISC ISC Controller communication ISC Controller communication, alternative 6003 port.
ISC is not supported in C·CURE 9000 v2.30 or later.
vAS 5025 TCP Bidirectional ISC ISC Point Change Port ISC Point Change Port. ISC is not supported in C·CURE
9000 v2.30 or later.
vAS 5026 TCP Bidirectional ISC ISC Version Attendance Port ISC Version Attendance Port. ISC is not supported in
C·CURE 9000 v2.30 or later.
vAS 5900 TCP Bidirectional everRun VNC with Linux VMs everRun communication for failover/redundancy
vAS 7144-7145 TCP Transmit EMC Replistor EMC Replistor For EMC Replistor failover/redundancy
vAS 7800 UDP Bidirectional Bosch Bosch Bosch receiver port
vAS 8005 TCP Bidirectional Windows System Trace Viewer URI System Trace Viewer URI
vAS 8006 TCP Bidirectional Windows Remote Hardware Interface Remote Hardware Interface List URI
List URI
5
C•CURE 9000 Server (victor Application Server)
Source Port/ Protocol Direction Destination Process/ Description
System Range System Service
vAS 8042-8045 TCP Transmit EMC Autostart EMC AutoStart For EMC AutoStart failover/redundancy
vAS 8080-8081 TCP Transmit everRun everRun eAC everRun eAC communication for failover/redundancy
vAS 8085 TCP Bidirectional Client Auto Update Auto Update for clients and SAS from MAS
vAS 8985 TCP Bidirectional iSTAR/vAS BASE ADDRESS OF DRIVER location = Server
SERVICE Base for drivers for iSTAR, VideoEdge, Intellex, etc.
used to drive communication
vAS 8995 TCP Bidirectional MAS and SAS Installation, upgrade and For MAS and SAS installation, upgrade and repair
repair operations on MAS and communication between MAS and SAS, only required
SAS when SAS needs to be installed
vAS 8996 TCP Bidirectional Client Crossfire service of web client location = vAS, Traffic Direction from vAS = inbound,
session Connection Initiate from 9000 Client. For clients to
access C·CURE from web.
vAS 8997 TCP Bidirectional Client Admin / Monitor Client stream location = vAS, Traffic Direction from vAS = inbound,
Connection Initiate from 9000 Client. Client access to
administrative or monitor station of C·CURE
vAS 8998 TCP Bidirectional Client Crossfire service of HTTP client location = vAS, Traffic Direction from vAS = inbound,
session Connection Initiate from 9000 Client. For HTTP of
crossfire for client session
vAS 8999 TCP Bidirectional Client Crossfire service of TCP client location = vAS, Traffic Direction from vAS = inbound,
session Connection Initiate from 9000 Client. For crossfire
service of TCO client session.
vAS 8999 TCP Bidirectional MAS and SAS Installation, upgrade and For MAS and SAS installation, upgrade and repair
repair operations on MAS and communication between MAS and SAS
SAS
vAS 9701 TCP Bidirectional iSTAR Ultra ICU.exe/LightTPD.exe iSTAR Ultra download firmware
vAS 10001- TCP Bidirectional Lantronix serial DSC serial through Lantronix and Simplex 4100U serial
10002 through Lantronix
vAS 22609 TCP Bidirectional HDVR HDVR Admin/Line/Alarm Port HDVR Admin/Line/Alarm Port
vAS 27000 TCP Bidirectional MAS and SAS TycoESS License software location = vAS, traffic direction from vAS = inbound,
Connection initiate from vAS/9000 Client. Used for
verifying licenses with Software House.
6
C•CURE 9000 Server (victor Application Server)
Source Port/ Protocol Direction Destination Process/ Description
System Range System Service
vAS 27010 TCP Bidirectional MAS and SAS TycoESS – License Vendor For multiple licenses.
Daemon
vAS 28001 TCP Bidirectional iSTAR iSTAR eX/Edge/Ultra Fast location = vAS, traffic direction from vAS = inbound,
download connection Connection initiate from encrypted iSTAR panels
vAS 28002 TCP Bidirectional iSTAR iSTAR eX/Edge/Ultra Fast location = vAS, traffic direction from vAS = inbound,
image download Connection initiate from encrypted iSTAR panels
vAS 28003 TCP Bidirectional iSTAR iSTAR eX/Edge/Ultra Used by location = vAS, traffic direction from vAS = inbound,
host to accept eX or Edge Connection initiate from encrypted iSTAR panels
request for certificate signing
vAS 28004 TCP Bidirectional iSTAR ISTAR eX/Edge/Ultra Used by location = encrypted iSTAR Panels, traffic direction
eX or Edge to accept a signed from vAS = outbound, connection initiate from vAS
certificate
vAS 28009 TCP Bidirectional iSTAR iSTAR EX/Edge/Ultra master location = master iSTAR, connection initiate from iSTAR
port for incoming member panels
connections
This port is used to communicate between iSTARs in
the same cluster. Not needed for stan-alone iSTARs,
but cannot be closed.
vAS 28010 TCP Bidirectional iSTAR Host port for incoming iSTAR Port used by stunnel on server for incoming iSTAR
connections panel connection
vAS 47808 UDP Bidirectional MZX MZX MZX fire detection integration
vAS 32200- UDP Bidirectional VideoEdge VideoEdge streaming VideoEdge NVR Streaming Port
38200
vAS 30000- TCP Bidirectional iSTAR iSTAR to C·CURE Stunnel
65535 communication (30000- This port number is generated during bootup and is
61000) the stunnel communication for C·CURE.
C·CURE communication
(30000-655535)
vAS 10001 - TCP Bidirectional Honeywell Galaxy Galaxy Honeywell Galaxy Panel
10002 panel
vAS 3072 TCP Bidirectional DSC PowerSeries ITV2 ITV2 – DSC PowerSeries Neo
vAS 5001 TCP Bidirectional TOA Server TOA TOA Intercom server
vAS 3001 TCP Bidirectional Commend Server Commend Commend Intercom server
7
C•CURE 9000 Server (victor Application Server)
Source Port/ Protocol Direction Destination Process/ Description
System Range System Service
vAS 2004-2005 TCP Bidirectional KONE Elevator KONE Elevator KONE Elevator
vAS 45303, TCP Bidirectional Otis Elevator Otis Elevator Otis Elevator
45307,
45308,
46307,
46308,
47307
vAS 8038-8041 TCP Bidirectional ThyssenKrupp ThyssenKrupp Elevator ThyssenKrupp Elevator
Elevator
vAS 47808 TCP Bidirectional BACNet controller BACNet BACNet Building Management
vAS 1001 TCP Bidirectional Elpas Elpas Elpas real time location
vAS 4040, 5050 TCP Bidirectional Schindler Elevator Schindler Elevator Schindler Elevator
vAS 30000 TCP Bidirectional CEM CDC Server CEM CEM Access Control
vAS 8801 TCP Bidirectional Entrapass Server Entrapass Entrapass Access Control
vAS / 8080 TCP Bidirectional 3VR Recorder 3VR 3VR video recorder
victor
vAS / 80 TCP Bidirectional Bosch Recorder Bosch Video Bosch video recorder
victor
vAS / 8016 TCP Bidirectional Matrix Recorder Matrix Video Matrix video recorder
victor
vAS / 80 TCP Bidirectional Dedicated Micro Dedicated Micro Dedicated Micro video recorder
victor Recorder
vAS 5050 TCP Bidirectional Mastermind Mastermind Mastermind Alarm Management
System
8
C•CURE 9000 Client
Client 123 UDP Bidirectional vAS Time Synchronization For time synchronization
Client 8085 TCP Bidirectional MAS and SAS Auto Update Auto Update for clients and SAS from MAS
Crossfire Service of location = vAS, Traffic Direction from vAS = inbound,
Client 8996 TCP Bidirectional vAS web client session Connection Initiate from 9000 Client
Admin/ Monitor client location = vAS, Traffic Direction from vAS = inbound,
Client 8997 TCP Bidirectional vAS stream Connection Initiate from 9000 Client
Crossfire Service of location = vAS, Traffic Direction from vAS = inbound,
Client 8998 TCP Bidirectional vAS HTTP client session Connection Initiate from 9000 Client
Crossfire Service of location = vAS, Traffic Direction from vAS = inbound,
Client 8999 TCP Bidirectional vAS TCP client session Connection Initiate from 9000 Client
9
iSTAR Edge/eX
iSTAR Edge/eX
Source Port/ Protocol Direction Destination Process/ Description
System Range System Service
iSTAR Web connection used for diagnostic website. Port is closed in FIPS
Edge/eX 80 TCP Bidirectional Web HTTP mode. Only necessary for diagnostics
iSTAR
Edge/eX 1999 TCP Bidirectional ICU Configuration iSTAR port for incoming ICU requests.
iSTAR PC running iWATCH connection port. Not open by default, but can be enabled via
Edge/eX 2008 TCP Bidirectional iWatch iWATCH webpage diag settings.
iSTAR HOST/Master
Edge/eX 28004 TCP Bidirectional iSTAR encryption Used to accept signed certificate for encryption.
iSTAR encrypted
Edge/eX 28009 TCP Bidirectional iSTAR Cluster member iSTAR port for incoming encrypted member requests
iSTAR 1025 - iSTAR to C·CURE This port number is generated during bootup and is the stunnel
Edge/eX 5000 TCP Bidirectional Host communication communication for C·CURE [port 28010 (stunnel)]
iSTAR
Edge/eX 2001 UDP Inbound ICU discovery iSTAR port for ICU broadcasts
Windows DNS, a function of the Windows operating system on the iSTAR
which resolves domain names. This port cannot be closed, but is not
iSTAR part of the iSTAR function. Customer can block this port via network
Edge/eX 1025 UDP Bidirectional vAS Windows DNS firewall.
SNMP
Protocol for collecting and organizing information about managed
iSTAR devices on IP networks and for modifying that information to change
Edge/eX 161 UDP Bidirectional vAS SNMP device behavior.
iSTAR NetBIOS Name Service. This is a function of Windows and cannot be
Edge/eX 137 UDP Bidirectional vAS Netbios-NS closed, but is not required for iSTAR operation.
NETBIOS Datagram Service. This is a function of Windows and cannot be
iSTAR closed, but is not required for iSTAR operation. Customer can block this
Edge/eX 138 UDP Bidirectional vAS Netbios-DS port via network firewall.
10
iSTAR Pro
iSTAR Pro
Source Port/ Protocol Direction Destination Process/ Description
System Range System Service
iSTAR Web connection used for diagnostic website. Port is closed in FIPS mode. Only necessary
Pro 80 TCP Bidirectional Web HTTP for diagnostics
iSTAR iSTAR master port for incoming non-encrypted member connections, plus incoming ICU
Pro 1999 TCP Bidirectional iSTAR/ICU Master requests
iSTAR PC running iWATCH connection port. Not open by default, but can be enabled via webpage diag
Pro 2008 TCP Bidirectional iWatch iWATCH settings
iSTAR
Pro 2001 UDP Inbound ICU discovery iSTAR port for ICU broadcasts
SNMP
iSTAR Protocol for collecting and organizing information about managed devices on IP networks
Pro 161 UDP Bidirectional vAS SNMP and for modifying that information to change device behavior
Windows DNS, a function of the Windows operating system on the iSTAR which resolves
iSTAR domain names. This port cannot be closed, but is not part of the iSTAR function. Customer
Pro 1025 UDP Bidirectional vAS Windows DNS can block this port via network firewall.
iSTAR 1025 - TCP Bidirectional Host iSTAR to C·CURE This port number is generated during bootup.
Pro 5000 communication
11
iSTAR Ultra and iSTAR Ultra SE
iSTAR Ultra and iSTAR Ultra SE (Note: iSTAR Ultra SE Pro Mode doesn’t support encryption.)
iSTAR
Ultra,
Ultra SE 80 TCP Bidirectional Web HTTP Redirect to HTTPS (port 443)
iSTAR
Ultra, Secure web connection used for diagnostic website. Port is
Ultra SE 443 TCP Bidirectional Web HTTPs closed in FIPS mode. Only necessary for diagnostics
iSTAR
Ultra, Non-encrypted iSTAR master port for incoming non-encrypted member
Ultra SE 1999 TCP Bidirectional iSTAR/ICU Master connections, plus incoming ICU requests.
iSTAR
Ultra, iWATCH connection port. Not open by default, but can be
Ultra SE 2008 TCP Bidirectional PC running iWatch iWATCH enabled via webpage diag settings
iSTAR
Ultra, HOST/Master
Ultra SE 28004 TCP Bidirectional iSTAR encryption Used to accept signed certificate for encryption.
iSTAR
Ultra,
Ultra SE 28009 TCP Bidirectional Encrypted iSTAR iSTAR Member iSTAR Ultra incoming encrypted member connection port
iSTAR
Ultra,
Ultra SE 255 raw Bidirectional Host ICMP ICMP broadcast
iSTAR
Ultra,
Ultra SE 2900 TCP Bidirectional IP-ACM Communication Communication to the IP-ACM
12
iSTAR Ultra and iSTAR Ultra SE (Note: iSTAR Ultra SE Pro Mode doesn’t support encryption.)
13
iSTAR Ultra Video
VideoEdge 554 TCP Bidirectional Camera RTSP Camera video streaming connectiona
iSTAR master port for incoming non-encrypted
Non-encrypted member connections, plus incoming ICU
iSTAR Ultra 1999 TCP Bidirectional iSTAR /ICU Master requests.
It listens to requests from iSTAR web/iUVWeb,
and turns the web request to iSTAR messages
and sends them to GCM; when iUV web service
iSTAR Ultra receives GCM responses, the service will send
Video 2899 TCP Bidirectional iSTAR Ultra Web Service them back to web.
Communication between IP-ACM and iSTAR
iSTAR Ultra 2900 TCP Bidirectional IP-ACM Communication Ultra
Reserved for enhanced communication
iSTAR Ultra 2901 TCP Bidirectional IP-ACM Communication between IP-ACM and iSTAR Ultra
VideoEdge 55555 TCP Bidirectional Internally Used Transmit Manager Transmit manager - not used externally
VideoEdge 25 TCP Bidirectional mail server SMTP SMTP
VideoEdge 68 UDP Bidirectional DHCP server DHCPC Obtaining dynamic IP address (DHCP)
NTP (time
VideoEdge 123 UDP Bidirectional server) NTP ntp
VideoEdge 161 UDP Bidirectional SNMP manager SNMP SNMP
14
iSTAR Ultra Video
Source Port/ Protocol Direction Destination Process/ Description
System Range System Service
VideoEdge 162 UDP Bidirectional SNMP manager SNMP SNMP Trap
Remote control
(should be
VideoEdge 623 UDP Bidirectional closed) RPC RPC - standard Linux open port
VideoEdge 1900 UDP Bidirectional Any UPnP UPnP
veAutoDiscSSDP - Discovery of devices, close
VideoEdge 1900 SSDP Bidirectional Any AD discovery after setup
veAutoDiscScan - Discovery of devices, close
VideoEdge 2980 UDP Bidirectional Any AD discovery after setup
victor Client UDP Default VideoEdge UDP port range (for victor
VideoEdge 32200-38199 UDP Bidirectional victor Client communication client connections)
veAutoDiscMDNS - Discovery of devices, close
VideoEdge 32200-38199 UDP Bidirectional Any AD discovery after setup
veAutoDiscScan - Discovery of devices, close
VideoEdge 32200-38199 UDP Bidirectional Any AD discovery after setup
veAutoDiscSSDP - Discovery of devices, close
VideoEdge 32200-38199 UDP Bidirectional Any AD discovery after setup
15
Source Port/ Protocol Direction Destination Process/ Description
System Range System Service
Remote
Transcoding and
VideoEdge 9000-9128 TCP Bidirectional Failover NVR Failover Remote Transcoding and Failover
DHCP client. A function of Linux and
iSTAR Ultra 68 UDP Bidirectional Network DHCP networking.
iSTAR Ultra 2001 UDP Inbound ICU discovery iSTAR port for ICU broadcast
PC running
iSTAR Ultra 2008 TCP Bidirectional iWatch iWATCH iWATCH connection port
Encrypted iSTAR Ultra incoming encrypted member
iSTAR Ultra 28009 TCP Bidirectional iSTAR iSTAR Member connection port
Used to accept signing for certificate for
iSTAR Ultra 28004 TCP Bidirectional Host Certificate signing encryption
16
IP-ACM
IP-ACM
Source Port/ Protocol Direction Destination Process/ Description
System Range System Service
Web connection used for diagnostic website.
IP-ACM 80 TCP Bidirectional Web HTTP Only necessary for diagnostics
17
ICU
ICU 2001 UDP Inbound iSTAR Discovery Listening port for iSTAR broadcast.
ICU 2910 UDP Inbound iSTAR Discovery Listening port for IP-ACM broadcast.
ICU 9701 TCP bidirectional iSTAR ICU/LightTPD Server port for FW download to iSTAR Ultra
The trademarks, logos, and service marks displayed on this document are registered in the United States [or other countries]. Any misuse of the trademarks is strictly prohibited and Tyco will
aggressively enforce its intellectual property rights to the fullest extent of the law, including pursuit of criminal prosecution wherever necessary. All trademarks not owned by Tyco are the
property of their respective owners, and are used with permission or allowed under applicable laws.
Product offerings and specifications are subject to change without notice. Actual products may vary from photos. Not all products include all features. Availability varies by region; contact
your sales representative.
18