Security & trust · 4 min
Network and ports
Open only the paths required for installation, WebAdmin, and selected business services.
Reviewed 5 September 2026
Portal connections
Monitoring and managed control initiate outbound HTTPS connections from the server. No inbound monitoring or managed-agent port is required. Allow DNS and HTTPS access to the LSBS portal and package repository.
Administration access
- TCP 8443: local LSBS WebAdmin; scope it to administrator networks.
- TCP 22: SSH, needed for assisted installation and intentional emergency administration only.
- TCP 80/443: enable as required for public web services, certificate validation, or selected modules.
Service-specific ports
Mail, VPN, directory, DNS, DHCP, RADIUS, file sharing, and other modules have their own network requirements. Enable a module first, read its field help, and publish only paths needed by intended clients. Do not use a blanket allow rule as a substitute for module configuration.