Security & trust · 4 min

Network and ports

Open only the paths required for installation, WebAdmin, and selected business services.

Reviewed 5 September 2026

Portal connections

Monitoring and managed control initiate outbound HTTPS connections from the server. No inbound monitoring or managed-agent port is required. Allow DNS and HTTPS access to the LSBS portal and package repository.

Administration access

  • TCP 8443: local LSBS WebAdmin; scope it to administrator networks.
  • TCP 22: SSH, needed for assisted installation and intentional emergency administration only.
  • TCP 80/443: enable as required for public web services, certificate validation, or selected modules.

Service-specific ports

Mail, VPN, directory, DNS, DHCP, RADIUS, file sharing, and other modules have their own network requirements. Enable a module first, read its field help, and publish only paths needed by intended clients. Do not use a blanket allow rule as a substitute for module configuration.