For iba software to work properly, certain ports must be enabled in the firewall protecting the systems on which the service (server) is running. The ports in the following sections are distinguished between essential ports which are always opened by the service and ports which are used if needed. Furthermore, they are the default ports. Some of the ports can be changed ("modifiable").
Note |
|
|---|---|
|
The entries in the Traffic direction column correspond to the firewall rules of Windows Defender:
|
|
ibaPDA Server
Ports used by ibaPDA Server (service)
|
Interface |
Port / port range |
Connection |
Protocol |
Configurable |
Remark |
|---|---|---|---|---|---|
|
ibaPDA Client |
9170 |
inbound |
TCP |
yes |
ibaPDA client-server communication |
|
ibaPDA Discovery |
12800 |
inbound |
UDP |
no |
Searching for ibaPDA server IPv4: 226.254.92.220 |
Ports used by ibaPDA Server (service) if needed
The ports used depend on the product license. If an interface is not licensed, the corresponding port is not used.
|
Interface |
Port / port range |
Connection |
Protocol |
Configurable |
Remark |
|---|---|---|---|---|---|
|
AN-X-DCSNet |
47920 |
inbound |
UDP |
yes |
Receive data from AN-X-DCSNet devices |
|
Codesys V3 |
11740 |
outbound |
TCP |
yes |
- |
|
Codesys V3 Scan |
1742 |
outbound |
UDP |
nein |
Scanning for PLCs and retrieving address books |
|
CP1616 (PROFINET) |
34962 |
- |
TCP/UDP |
- |
- |
|
Request -DTBox UDP |
10000 - 10399 |
inbound |
UDP |
yes, on DT-Box side |
Receive data from DT-Box devices |
|
Ethernet Global Data (Interface-EGD) |
18246 |
inbound |
UDP |
yes |
Receive data from EGD devices |
|
Ethernet Global Data (EGD) Multicast |
18246 |
outbound |
UDP |
yes |
Discovery address IPv4: 224.0.7.1 |
|
EtherNet/IP |
44818 2222 |
inbound inbound |
TCP UDP |
no no |
Receive data from EtherNet/IP devices |
|
Flex Device discovery |
62101 |
inbound |
TCP |
no |
Autodetecting Flex devices |
|
Flex UDP Communication Port |
62012 |
- |
UDP |
no |
Used to receive data from ibaClock |
|
ibaPQU-S Computed Values |
62303 |
- |
UDP |
no |
Used to receive data from ibaPQU devices |
|
Generic TCP |
5010 (default) |
in-/outbound |
TCP |
yes |
outbound for output modules |
|
Generic UDP |
5010 (default) |
in-/outbound |
UDP |
yes |
outbound for output modules |
|
HiPAC request (discovery) |
26008 |
- |
UDP |
no |
Autodetecting HiPAC devices |
|
HPCi Request |
13245 |
outbound |
UDP |
yes, can be configured in address book (toc.ini) |
Autodetecting HPCi devices |
|
ibaNet-E |
7082 |
inbound |
UDP |
yes |
- |
|
ibaCapture |
9120 |
outbound |
TCP |
yes |
used, if ibaCapture devices are configured |
|
ibaCapture-ScreenCam |
9892 |
outbound |
TCP |
yes |
- |
|
ibaLogic TCP |
40002 |
inbound |
TCP |
yes |
Receive data from ibaLogic |
|
ibaPDA Multistation |
9175 |
inbound |
TCP |
yes |
Only if Multistation is enabled |
|
ibaPDA MultistationUnsynced Multicast |
9176 |
inbound |
UDP |
yes |
Only if non-synchronized slaves are configured IPv4: 226.227.228.100 (default) |
|
ibaPDA MultistationUnsynced Unicast |
9177 |
inbound |
UDP |
yes |
Only if non-synchronized slaves are configured |
|
ibaPDA SNMP |
1611 |
inbound |
UDP |
yes |
Only if SNMP server is enabled |
|
IEC 61850 Server |
102 |
- |
TCP |
yes |
Only if IEC 61850 server is enabled |
|
Micro-Epsilon for Discovery |
3956 |
outbound |
UDP |
no |
Scanning for Micro Epsilon devices |
|
Micro-Epsilon |
8000 61000 |
outbound outbound |
UDP UDP |
no no |
|
|
Modbus TCP Server Modbus TCP Client |
502 |
inbound |
TCP |
no |
- |
|
OPC DA |
135 |
inbound |
TCP |
no |
DCOM;only if OPC DA server is enabled |
|
137 |
inbound |
UDP |
no |
NetBIOS Filesharing |
|
|
138 |
inbound |
UDP |
no |
NBDS Filesharing |
|
|
139 |
inbound |
TCP |
no |
SMB Filesharing |
|
|
445 |
inbound |
TCP |
no |
SMB Filesharing |
|
|
OPC UA Server |
48080 |
outbound |
TCP |
yes |
Only if OPC UA server is enabled |
|
OPC UA Client |
4840 |
in-/outbound |
TCP |
yes |
- |
|
PTPv2 (ptp-event) |
319 |
in-/outbound |
UDP |
no |
Only if PTP is enabled IPv4: [IANA] 224.0.1.129 - 224.0.1.132 IPv6 1): [IANA] FF02::6BFF0x::181FF0x::182FF0x::183FF0x::184 |
|
PTPv2 (ptp-general) |
320 |
in-/outbound |
UDP |
no |
Only if PTP is enabled IPv4: [IANA] 224.0.1.129 - 224.0.1.132 IPv6 1): [IANA] FF02::6BFF0x::181FF0x::182FF0x::183FF0x::184 |
|
S7 TCP/UDP |
4170 |
inbound |
TCP/UDP |
yes |
Receive data from a SIMATIC S7 device or PLC |
|
Sisteam TCP |
8738 |
inbound |
TCP |
yes |
Receive data from a Sisteam PLC |
|
TCP/UDP Text |
1500, ... |
inbound |
TCP |
yes |
One port per TCP/UDP text module |
|
TDC TCP/UDP |
4171 |
inbound |
TCP/UDP |
yes |
Receive data from a SIMATIC TDC system |
|
TwinCAT PLC |
800 – 854 |
outbound |
AMS |
yes |
|
|
TwinCAT BC/BX controller |
800 – 854 |
outbound |
AMS |
yes |
|
|
TwinCAT-PLC BroadcastSearch |
48899 |
outbound |
UDP |
no |
Scanning for PLCs and retrieving address books |
|
VIP TCP/UDP |
5001 |
inbound |
TCP/UDP |
yes |
- |
|
Watchdog |
40001 |
outbound |
TCP/UDP |
yes |
Only if Watchdog is enabled |
|
X-Pact Request |
17477 |
- |
UDP |
yes |
Autodecting X-Pact devices |
1) These permanently assigned Multicast addresses are valid across all ranges. This is indicated by an "x" in the range field of the address, which means any valid range value.
ibaPDA Client
Ports used by ibaPDA Client
|
Interface |
Port / port range |
Connection |
Protocol |
Configurable |
Remark |
|---|---|---|---|---|---|
|
ibaPDA service |
9170 |
outbound |
TCP |
yes |
- |
|
ibaHD-Server |
9180 |
outbound |
TCP |
yes |
- |
|
ibaPDA Discovery |
12800 |
outbound |
UDP |
no |
Searching for ibaPDA servers IPv4: 226.254.92.220 |
|
ibaHD-Server Discovery |
12880 |
outbound |
UDP |
no |
Searching for ibaHD-Servers IPv4: 226.254.92.221 |
|
ibaQPanel (web browser) |
80 |
outbound |
TCP |
yes |
- |
|
ibaQPanel (web browser) |
443 |
outbound |
TCP |
yes |
- |
ibaPDA-S7-Xplorer Proxy
Ports used by ibaPDA-S7-Xplorer Proxy
|
Interface |
Port / port range |
Connection |
Protocol |
Configurable |
Remark |
|---|---|---|---|---|---|
|
ibaPDA Service |
9190 |
- |
TCP |
yes |
Communication between proxy and ibaPDA server |
ibaHD-Server (service)
Ports used by ibaHD-Server (service)
|
Interface |
Port / Port range |
Connection |
Protocol |
Configurable |
Remark |
|---|---|---|---|---|---|
|
ibaHD-Server |
9180 |
inbound |
TCP |
yes |
Communication with ibaHD clients, incl. ibaPDA server and client, ibaAnalyzer and ibaDatCoordinator |
|
ibaHD-Server Discovery |
12880 |
inbound |
UDP |
no |
Searching for ibaHD-Servers IPv4: 226.254.92.221 |
|
SNMP |
1614 |
inbound |
UDP |
yes |
Only if SNMP server is enabled |
|
ibaHD-API |
9003 |
inbound |
TCP |
yes |
Required to publish data for 3rd party clients and ibaDaVIS |
|
OPC UA |
4840 |
inbound |
TCP / HTTPS |
yes |
Required to publish data via OPC UA |
|
SMTP |
25 |
outbound |
TCP |
yes |
Required to send E-Mails |
ibaHD-Server Client
Ports used by ibaHD-Server Client (integrated in ibaPDA server and client, ibaAnalyzer, ibaDatCoordinator
|
Interface |
Port / Port range |
Connection |
Protocol |
Configurable |
Remark |
|---|---|---|---|---|---|
|
ibaHD-Server Discovery |
12880 |
inbound |
TCP |
no |
Searching for ibaHD-Servers |
ibaCapture Server
Ports used by ibaCapture Server (service)
|
Interface |
Port / Port range |
Connection |
Protocol |
Configurable |
Remark |
|---|---|---|---|---|---|
|
ibaCapture Discovery |
2378 |
inbound |
UDP |
no |
Searching for ibaCapture servers IPv4: 238.23.7.78 |
|
ibaCapture WCF services |
14809 |
inbound |
TCP |
no |
Communication with ibaCapture-Server |
|
ibaPDA communication |
9120 |
inbound |
TCP |
yes |
Incoming ibaPDA connections |
|
ibaPDA communication debugging |
6000 |
inbound |
TCP |
yes |
optional Debugging ibaPDA connection |
|
PTPv2 (ptp-event) |
319 |
outbound |
UDP |
no |
optional IPv4: [IANA] 224.0.1.129 - 224.0.1.132 IPv6 1): [IANA] FF02::6BFF0x::181FF0x::182FF0x::183FF0x::184 |
|
PTPv2 (ptp-general) |
320 |
outbound |
UDP |
no |
optional IPv4: [IANA] 224.0.1.129 - 224.0.1.132 IPv6 1): [IANA] FF02::6BFF0x::181FF0x::182FF0x::183FF0x::184 |
|
SNMP |
1616 |
inbound |
UDP |
yes |
optional |
|
RTSP Server |
8554 |
inbound |
TCP |
yes |
optional |
|
Camera replay stream port |
24950 – 25015 |
inbound |
TCP |
yes |
one port per camera; Video replay by ibaAnalyzer |
|
Camera live stream port |
24950 – 25015 |
inbound |
TCP |
yes |
one port per camera; optional |
1) These permanently assigned Multicast addresses are valid across all ranges. This is indicated by an "x" in the range field of the address, which means any valid range value.
Note: By default, camera live streams use dynamic ports. The fixed live stream ports allow to set up firewall rules.
Further ports, which may be used to access camera devices are not listed in this documentation.
ibaCapture GigE Vision Encoder
Ports used by ibaCapture GigE Vision Encoder
|
Interface |
Port / Port range |
Connection |
Protocol |
Configurable |
Remark |
|---|---|---|---|---|---|
|
ibaCapture GigE Vision Encoder WCF services |
9868 |
internal |
TCP |
yes |
only localhost |
|
ibaCapture GigE Vision Encoder WCF services |
14810 |
internal |
TCP |
no |
only localhost |
ibaCapture-ScreenCam
Ports used by ibaCapture-ScreenCam
|
Interface |
Port / Port range |
Connection |
Protocol |
Configurable |
Remark |
|---|---|---|---|---|---|
|
ibaCapture-ScreenCam discovery |
7072 |
inbound |
UDP |
no |
IPv4: 226.254.92.221 |
|
ibaCapture-ScreenCam WCF services |
9191 |
inbound |
TCP |
yes |
yes |
|
ibaCapture-ScreenCam camera instance |
9700, ... |
inbound |
TCP |
yes |
one port per instance |
|
ibaPDA communication |
9892 |
inbound |
TCP |
yes |
yes |
ibaVision
Ports used by ibaVision
|
Interface |
Port / Port range |
Connection |
Protocol |
Configurable |
Remark |
|---|---|---|---|---|---|
|
ibaVision discovery |
3702 |
inbound |
UDP |
no |
IPv4: 239.255.255.250 |
|
ibaVision WCF services |
7110 |
inbound |
TCP |
yes |
y |
|
Video outbound module |
7110 |
inbound |
TCP |
yes |
one port per module |
|
ibaPDA inbound module |
7111 |
outbound |
TCP |
yes |
one port per module |
|
ibaPDA outbound module |
7111 |
inbound |
TCP |
yes |
one port per module |
Note: The default port number is always the same, but ibaVision automatically assigns distinct port numbers during configuration.
ibaDatCoordinator
Ports used by ibaDatCoordinator
|
Interface |
Port / Port range |
Connection |
Protocol |
Configurable |
Remark |
|---|---|---|---|---|---|
|
ibaDatCoordinator |
8800 |
inbound |
TCP |
yes |
- |
|
ibaDatCoordinator service discovery |
12861 |
inbound |
UDP |
yes |
Searching for ibaDatCoordinator (service) IPv4: 226.254.92.220 |
|
ibaHD-Server |
9180 |
outbound |
TCP |
yes |
Read or write HD data |
|
SNMP |
1612 |
inbound |
UDP |
yes |
Only if SNMP is enabled; |
|
TCP/IP Watchdog |
40002 |
inbound |
TCP |
yes |
Only if Watchdog is enabled; |
|
OPC UA Server |
48081 |
inbound |
TCP |
yes |
Only if OPC UA server is enabled; Communication to 3rd party tools using OPC UA protocol |
|
Kafka / Event Hub |
8083 |
outbound |
TCP |
yes |
Communication to 3rd party tools using Kafka protocol |
|
Data Transfer Server |
30051 |
inbound |
TCP |
yes |
Only if Data Transfer Server is enabled; receive data from another ibaDatCoordinator instance |
|
FTP |
21, 20 |
outbound |
TCP |
yes |
- |
|
FTPS |
990, 989 |
outbound |
TCP |
yes |
- |
|
SMTP |
25 |
outbound |
TCP |
yes |
- |
|
S7 Writer |
102 |
outbound |
TCP |
no |
for PG connection, OP connection and other |
|
Amazon S3 |
443 |
outbound |
TCP |
yes |
|
|
Azure Data Lake |
443 |
outbound |
TCP |
yes |
|
|
Azure Blob Storage |
443 |
outbound |
TCP |
yes |
ibaAnalyzer
Ports used by ibaAnalyzer
|
Interface |
Port / Port range |
Connection |
Protocol |
Configurable |
Remark |
|---|---|---|---|---|---|
|
ibaHD-Server |
9180 |
outbound |
TCP |
yes |
- |
|
Microsoft SQL-Sever |
1433 |
outbound |
TCP |
yes |
- |
|
Oracle |
1521 |
outbound |
TCP |
yes |
- |
|
MySql/MariaDB |
3306 |
outbound |
TCP |
yes |
- |
|
PostgreSQL |
5432 |
outbound |
TCP |
yes |
- |
|
IBM DB2 |
50000 |
outbound |
TCP |
yes |
- |
ibaLicenseService-V2
Ports used by ibaLicenseService-V2
|
Interface |
Port / Port range |
Connection |
Protocol |
Configurable |
Remark |
|---|---|---|---|---|---|
|
Configuration |
8766 |
- |
TCP |
yes |
Remote configuration |
|
Data |
9033 |
- |
TCP |
yes |
Data communication |
|
Transport port for Support file |
8767 |
- |
TCP |
no |
- |
ibaDaVIS
Ports used by ibaDaVIS
|
Interface |
Port / Port range |
Connection |
Protocol |
Configurable |
Remark |
|---|---|---|---|---|---|
|
Microsoft SQL-Sever |
1433 |
outbound |
TCP |
yes |
SQL communication |
|
MySQL/MariaDB |
3306 |
outbound |
TCP |
yes |
SQL communication |
|
Oracle |
1521 |
outbound |
TCP |
no |
SQL communication |
|
PostgreSQL |
5432 |
outbound |
TCP |
yes |
SQL communication |
|
Web interface HTTP |
80 |
inbound |
TCP |
yes |
yes, in configuration file for application use |
|
Web interface HTTPS |
443 |
inbound |
TCP |
yes |
SSL communication |
|
ibaHD-API |
9003 |
outbound |
TCP |
yes |
Commnication with ibaHD-Server |
ibaManagementStudio Server
Ports used by ibaManagementStudio Server
|
Interface |
Port / port range |
Connection |
Protocol |
Configurable |
Remark |
|---|---|---|---|---|---|
|
Web interface HTTPS |
10522 |
inbound |
TCP |
yes |
Open the web client |
|
Agents(connection initiated by server) |
10519 |
inbound |
TCP |
yes |
Communication with agents in WAN mode |
Note |
|
|---|---|
|
ibaManagementStudio services ibaManagementStudio runs as a service under Windows. In addition to the agent service, an auxiliary service must also be running to perform tasks that require elevated permissions. This means that the agent service, which does not have an open interface, does not require elevated permissions. The auxiliary service does not open any additional ports, but uses the interaction port of the software. |
|
ibaManagementStudio Agent
Ports used by ibaManagementStudio Agent
|
Interface |
Port / port range |
Connection |
Protocol |
Configurable |
Remark |
|---|---|---|---|---|---|
|
Agent discovery |
10517 |
inbound |
UDP |
no |
Searching for agents by Managementstudio server IPv4: 238.23.7.100 |
|
Agent (connection initiated by agent) |
10518 |
inbound |
TCP |
yes |
Communication to agents in LAN mode |
|
Agent(connection initiated by server) |
10519 |
outbound |
TCP |
yes |
- |
|
Interaction port software |
10521 |
internal |
TCP |
yes |
- |
ibaCMC
Ports used by ibaCMC
|
Interface |
Port / Port range |
Connection |
Protocol |
Configurable |
Remark |
|---|---|---|---|---|---|
|
MQTT Broker |
1883 |
inbound |
TCP |
yes |
Communication with ibaPDA |
|
MQTT Broker |
88883 |
inbound |
TCP |
yes |
TLS |
|
Traces |
16461 |
- |
UDP |
yes |
Debug traces |
|
Web interface |
80 |
inbound |
HTTP |
yes |
Connecting a web browser with ibaCMC web client |
|
Web Interface |
443 |
inbound |
HTTPS |
yes |
- |
|
SMTP |
25 |
outbound |
TCP |
yes |
- |
Configuration and modification of ports by editing appsettings.json file.
ibaLogic Server
Ports used by ibaLogic Server
|
Interface |
Port range |
Connection |
Protocol |
Configurable |
Remark |
|---|---|---|---|---|---|
|
ibaLogic Server |
6510 |
inbound |
TCP |
yes |
Client-server communication |
|
ILUS Update |
22012 |
inbound |
TCP |
no |
For ibaPADU-S-IT only, for update and control of PMAC |
|
Microsoft SQL-Server |
1433 |
outbound |
TCP |
no |
Database communication |
|
OPC Control Service Communication |
22050 ... 22052 |
outbound |
UDP |
no |
Control of OPC UA services |
|
PMAC Communication |
21000 ... 21002 |
outbound |
TCP |
no |
Communication with PMAC |
|
OPC DA Communication |
21004 ... 21005 |
outbound |
TCP |
no |
Communication with OPC DA |
|
PMAC Control Service Communication |
22046 ... 22049 |
outbound |
UDP |
no |
For control and configuration of local PMAC |
|
PMAC Network Discovery |
22044 ... 22045 |
outbound |
UDP |
no |
Scanning the local network for PMACs |
ibaLogic Client
Ports used by ibaLogic Client
|
Interface |
Port / Port range |
Connection |
Protocol |
Configurable |
Remark |
|---|---|---|---|---|---|
|
ibaLogic PDA Express Communication |
21003 |
outbound |
TCP |
no |
Parameter transfer to PDA-Express |
|
ibaLogic Server Communication |
6510 |
outbound |
TCP |
yes |
Client-server communication |
ibaLogic PMAC
Ports used by ibaLogic PMAC
|
Interface |
Port / Port range |
Connection |
Protocol |
Configurable |
Remark |
|---|---|---|---|---|---|
|
ibaLogic OPC Server Communication |
21004 - 21005 |
outbound |
TCP |
no |
Read/write values from/to OPC DA, OPC UA |
|
ibaLogic PDA Express Communication |
21003 |
outbound |
TCP |
no |
Read values from PDA-Express |
|
ibaLogic Server Communication |
21000 - 21002 |
inbound |
TCP |
no |
Communication with ibaLogic server and OPC UA/DA server |
|
PMAC Network Discovery |
22044 |
inbound |
UDP |
no |
Scanning the local network for PMACs |
|
PMAC Port in ibaLogic V4 |
23042 |
inbound |
TCP |
no |
In ibaLogic V4 only, communication with server |
|
Timing-Diagnostics Tool |
22013 |
inbound |
TCP |
no |
Retrieving values from the Timing Diagnostic Tool |
ibaLogic OPC-Server
Ports used by ibaLogic OPC-Server
|
Interface |
Port / Port range |
Connection |
Protocol |
Configurable |
Remark |
|---|---|---|---|---|---|
|
OPC UA Endpoint |
21060 ... 21061 |
inbound |
TCP |
no |
Communication between OPC UA service and ibaLogic sever |
|
PMAC Communication |
21004 ... 21005 |
inbound |
TCP |
no |
Read/Write values from/to PMAC |
WIBU CodeMeter Runtime
The software CodeMeter Runtime is a third party software, which is used to license iba software products. Therefore, it needs to be installed where iba software products are licensed by the WIBU system.
Ports, used by WIBU CodeMeter Runtime
|
Interface |
Port / Port range |
Connection |
Protocol |
Configurable |
Remark |
|---|---|---|---|---|---|
|
Standard CodeMeter communication |
22350 |
inbound |
TCP |
yes |
- |
|
HTTP (WebAdmin) |
22352 |
internal |
TCP |
yes |
- |
|
HTTPS (WebAdmin) |
22353 |
internal |
TCP |
yes |
- |
Note |
|
|---|---|
|
For more information about ports and access permissions, please refer directly to WIBU-SYSTEMS AG (http://www.wibu.com). |
|