A Configuring Ports
To ensure the functionality of the Sophos Web Appliance, configure your network to allow access
on the ports listed below. Some ports are required only for specific situation, such as when you
enable FTP backups or central management.
External Connections
These services are typically used for connections between your Web Appliance(s) and locations
outside of your organization’s network.
ConnectionProtocolServiceFunctionPort
Outbound from appliance to
sophos.com
TCPSSHRemote assistance22
Outbound from Web Appliance to
Management Appliance (if not
collocated)
TCPSSHCentral configuration, status and
reporting
22
Outbound from appliance to
sophos.com
TCPSMTPRemote assistance notification25
Outbound from appliance to internetTCPHTTPOutbound network web traffic80
Outbound from appliance to internetUDPNTPNetwork time synchronization123
Outbound from appliance to internetTCPHTTPSOutbound network web traffic443
Note: Opening ports 80 and 443 is a standard best practice. However, certain web sites may
also require other ports to be opened.
Internal Connections
These services are typically used for connections within your organization’s network and your
Web Appliance(s), or between appliances themselves, if you have multiple appliances.
ConnectionProtocolServiceFunctionPort
Outbound from appliance to FTP
server
TCPFTPBackups using passive FTP21
Outbound from Web Appliance to
Management Appliance (if
collocated)
TCPSSHCentral configuration, status and
reporting
22
196 | Configuring Ports | Sophos Web Appliance