Using Enhance with an External Firewall
When setting up Enhance with an external firewall, ensure the following ports are allowed based on the roles assigned to your servers. If a server has multiple roles, enable all relevant ports for seamless operation and customer access.
General Firewall Configuration Tips
- Allow all ports from your control panel server's IP and between servers within your Enhance cluster.
- This is essential for internal RPCs, which use ephemeral ports.
Required Ports by Role
Application Role
- 80, 443*: Web traffic (HTTP/HTTPS)
- 22: SSH (admin and customer access)
- 21: FTP
- 30000-31000 UDP: Passive mode FTP
- Optional: If using LiteSpeed with HTTP/3 (QUIC), allow 443 UDP.
Database Role
- 3306: MySQL/MariaDB
Email Role
- 143, 110: IMAP and POP3 (non-secure)
- 993, 995: IMAP and POP3 (secure)
- 25, 587, 465: SMTP (non-secure and secure)
DNS Role
- 53 UDP and TCP: DNS queries
Configure your firewall according to these guidelines to ensure uninterrupted operation of Enhance services.