Using Enhance with an External Firewall

When setting up Enhance with an external firewall, ensure the following ports are allowed based on the roles assigned to your servers. If a server has multiple roles, enable all relevant ports for seamless operation and customer access.

General Firewall Configuration Tips

  • Allow all ports from your control panel server's IP and between servers within your Enhance cluster.
    • This is essential for internal RPCs, which use ephemeral ports.

Required Ports by Role

Application Role

  • 80, 443*: Web traffic (HTTP/HTTPS)
  • 22: SSH (admin and customer access)
  • 21: FTP
  • 30000-31000 UDP: Passive mode FTP
  • Optional: If using LiteSpeed with HTTP/3 (QUIC), allow 443 UDP.

Database Role

  • 3306: MySQL/MariaDB

Email Role

  • 143, 110: IMAP and POP3 (non-secure)
  • 993, 995: IMAP and POP3 (secure)
  • 25, 587, 465: SMTP (non-secure and secure)

DNS Role

  • 53 UDP and TCP: DNS queries

Configure your firewall according to these guidelines to ensure uninterrupted operation of Enhance services.

Was this answer helpful? 0 Users Found This Useful (0 Votes)