Firewall ports and protocols

The following table contains ports and protocols that must be allowed by the firewall of the GFI EventsManager host:

Port Protocols Description
135 UDP and TCP

Target machines use this port to publish information regarding available dynamic ports. GFI EventsManager uses this information to be able to communicate with the target machines.

139 and 445 UDP and TCP

Used by GFI EventsManager to retrieve the event log descriptions from target machines.

162 UDP and TCP

Used by GFI EventsManager to receive SNMP traps. Ensure that this port is open on the machine where GFI EventsManager is installed.

514 UDP and TCP Used by GFI EventsManager to receive SYSLOG messages.
1433 UDP and TCP

Used by GFI EventsManager to communicate with the SQL Server® database backend. Ensure that this port is enabled on Microsoft® SQL Server® and on the machine where GFI EventsManager is installed.

1521 UDP and TCP

Used to collect Oracle Server audit logs. Port 1521 is the default port for this connection. If the port is changed manually in the Oracle Listener’s configuration, adjust firewall settings accordingly.

49153 UDP and TCP Used by GFI EventsManager to collect events from event sources with Microsoft® Windows® Vista or Microsoft® Windows® 7.

Firewall permissions

The following list contains permissions that must be allowed by the firewall of the GFI EventsManager host:

For more information refer to Configuring Third-Party components.

Antivirus exceptions

If an antivirus application installed on the computer where GFI EventsManager is running, make sure that:

  • Traffic is not blocked on the ports in use by GFI EventsManager.
  • esmui.exe and esmproc.exe are allowed access through the firewall(s).
  • GFI EventsManager folders are excluded from real-time antivirus scanning.