Firewall port settings

Configure your firewall to allow the ports used by GFI MailEssentials.

Port Description
53 - DNS

Used by the following anti-spam filters:

  • IP DNS Blocklist
  • SpamRazer
  • URI DNS Blocklist
80 - HTTP

Used by GFI MailEssentials to download product patches and updates for:

  • SpamRazer
  • Anti-Phishing
  • Bayesian Analysis
  • Antivirus definition files
  • Trojan and executable scanner
  • Email Exploit engine

GFI MailEssentials downloads from the following locations:

  • meupdate.gfi.com
  • support.gfi.com
  • *.mailshell.net
  • *.rules.mailshell.net
  • spamrazer.gfi.com
  • db11.spamcatcher.net
  • gfi-downloader-137146314.us-east-1.elb.amazonaws.com
  • cdnupdate.gfi.com
  • cdnpatches.gfi.com

NOTE: GFI MailEssentials can also be configured to download updates through a proxy server. For more information refer to Proxy settings.

9090, 9091 - Remoting

These ports are used for inter-process communication. No firewall configuration is required to allow connections to or from the remoting ports since all the GFI MailEssentials processes run on the same server.

NOTE: Ensure that no other applications (except GFI MailEssentials) are listening on these ports. If other applications are using this ports, these ports can be changed. For more information refer to Remoting ports.

9095, 9096 - Multi-Server These TCP ports are used for communications between GFI MailEssentials servers that are joined to the Multi-Server network. Ensure that the master and all salve servers can communicate together via these ports.
389/636 - LDAP/LDAPS

This port is used in these scenarios:

  • Remote Active Directory mode - When the GFI MailEssentials server is not joined to an Active Directory domain, but retrieves the list of users from a remote Active Directory instance.
  • GFI Directory mode - When the GFI MailEssentials server is not joined to an Active Directory domain, but retrieves the list of users from GFI Directory instance.
  • Microsoft® Exchange environment - Required if the server running GFI MailEssentials does not have access to or cannot get list of users from Active Directory, for example, in a DMZ environment or other environments which do not use Active Directory.
  • Lotus Domino mail server environment - Required to get email addresses from Lotus Domino server.
  • Other SMTP mail server environments - Required to get email addresses from SMTP server.
61000 TCP port used for the communication between GFI MailEssentials and GFI Directory. If the GFI Directory is used, ensure that no other applications (except GFI MailEssentials) are listening on this port. This ports can be changed from the Switchboard. For more information refer to GFI Directory mode.