Communication ports used for ADC, ADM

Communication ports used for ADC, ADM

book

Article ID: CTX462403

calendar_today

Updated On:

Description

Customer's security team has scanned unusual traffic originated from SNIP from ports 4899,12345 etc..
Customer wanted to investigate on this.


Instructions

We verified the traces and the destination ports were 5557, 53 which was used for ADM analytics communication and DNS.
Source port will be random TCP ports and destination ports matters.

Citrix ADC
SourceDestinationTypePortDetails
Citrix ADC SNIPCitrix ADMUDP4739For AppFlow communication
  SNMP161, 162To send SNMP events
  Syslog514To receive syslog messages in Citrix ADM
  TCP5557, 5558For logstream communication from Citrix ADC to Citrix ADM.
 DNS ServerTCP, UDP53DNS name resolution


Citrix ADM
SourceDestinationTypePortDetails
Citrix ADC SNIPCitrix ADMTCP5563To receive ADC metrics (counters), system events, and Audit Log messages from Citrix ADC instance to Citrix ADM
  TCP5557, 5558For logstream communication (for Security Insight, Web Insight, and HDX Insight) from Citrix ADC
  UDP162To receive SNMP events from Citrix ADC
  UDP4739To receive ADC analytics log data using IPFIX protocol
Citrix NSIPCitrix ADMUDP514To receive syslog messages from Citrix ADC ADM
Citrix ADMCitrix ADM AgentTCP443, 8443, 7443Port for communication between Citrix ADC agent and Citrix ADM

Issue/Introduction

This article provides an overview of common ports that are used by Citrix components and must be considered as part of networking architecture, especially if communication traffic traverses network components such as firewalls or proxy servers where ports must be opened to ensure communication flow. Not all ports need to be open, depending on your deployment and requirements.