Skip to content

Ports and firewalls

The central service never connects to nodes. Nodes connect to it, and receive their configuration and commands in the answer to their heartbeat. A firewall between them only needs to let nodes reach the central service.

From Port Protocol What for
Browsers 5080 HTTPS The web console and its API.
Nodes 5080 HTTPS Enrollment, heartbeats, configuration, history.
Prometheus 5080 HTTPS /metrics, with a bearer token.
Update scripts 5080 HTTPS Draining, checking and resuming nodes, with an API token.
Load balancers 5080 HTTPS /health, without sign-in.

The port is the central Port setting (installer property HTTPPORT). See Central service settings.

To Port Protocol What for
SQL Server 1433 TDS The database. Named instances may use another port, or the SQL Browser (UDP 1434).
PostgreSQL 5432 PostgreSQL The database.
Identity provider 443 HTTPS Console sign-in with OpenID Connect.
Domain controllers Kerberos and LDAP Windows sign-in, and group membership.
SMTP server 25 (as set) SMTP, optionally STARTTLS Alert and report emails.
Webhook 443 HTTPS Alert notifications.
HL7 status update receivers as set MLLP, optionally TLS Worklist order status updates.
Syslog server 514 UDP or TCP, 6514 TLS Syslog The log, when set.
OpenTelemetry collector 4317 (gRPC) or 4318 (HTTP), as set OTLP over HTTP or HTTPS Metrics, traces and logs, when set.
api.github.com (or UpdateFeedUrl) 443 HTTPS Once a day: whether a newer release is out (Settings › Check daily for a newer release).
From Port Protocol What for
Senders (modalities, PACS, archives) 11112 DICOM Storage, verification, storage commitment, query/retrieve, worklist, MPPS. Settings › Listen ports.
Senders none by default (2762 is usual) DICOM over TLS The same, over TLS. Settings › TLS ports.
Archives the node retrieves from by C-MOVE, destinations returning storage commitment results the listen ports DICOM They open an association back to the node.
Web viewers, cloud services, scripts none by default (8443 is usual) HTTPS (or HTTP) DICOMweb. Settings › DICOMweb port.
RIS, interface engine none by default (2575 is usual) MLLP, optionally TLS HL7 orders and patient updates. Settings › HL7 port.

A load balancer in front of the nodes forwards these ports to every node. See Adding nodes for load balancer settings.

To Port Protocol What for
The central service 5080 HTTPS Everything the node learns and reports.
Destinations as set (usually 104 or 11112) DICOM, optionally TLS Sending instances; storage commitment requests.
DICOMweb destinations 443 (as set) HTTPS STOW-RS.
Archives as set DICOM Query, retrieve and prior studies.
Storage commitment requesters 104 by default (as the source sets) DICOM Commitment results, on a new association.
HL7 destinations as set MLLP, optionally TLS Routed HL7 messages.
MPPS destinations as set DICOM Forwarded procedure steps.
AI services as set DICOM or DICOMweb Studies for analysis.
Identity provider 443 HTTPS Checking DICOMweb users’ tokens, when DICOMweb sign-in is set.
Syslog server 514 UDP or TCP, 6514 TLS Syslog The log, when set.
OpenTelemetry collector 4317 (gRPC) or 4318 (HTTP), as set OTLP over HTTP or HTTPS Traces, logs and runtime metrics, when set.

Ports below 1024 (such as 104) need the node to be given the capability to bind them, or a firewall rule that forwards the port. See Linux.