Ports and firewalls
The central service never connects to nodes. Nodes connect to it, and receive their configuration and commands in the answer to their heartbeat. A firewall between them only needs to let nodes reach the central service.
Connections the central service accepts
Section titled “Connections the central service accepts”| From | Port | Protocol | What for |
|---|---|---|---|
| Browsers | 5080 | HTTPS | The web console and its API. |
| Nodes | 5080 | HTTPS | Enrollment, heartbeats, configuration, history. |
| Prometheus | 5080 | HTTPS | /metrics, with a bearer token. |
| Update scripts | 5080 | HTTPS | Draining, checking and resuming nodes, with an API token. |
| Load balancers | 5080 | HTTPS | /health, without sign-in. |
The port is the central Port setting (installer property HTTPPORT). See
Central service settings.
Connections the central service makes
Section titled “Connections the central service makes”| To | Port | Protocol | What for |
|---|---|---|---|
| SQL Server | 1433 | TDS | The database. Named instances may use another port, or the SQL Browser (UDP 1434). |
| PostgreSQL | 5432 | PostgreSQL | The database. |
| Identity provider | 443 | HTTPS | Console sign-in with OpenID Connect. |
| Domain controllers | Kerberos and LDAP | Windows sign-in, and group membership. | |
| SMTP server | 25 (as set) | SMTP, optionally STARTTLS | Alert and report emails. |
| Webhook | 443 | HTTPS | Alert notifications. |
| HL7 status update receivers | as set | MLLP, optionally TLS | Worklist order status updates. |
| Syslog server | 514 UDP or TCP, 6514 TLS | Syslog | The log, when set. |
| OpenTelemetry collector | 4317 (gRPC) or 4318 (HTTP), as set | OTLP over HTTP or HTTPS | Metrics, traces and logs, when set. |
api.github.com (or UpdateFeedUrl) |
443 | HTTPS | Once a day: whether a newer release is out (Settings › Check daily for a newer release). |
Connections nodes accept
Section titled “Connections nodes accept”| From | Port | Protocol | What for |
|---|---|---|---|
| Senders (modalities, PACS, archives) | 11112 | DICOM | Storage, verification, storage commitment, query/retrieve, worklist, MPPS. Settings › Listen ports. |
| Senders | none by default (2762 is usual) | DICOM over TLS | The same, over TLS. Settings › TLS ports. |
| Archives the node retrieves from by C-MOVE, destinations returning storage commitment results | the listen ports | DICOM | They open an association back to the node. |
| Web viewers, cloud services, scripts | none by default (8443 is usual) | HTTPS (or HTTP) | DICOMweb. Settings › DICOMweb port. |
| RIS, interface engine | none by default (2575 is usual) | MLLP, optionally TLS | HL7 orders and patient updates. Settings › HL7 port. |
A load balancer in front of the nodes forwards these ports to every node. See Adding nodes for load balancer settings.
Connections nodes make
Section titled “Connections nodes make”| To | Port | Protocol | What for |
|---|---|---|---|
| The central service | 5080 | HTTPS | Everything the node learns and reports. |
| Destinations | as set (usually 104 or 11112) | DICOM, optionally TLS | Sending instances; storage commitment requests. |
| DICOMweb destinations | 443 (as set) | HTTPS | STOW-RS. |
| Archives | as set | DICOM | Query, retrieve and prior studies. |
| Storage commitment requesters | 104 by default (as the source sets) | DICOM | Commitment results, on a new association. |
| HL7 destinations | as set | MLLP, optionally TLS | Routed HL7 messages. |
| MPPS destinations | as set | DICOM | Forwarded procedure steps. |
| AI services | as set | DICOM or DICOMweb | Studies for analysis. |
| Identity provider | 443 | HTTPS | Checking DICOMweb users’ tokens, when DICOMweb sign-in is set. |
| Syslog server | 514 UDP or TCP, 6514 TLS | Syslog | The log, when set. |
| OpenTelemetry collector | 4317 (gRPC) or 4318 (HTTP), as set | OTLP over HTTP or HTTPS | Traces, logs and runtime metrics, when set. |
On Linux
Section titled “On Linux”Ports below 1024 (such as 104) need the node to be given the capability to bind them, or a firewall rule that forwards the port. See Linux.
