Deep Security Ports:
• 4118/HTTPS — Deep Security Agent/appliance port (inbound & outbound)
• 53/DNS over TCP or UDP – DNS Server port (outbound)
• 80/HTTP, 443/HTTPS – Smart Protection Network port, Smart Protection Server for
File Reputation (outbound)
• 123/NTP over UDP – NTP server port (outbound)
• 4119/HTTPS - Deep Security Manager GUI and API port. This port is also used to
download agent software when using deployment scripts (inbound & outbound)
• 4120/HTTPS – Deep Security Manager agent heartbeat port (inbound & outbound)
• 514/Syslog over UDP – SIEM or syslog server port. (outbound)
• 1433/SQL over TCP or UDP – Microsoft SQL database port (outbound)
Deep Security URLs:
• API Clients (Deep Security APIs)
o <manager FQDN or IP>:4119/webservice/Manger?WSDL
o <manager FQDN or IP>:4119/api
o <manager FQDN or IP>:4119/rest
• Legacy REST API clients (Deep Security legacy REST API’s Status Monitoring
API)
o <manager FQDN or IP>:4119/rest/status/manager/ping
• Deep Security Manager, Deep Security Agent/Appliance, Deep Security Relay
(Download Center or web server, Hosts software)
o files.trendmicro.com
• Deep Security Manager (Smart Protection Network – Certified Safe Software
Service, Used for event tagging with integrity Monitoring)
o grid-global.trendmicro.com
• Deep Security Agent/Appliance (Smart Protection Network - Global Census
Service, Used for behavior monitoring and predictive machine learning)
o ds2000-en-census.trendmicro.com
o ds2000-jp-census.trendmicro.com
• Deep Security Agent/Appliance (Smart Protection Network – Good File
Reputation Service, Used for behavior monitoring, predictive machine learning,
and process memory scans)
o deepsec20-en.gfrbridge.trendmicro.com
o deepsec20-jp.gfrbridge.trendmicro.com
• Deep Security Agent/Appliance (Smart Protection Network – Smart Feedback)
o ds200-en.fbs25.trendmicro.com
o ds200-jp.fbs25.trendmicro.com
• Deep Security Agent/Appliance (Smart Protection Network – Smart Scan Service)
o ds20.icrc.trendmicro.com
o ds20-jp.icrc.trendmicro.com
• Deep Security Agent/Appliance (Smart Protection Network – predictive machine
learning)
o ds20-en-b.trx.trendmicro.com
o ds20-jp-b.trx.trendmicro.com
o ds20-en-f.trx.trendmicro.com
o ds20-jp-f.trx.trendmicro.com
• Deep Security Agent/Appliance (Smart Protection Network – Web Reputation
Service)
o ds20-0-en.url.trendmicro.com
o ds20-0-jp.url.trendmicro.com
• Deep Security Manger (Help and support)
o help.deepsecurity.trendmicro.com
o success.trendmicro.com/product-support/deep-security
• Deep Security Manager (News feed)
o news.deepsecurity.trendmicro.com
o news.deepsecurity.trendmicro.com/news.atom
o news.deepsecurity.trendmicro.com/news_ja.atom
• Deep Security Relay, and Deep Security Agent/Appliance (Update Server, Hosts
security updates)
o iaus.activeupdate.trendmicro.com
o iaus.trendmicro.com
o ipv6-iaus.activeupdate.trendmicro.com
o ipv6-iaus.trendmicro.com
• Deep Security Manager (Telemetry service)
o telemetry.deepsecurity.trendmicro.com
• Deep Security Manager (Activation)
o flywheel.xdr.trendmicro.com
For reference: https://help.deepsecurity.trendmicro.com/20_0/on-premise/communication-
ports-urls-ip.html