Cisco Unified Communications Manager TCP and UDP port usage
This chapter provides a list of the TCP and UDP ports that Cisco Unified Communications Manager release 9.0(1) uses for intracluster connections and for communication with external applications or devices. You will also find important information for the configuration of firewalls, Access Control Lists (ACLs), and quality of service (QoS) on a network when an IP Communications solution is implemented.
Cisco has not verified all possible configuration scenarios for these ports. If you are having configuration problems using this list, contact Cisco technical support for assistance.
Port references apply specifically to Cisco Unified Communications Manager Release 9.0(1). Some ports change from one release to another, and future releases may introduce new ports. Therefore, make sure that you are using the correct version of this document for the version of Cisco Unified Communications Manager that is installed.
While virtually all protocols are bidirectional, directionality from the session originator perspective is presumed. In some cases, the administrator can manually change the default port numbers, though Cisco does not recommend this as a best practice. Be aware that Cisco Unified Communications Manager opens several ports strictly for internal use.
Installing Cisco Unified Communications Manager software automatically installs the following network services for serviceability and activates them by default. Refer to Table 1 for details:
Cisco Log Partition Monitoring (To monitor and purge the common partition. This uses no custom common port.)
Cisco Trace Collection Service (TCTS port usage)
Cisco RIS Data Collector (RIS server port usage)
Cisco AMC Service (AMC port usage)
Configuration of firewalls, ACLs, or QoS will vary depending on topology, placement of telephony devices and services relative to the placement of network security devices, and which applications and telephony extensions are in use. Also, bear in mind that ACLs vary in format with different devices and versions.
Note
You can also configure Multicast Music on Hold (MOH) ports in Cisco Unified Communications Manager. Port values for multicast MOH are not provided because the administrator specifies the actual port values.
Intracluster communication between Cisco Extended Services for
Active/Backup determination
Unified CM (RIS)
Unified CM (RIS)
2555 / TCP
Real-time Information Services (RIS) database server
Unified CM (RTMT/AMC/SOAP)
Unified CM (RIS)
2556 / TCP
Real-time Information Services (RIS) database client for Cisco RIS
Unified CM (DRS)
Unified CM (DRS)
4040 / TCP
DRS Master Agent
Unified CM (Tomcat)
Unified CM (SOAP)
5007 / TCP
SOAP monitor
Unified CM (RTMT)
Unified CM (TCTS)
Ephemeral / TCP
Cisco Trace Collection Tool Service (TCTS) -- the back end service
for RTMT Trace and Log Central (TLC)
Unified CM (Tomcat)
Unified CM (TCTS)
7000, 7001, 7002 / TCP
This port is used for communication between Cisco Trace Collection
Tool Service and Cisco Trace Collection servlet.
Unified CM
Certificate Manager
7070 / TCP
Certificate Manager service
Unified CM (DB)
Unified CM (CDLM)
8001 / TCP
Client database change notification
Unified CM (SDL)
Unified CM (SDL)
8002 / TCP
Intracluster communication service
Unified CM (SDL)
Unified CM (SDL)
8003 / TCP
Intracluster communication service (to CTI)
Unified CM
CMI Manager
8004 / TCP
Intracluster communication between Cisco Unified Communications
Manager and CMI Manager
Unified CM (Tomcat)
Unified CM (Tomcat)
8005 / TCP
Internal listening port used by Tomcat shutdown scripts
Unified CM (Tomcat)
Unified CM (Tomcat)
8080 / TCP
Communication between servers used for diagnostic tests
Unified CM (IPSec)
Unified CM (IPSec)
8500 / TCP and UDP
Intracluster replication of system data by IPSec Cluster Manager
Unified CM (RIS)
Unified CM (RIS)
8888 - 8889 / TCP
RIS Service Manager status request and reply
Location Bandwidth Manager (LBM)
Location Bandwidth Manager (LBM)
9004 / TCP
Intracluster communication between LBMs
Unified CM [Dialed Number Analyzer (DNA) initializing server]
JNIWrapper server
30000 / TCP
Dialed Number Analyzer (DNA)
Port used by the server that handles DNA initialization.
JNIWrapper functions respond to requests that the DNA Java service sends.
Table 2 Common Service Ports
From (Sender)
To (Listener)
Destination Port
Purpose
Endpoint
Unified CM
7
Internet Control Message Protocol (ICMP) This protocol number
carries echo-related traffic. It does not constitute a port as indicated in the
column heading.
Unified CM
Endpoint
Unified CM
Endpoint
22 / TCP
Secure FTP service, SSH access
Endpoint
Unified CM (DNS Server)
Ephemeral / UDP
Cisco Unified Communications Manager acting as a DNS server or DNS
client
Note
Cisco recommends that Cisco Unified Communications Manager not
act as a DNS server and that all IP telephony applications and endpoints use
static IP addresses instead of hostnames.
Unified CM
DNS Server
Endpoint
Unified CM (DHCP Server)
67 / UDP
Cisco Unified Communications Manager acting as a DHCP server
Note
Cisco does not recommend running DHCP server on Cisco Unified
Communications Manager.
Unified CM
DHCP Server
68 / UDP
Cisco Unified Communications Manager acting as a DHCP client
Note
Cisco does not recommend running DHCP client on Cisco Unified
Communications Manager. Configure Cisco Unified Communications Manager with
static IP addresses instead.)
Endpoint or Gateway
Unified CM
69, 6969, then Ephemeral / UDP
Trivial File Transfer Protocol (TFTP) service to phones and
gateways
Endpoint or Gateway
Unified CM
6970 / TCP
Trivial File Transfer Protocol (TFTP) between master and proxy servers.
HTTP service from the TFTP server to phones and gateways.
Unified CM
NTP Server
123 / UDP
Network Time Protocol (NTP)
SNMP Server
Unified CM
161 / UDP
SNMP service response (requests from management applications)
CUCM Server SNMP Master Agent application
SNMP trap destination
162 / UDP
SNMP traps
SNMP Server
Unified CM
199 / TCP
Native SNMP agent listening port for SMUX support
Unified CM
DHCP Server
546 / UDP
DHCPv6. DHCP port for IPv6.
Unified CM
Serviceability
Location Bandwidth Manager (LBM)
5546 / TCP
Enhanced Location CAC Serviceability
Unified CM
Location Bandwidth Manager (LBM)
5547 / TCP
Call Admission requests and bandwidth deductions
Unified CM
Unified CM
6161 / UDP
Used for communication between Master Agent and Native Agent to
process Native agent MIB requests
Unified CM
Unified CM
6162 / UDP
Used for communication between Master Agent and Native Agent to
forward notifications generated from Native Agent
Unified CM
Unified CM
6666 / UDP
Netdump server
Centralized TFTP
Alternate TFTP
6970 / TCP
Centralized TFTP File Locator Service
Unified CM
Unified CM
7161 / TCP
Used for communication between SNMP Master Agent and subagents
SNMP Server
Unified CM
7999 / TCP
Cisco Discovery Protocol (CDP) agent communicates with CDP
executable
Unified CM
Unified CM
9050 / TCP
Service CRS requests through the TAPS residing on Cisco Unified
Communications Manager
Unified CM
Unified CM
61441 / UDP
Cisco Unified Communications Manager applications send out alarms
to this port through UDP. Cisco Unified Communications Manager MIB agent
listens on this port and generates SNMP traps per Cisco Unified Communications
Manager MIB definition.
Unified CM
Unified CM
Ephemeral
Provide trunk-based SIP services
Table 3 Ports Between Cisco Unified Communications Manager and LDAP
Directory
Cisco Unified Communications Manager only uses 24576-32767
although other devices use the full range.
Phone
IP VMS
Table 7 Signaling, Media, and Other Communication Between Gateways and Cisco
Unified Communications Manager
From (Sender)
To (Listener)
Destination Port
Purpose
Gateway
Unified CM
47, 50, 51
Generic Routing Encapsulation (GRE), Encapsulating Security
Payload (ESP), Authentication Header (AH). These protocols numbers carry
encrypted IPSec traffic. They do not constitute a port as indicated in the
column heading.
Unified CM
Gateway
Gateway
Unified CM
500 / UDP
Internet Key Exchange (IKE) for IP Security protocol (IPSec)
establishment
Unified CM
Gateway
Gateway
Unified CM (TFTP)
69, then Ephemeral / UDP
Trivial File Transfer Protocol (TFTP)
CUCM with Cisco Intercompany Media Engine (CIME) trunk
CIME ASA
1024-65535 / TCP
Port mapping service. Only used in the CIME off-path deployment
model.
Gatekeeper
Unified CM
1719 / UDP
Gatekeeper (H.225) RAS
Gateway
Unified CM
1720 / TCP
H.225 signaling services for H.323 gateways and Intercluster Trunk
(ICT)
Unified CM
Gateway
Gateway
Unified CM
Ephemeral / TCP
H.225 signaling services on gatekeeper-controlled trunk
Unified CM
Gateway
Gateway
Unified CM
Ephemeral / TCP
H.245 signaling services for establishing voice, video, and data
Unified CM
Gateway
Gateway
Unified CM
2000 / TCP
Skinny Client Control Protocol (SCCP)
Gateway
Unified CM
2001 / TCP
Upgrade port for 6608 gateways with Cisco Unified CM deployments
Gateway
Unified CM
2002 / TCP
Upgrade port for 6624 gateways with Cisco Unified CM deployments
Gateway
Unified CM
2427 / UDP
Media Gateway Control Protocol (MGCP) gateway control
Gateway
Unified CM
2428 / TCP
Media Gateway Control Protocol (MGCP) backhaul
--
--
4000 - 4005 / TCP
These ports are used as phantom Real-Time Transport Protocol (RTP)
and Real-Time Transport Control Protocol (RTCP) ports for audio, video and data
channel when Cisco Unified CM does not have ports for these media.
Gateway
Unified CM
5060 / TCP and UDP
Session Initiation Protocol (SIP) gateway and Intercluster Trunk
(ICT)
Unified CM
Gateway
Gateway
Unified CM
5061 / TCP and UDP
Secure Session Initiation Protocol (SIPS) gateway and Intercluster
Trunk (ICT)
RMI server sends RMI callback messages to clients on these ports.
Unified CM Attendant Console
Unified CM
1102 / TCP
Attendant Console (AC) RMI server bind port -- RMI server sends
RMI messages on these ports.
Unified CM Attendant Console
Unified CM
3223 / UDP
Cisco Unified Communications Manager Attendant Console (AC) server
line state port receives ping and registration message from, and sends line
states to, the attendant console server.
Unified CM Attendant Console
Unified CM
3224 / UDP
Cisco Unified Communications Manager Attendant Console (AC)
clients register with the AC server for line and device state information.
Unified CM Attendant Console
Unified CM
4321 / UDP
Cisco Unified Communications Manager Attendant Console (AC)
clients register to the AC server for call control.
Cisco recommends a value of 5620 for this port, but you can change
the value by executing the add ime vapserver or set ime vapserver port CLI
command on the Cisco IME server.
VAP protocol used to communicate to the Cisco Intercompany Media
Engine server.
Cisco Unified Communications App
Unified CM
8443 / TCP
AXL / SOAP API for programmatic reads from or writes to the Cisco
Unified Communications Manager database that third parties such as billing or
telephony management applications use.
Table 9 Communication Between CTL Client and Firewalls
From (Sender)
To (Listener)
Destination Port
Purpose
CTL Client
TLS Proxy Server
2444 / TCP
Certificate Trust List (CTL) provider listening service in an ASA
firewall