GravityZone Cloud Instance 2
This article provides all the ports and addresses associated with the GravityZone Cloud Instance 2 (cloud.gravityzone.bitdefender.com).
Web Console
Inbound
Port | Source / Destination | Purpose |
80 (HTTP) | Any | Access to the Control Center web console; it redirects to 443. |
443 (HTTPS) | Any | Access to the Control Center web console. |
cloud-wbs.gravityzone.bitdefender.com | Communication between GravityZone and microservices. |
Outbound
Port | Source / Destination | Purpose |
443 | cloud-wbs.gravityzone.bitdefender.com | Communication between GravityZone and microservices. |
Security Agent (BEST, BEST Legacy, Endpoint Security)
Inbound
Port | Source / Destination | Purpose |
135 (RPC) | Any | Deployment through Relay. |
137, 138, 139 (NetBIOS) | Any | Deployment through Relay. |
Outbound
Port | Source / Destination | Purpose |
389 (LDAP) | Active Directory Domain Controller | Integration with Active Directory (only for the endpoint with the role of Active Directory Integrator). |
636 (LDAPS) | ||
3268 | Domain Controller Global Catalog | |
3269 | ||
7074 | Relay agent (if available) | Required for downloading installation packages from the Relay agent, in the deployment phase. Used for product and security content updates. Communication messages received from endpoints linked to the Relay agent. |
7076 | Bitdefender Global Protective Network | Encrypted communication messages (when the Relay agent is used as a proxy). |
7079 | Relay agent (if available) | Required for downloading installation packages from the Relay agent, in the deployment phase. Used for product and security content updates. Used for update staging. |
443 | cloud.gravityzone.bitdefender.com | Downloading installation packages during deployment (Setup Downloader). |
cloud-ecs.gravityzone.bitdefender.com | The link between the security agents and Communication Server. | |
us-lurker-input.gravityzone.bitdefender.com | The EDR traffic sent by security agent. | |
cloud-sens.gravityzone.bitdefender.com | Communication between GravityZone and the vCenter server integrator. | |
upgrade.bitdefender.com | Downloading updates from the online Bitdefender Update Servers (the official repository) over an encrypted channel. | |
*.nimbus.bitdefender.net Or you can exclude all the addresses below instead: nimbus.bitdefender.net mclb-gcp.nimbus.bitdefender.net eu.nimbus.bitdefender.net us.nimbus.bitdefender.net elb-fra-gcp.nimbus.bitdefender.net elb-ned-gcp.nimbus.bitdefender.net elb-nvi-gcp.nimbus.bitdefender.net elb-ore-gcp.nimbus.bitdefender.net elb-iow-gcp.nimbus.bitdefender.net elb-tky-gcp.nimbus.bitdefender.net | Antimalware, antiphishing and content control scanning with Bitdefender Global Protective Network. | |
update-cloud.2d585.cdn.bitdefender.net | Downloading signature and product updates from the online Bitdefender Update Servers (the official repository) over an encrypted channel. | |
download.bitdefender.com | Downloading product updates from the online Bitdefender Update Servers (the official repository) over an encrypted channel. | |
ingestors-us.bmdr.bitdefender.com | Traffic between the security agent and the Bitdefender MDR communication server. | |
cloud-wbs-endpoints.gravityzone.bitdefender.com | Used by Remote shell and Live search when customers use MITM solutions that decrypt traffic or perform certificate pinning between endpoints and GravityZone. | |
us-nvi-support-tool01.s3.us-east-1.amazonaws.com | Used for remote troubleshooting when collecting logs and storing them in the Bitdefender Cloud storage location. | |
lc-bootstrap-us.cirrus.gravityzone.bitdefender.com | Communication between the security agent and GravityZone Cloud Services. | |
22, 445 (SSH & SMB) | Any | Detects endpoints in the local network. |
53 (DNS) | DNS Server | Internal use for DNS queries. |
88 (Kerberos) | Active Directory Domain Controller | Active Directory integration for Linux endpoints. |
389, 636 (LDAP & LDAPS) | Active Directory Domain Controller | Active Directory integration. |
Kubernetes Cluster Agent
Outbound
Port | Source/Destination | Purpose |
|---|---|---|
443 | cnapp-api-us.cirrus.gravityzone.bitdefender.com | The link between Kubernetes Cluster Agent and the GravityZone Control Center |
cloud-ecs.gravityzone.bitdefender.com | The link between Kubernetes Cluster Agent and the Communication Server | |
nimbus.bitdefender.net us.nimbus.bitdefender.net | The link between Kubernetes Cluster Agent and the Bitdefender Global Protective Network |
Relay Agent
Inbound
Port | Source / Destination | Purpose |
7074 | Security agent | Communication messages (such as settings and events) received from endpoints linked to the Relay agent. Used for product and security content updates. |
7076 | Bitdefender Global Protective Network | Encrypted communication messages proxied from connected endpoints to Bitdefender Global Protective Network. |
7079 | Security agent | Used for product and security content updates. Used for update staging. |
Outbound
Port | Source / Destination | Purpose |
389 | Active Directory Domain Controller | Integration with Active Directory (only for the endpoint which has the role of Active Directory Integrator). |
7074 | Relay agent( | Downloading installation packages from another Relay agent, in the deployment phase. Communication messages received from endpoints linked to the Relay agent |
7076 | Bitdefender Global Protective Network | Encrypted communication messages received from endpoints linked to the Relay agent. |
443 | cloud.gravityzone.bitdefender.com | Downloading installation packages during deployment (Setup Downloader) |
cloud-ecs.gravityzone.bitdefender.com | Link between the Relay agent and Communication Server. | |
upgrade.bitdefender.com | Downloading updates from the online Bitdefender Update Servers (the official repository) over an encrypted channel | |
*.nimbus.bitdefender.net Or you can exclude instead all the addresses below: nimbus.bitdefender.net mclb-gcp.nimbus.bitdefender.net eu.nimbus.bitdefender.net us.nimbus.bitdefender.net elb-fra-gcp.nimbus.bitdefender.net elb-ned-gcp.nimbus.bitdefender.net elb-nvi-gcp.nimbus.bitdefender.net elb-ore-gcp.nimbus.bitdefender.net elb-iow-gcp.nimbus.bitdefender.net elb-tky-gcp.nimbus.bitdefender.net | Antimalware, antiphishing, and content control scanning with Bitdefender Global Protective Network. | |
download.bitdefender.com | Downloading installation packages before deployment from the GravityZone Control Center. | |
update-cloud.2d585.cdn.bitdefender.net | Downloading updates from the online Bitdefender Update Servers (the official repository) over an encrypted channel | |
ingestors-us.bmdr.bitdefender.com | Traffic between the Relay agent and the Bitdefender MDR communication server. | |
us-lurker-input.gravityzone.bitdefender.com | Encrypted communication messages proxied from connected endpoints to Bitdefender EDR communication server. |
Security Server (Multi-Platform)
Inbound
Port | Source / Destination | Purpose |
1344 | Any | Used by the Security for Storage protection layer to communication between NAS devices compliant with ICAP and the Security Server. |
6379 | Security Server | Allows traffic between Security Servers. |
7081 | Any | Antimalware traffic scanning sent by the Security Agent. |
7083 | Any | Antimalware traffic scanning sent by the Security Agent over SSL. |
Outbound
Port | Source / Destination | Purpose |
443 | *.nimbus.bitdefender.net Or you can exclude all the addresses below instead: nimbus.bitdefender.net mclb-gcp.nimbus.bitdefender.net eu.nimbus.bitdefender.net us.nimbus.bitdefender.net elb-fra-gcp.nimbus.bitdefender.net elb-ned-gcp.nimbus.bitdefender.net elb-nvi-gcp.nimbus.bitdefender.net elb-ore-gcp.nimbus.bitdefender.net elb-iow-gcp.nimbus.bitdefender.net elb-tky-gcp.nimbus.bitdefender.net | Periodical verification of antimalware detections with Bitdefender Global Protective Network. |
upgrade.bitdefender.com | Downloading updates from the online Bitdefender Update Servers (the official repository) over an encrypted channel. | |
*.cdn.bitdefender.net | Downloading updates from the online Bitdefender Update Servers (the official repository) over an encrypted channel. | |
cloud-ecs.gravityzone.bitdefender.com | The link between the Security Server and the Communication Server. | |
download.bitdefender.com | Downloading updates. | |
us-nvi-support-tool01.s3.us-east-1.amazonaws.com | Used for remote troubleshooting when collecting logs and storing them in the Bitdefender Cloud storage location. |
XDR Network Sensor Virtual Appliance
Inbound
Port | Source | Purpose |
22 | Any | SSH connections (optional). |
Outbound
Port | Destination | Purpose |
443 | *.nimbus.bitdefender.net Or you can exclude all the addresses below instead: nimbus.bitdefender.net mclb-gcp.nimbus.bitdefender.net eu.nimbus.bitdefender.net us.nimbus.bitdefender.net elb-fra-gcp.nimbus.bitdefender.net elb-ned-gcp.nimbus.bitdefender.net elb-nvi-gcp.nimbus.bitdefender.net elb-ore-gcp.nimbus.bitdefender.net elb-iow-gcp.nimbus.bitdefender.net elb-tky-gcp.nimbus.bitdefender.net | Periodical verification of detections with the Bitdefender Global Protective Network. |
*.cdn.bitdefender.net download.bitdefender.com | Download product updates. | |
cloud-ecs.gravityzone.bitdefender.com | The link between the Security Server and the Communication Server. | |
us-nvi-support-tool01.s3.us-east-1.amazonaws.com | Used for remote troubleshooting when collecting logs and storing them in the Bitdefender Cloud storage location. | |
us-lurker-input.gravityzone.bitdefender.com | The XDR NSVA detections sent by the product. | |
7074 | Relay agent (if available) | Used for product and security content updates. |
7079 | Relay agent (if available) | Used for product and security content updates. |
Sandbox Analyzer
Inbound and outbound
Port | Source / Destination | Purpose |
443 | sandbox-portal-us.gravityzone.bitdefender.com | Allows communication between the endpoint and the Sandbox Analyzer Portal. |
Network Attack Defense
Inbound and outbound
Port | Source / Destination | Purpose |
8887 (TCP) | Any | Opened with BEST for Linux to enable Network Attack Defense. If port 8887 is used by another application or blocked by a firewall, Network Attack Defense will not receive traffic. |
Security Data Lake
Outbound
Port | Source / Destination | Purpose |
443 | us-sdl-tenantid.datainsights.gravityzone.bitdefender.com | Access to the Security Data Lake web console. |
13301,13302 | ingest-us-sdl-tenantid.datainsights.gravityzone.bitdefender.com | Communication messages received from the Security Data Lake forwarder to Security Data Lake receiver. |
GravityZone Identity Provider
Inbound
Port | Source / Destination | Purpose |
443 | nexus-us.gravityzone.bitdefender.com | Bitdefender's own SAML SSO Identity Provider, that allows GravityZone users to login via single sign-on to GravityZone and other Bitdefender services (like MDR, Intellizone). |
(*) Since the relay is an update server that needs to listen on a port at all times, Bitdefender provides a mechanism able to automatically open a random port on localhost (127.0.0.1), so that the update server can receive proper configuration details. The update server tries to open the 7075 port to listen on localhost. If 7075 port is unavailable, the update server will search for another port that is free (in the range of 1025 to 65535) and successfully bind to listen on localhost.
Port 7074 must be open for deployment through Bitdefender Endpoint Security Tools Relay to work.
Note
To ensure secure communication between GravityZone Control Center and the endpoints, create a firewall rule that whitelists the web addresses required to verify the server certificate revocation. The rule should whitelist all the web addresses that contain digicert.com.
Example of web addresses the rule should match:
http://crl3.digicert.comhttp://crl4.digicert.comhttp://ocsp.digicert.com