Network and ports
Allow only the connections required by your deployment and data flow. HyperFileLens Community uses the ports below by default and can map them to standard HTTPS through a reverse proxy.
Default ports
- Access
- Make available to users when needed
- Access
- User networks and the networks where Agents, Proxies, and Private Data Gateways run
- Access
- Management networks only
- Access
- Management networks only
Ports 11442–11445/TCP must be free on the Community host during installation. With a domain and reverse proxy, browsers and components can use the mapped 443/TCP endpoint instead. Use the address configured for your environment. The Public Data Gateway included with Community runs on the control-plane host and does not require another public port.
Connection paths
- Browsers
- Connect to the product console on
11443/TCPor its mapped port - Agent, Proxy, and Private Data Gateway
- Connect over HTTPS/WSS on
11443/TCPor its mapped port for registration, status reporting, and job control - Community host
- Uses
443/TCPto reach GitHub, container registries, and Ubuntu package repositories during online installation and upgrades
- Object storage
- The control plane and the Agent or Proxy running a job connect to the object-storage endpoint. Use the configured endpoint port; HTTPS normally uses
443/TCP - NAS
- The Proxy connects to SMB on
445/TCPor NFS on2049/TCP - Proxy storage from another host
- Allow backup hosts or Private Data Gateways to reach
51515–52014/TCPon the Proxy when they need its attached NAS or local storage
- Backup repository
- A Private Data Gateway reads the selected snapshot from object storage or through the Proxy attached to NAS or local storage
- AI model service
- Insights connects to the configured model endpoint. Use the endpoint's configured port; HTTPS normally uses
443/TCP
Agents, Proxies, and Private Data Gateways initiate their own connections to the control plane, so they normally do not need inbound access from it. Open 51515–52014/TCP on a Proxy only when another backup host or Private Data Gateway must reach storage attached to that Proxy.
Configuration guidelines
- Open only the ports required for your connection paths and restrict access to the appropriate source networks.
- Limit
11444/TCPand11445/TCPto management networks. Allow Proxy ports51515–52014/TCPonly from Agents or Private Data Gateways that require cross-host repository access. - Object-storage endpoints must be reachable, but buckets do not need to be public. Use dedicated credentials with the minimum required permissions.
- Keep TLS verification enabled where possible. Do not solve connectivity problems by permanently disabling verification or opening unrestricted firewall access.
- After changing network policy, confirm that components are online and target storage is reachable, then test backup, restore, and Insights.

