Skip to content

Network and ports ​

Allow only the connections required by your deployment and data flow. HyperFileLens Community uses the ports below by default and can map them to standard HTTPS through a reverse proxy.

Default ports ​

11442/TCPProduct website and documentation
Access
Make available to users when needed
11443/TCPProduct console and component connections
Access
User networks and the networks where Agents, Proxies, and Private Data Gateways run
11444/TCPPlatform operations and system administration
Access
Management networks only
11445/TCPInsights service administration
Access
Management networks only

Ports 11442–11445/TCP must be free on the Community host during installation. With a domain and reverse proxy, browsers and components can use the mapped 443/TCP endpoint instead. Use the address configured for your environment. The Public Data Gateway included with Community runs on the control-plane host and does not require another public port.

Connection paths ​

Control trafficControl plane
Browsers
Connect to the product console on 11443/TCP or its mapped port
Agent, Proxy, and Private Data Gateway
Connect over HTTPS/WSS on 11443/TCP or its mapped port for registration, status reporting, and job control
Community host
Uses 443/TCP to reach GitHub, container registries, and Ubuntu package repositories during online installation and upgrades
Data trafficBackup and restore
Object storage
The control plane and the Agent or Proxy running a job connect to the object-storage endpoint. Use the configured endpoint port; HTTPS normally uses 443/TCP
NAS
The Proxy connects to SMB on 445/TCP or NFS on 2049/TCP
Proxy storage from another host
Allow backup hosts or Private Data Gateways to reach 51515–52014/TCP on the Proxy when they need its attached NAS or local storage
Analysis trafficInsights
Backup repository
A Private Data Gateway reads the selected snapshot from object storage or through the Proxy attached to NAS or local storage
AI model service
Insights connects to the configured model endpoint. Use the endpoint's configured port; HTTPS normally uses 443/TCP

Agents, Proxies, and Private Data Gateways initiate their own connections to the control plane, so they normally do not need inbound access from it. Open 51515–52014/TCP on a Proxy only when another backup host or Private Data Gateway must reach storage attached to that Proxy.

Configuration guidelines ​

  • Open only the ports required for your connection paths and restrict access to the appropriate source networks.
  • Limit 11444/TCP and 11445/TCP to management networks. Allow Proxy ports 51515–52014/TCP only from Agents or Private Data Gateways that require cross-host repository access.
  • Object-storage endpoints must be reachable, but buckets do not need to be public. Use dedicated credentials with the minimum required permissions.
  • Keep TLS verification enabled where possible. Do not solve connectivity problems by permanently disabling verification or opening unrestricted firewall access.
  • After changing network policy, confirm that components are online and target storage is reachable, then test backup, restore, and Insights.