Standart Ports
Standart Ports
Standart Ports
Marcelo Zanata
Intracluster Ports Between CUCMs
Des Port
Purpouse
Endpoint
CUCM
CUCM
RTMT
CUCM (DB)
CUCM (DB)
CUCM (DB)
CUCM (DB)
Cisco Extended
CUCM (DB)
Functions (QRT)
CUCM
CUCM
CUCM (RIS)
CUCM (RIS)
CUCM
CUCM (RIS)
(RTMT/AMC/SOAP)
CUCM (DRF)
CUCM (DRF)
CUCM (Tomcat)
CUCM (SOAP)
Endpoint
License Manager
514/udp
1090,1099/tcp
1500,1501/tcp
1515/tcp
2552/tcp
2551/tcp
2555/tcp
2556/tcp
4040/tcp
5007/tcp
5555/tcp
CUCM (RTMT)
CUCM (TCTS)
Ephemeral/tcp
CUCM (Tomcat)
CUCM (TCTS)
CUCM
CUCM (DB)
CUCM (SDL)
CUCM (SDL)
CUCM
CUCM (Tomcat)
CUCM (IPSec)
CUCM (RIS)
7000 then
Ephemeral
(Linux)/tcp
Certificate Manager 7070/tcp
CUCM (CDLM)
8001/tcp
CUCM (SDL)
8002/tcp
CUCM (SDL)
8003/tcp
CMI Manager
8004/tcp
CUCM (Tomcat)
8005/tcp
CUCM (IPSec)
8500/tcp,udp
CUCM (RIS)
8888-8889/tcp
This port is used for communication between Cisco Trace Collection Tool Service and Cisco Trace
Collection servlet.
Certificate Manager service
Client database change notification
Intracluster communication service
Intracluster communication service (to CTI)
Intracluster communication between CUCM and CMI Manager
Internal listening port used by Tomcat shutdown scripts
Intracluster replication of system data by IPSec Cluster Manager
RIS Service Manager status request and reply
Des Port
Purpouse
CUCM
Endpoint or
Gateway
CUCM
SNMP Server
SNMP Server
CUCM
7
Endpoint
Endpoint
22/tcp
CUCM (DNS Server)
Ephemeral/udp
DNS Server
CUCM (DHCP
67/udp
Server)
DHCP Server
68/udp
69, 6969, then
CUCM
Ephemeral/udp
NTP Server
123/udp
CUCM
161/udp
CUCM
199/tcp
CUCM
CUCM
6161/udp
CUCM
CUCM
6162/udp
CUCM
Centralized TFTP
CUCM
SNMP Server
CUCM
CUCM
Alternate TFTP
CUCM
CUCM
CUCM
6666/udp
6970/tcp
7161/tcp
7999/tcp
9050/tcp
CUCM
CUCM
61441/udp
CUCM
CUCM
Ephemeral
Endpoint
Internet Control Message Protocol (ICMP) This protocol number carries echo-related traffic. It does
not constitute a port as indicated in the column heading.
Secure FTP service, SSH access
CUCM acting as a DNS server or DNS client
CUCM acting as a DHCP server (Note: Cisco does not recommend running DHCP server on CUCM.)
CUCM acting as a DHCP client
Trivial File Transfer Protocol (TFTP) service to phones and gateways
Network Time Protocol (NTP)
SNMP service response (requests from management applications)
Native SNMP agent listening port for SMUX support
Used for communication between Master Agent and Native Agent to process Native agent MIB
requests
Used for communication between Master Agent and Native Agent to forward notifications
generated from Native Agent
Netdump server
Centralized TFTP File Locator Service
Used for communication between SNMP Master Agent and subagents
Cisco Discovery Protocol (CDP) agent communicates with CDP executable
Service CRS requests through the TAPS residing on CUCM
CUCM applications send out alarms to this port via UDP. CUCM MIB agent listens on this port and
generates SNMP traps per CUCM MIB definition.
Provide trunk-based SIP services
Des Port
External Directory
Ephemeral/ tcp
CUCM
LDAP Server
3268/???
LDAP Server
389
Purpouse
Lightweight Directory Access Protocol
Microsoft AD Global Catalog Search
Subtree specific search (LDAP Default Port)
Phone
80/tcp
Port Usage
Marcelo Zanata
Configuration
page
Des Port
Purpouse
Phone
CUCM (TFTP)
69, Ephemeral/udp Trivial File Transfer Protocol (TFTP) used to download firmware and configuration files
Phone
CUCM
8080/tcp
Phone
Phone
CUCM
CUCM
2000/tcp
2443/tcp
Phone
CUCM (CAPF)
3804/tcp
Phone
CUCM
CUCM
Phone
CUCM
Phone
CUCM
Phone
IP VMS
Phone
Phone
IP VMS
Phone URLs for XML applications, authentication, directories, services, and so on. You can
configure these ports on a per-service basis.
Skinny Client Control Protocol (SCCP)
Secure Skinny Client Control Protocol (SCCPS)
Certificate Authority Proxy Function (CAPF) listening port for issuing Locally Significant Certificates
(LSCs) to IP phones
5060/tcp,udp
5061/tcp,udp
16384 - 32767/udp
Real-Time Protocol (RTP), Secure Real-Time Protocol (SRTP) (Note: CUCM only uses 24576-32767
although other devices use the full range.)
Des Port
Purpouse
47, 50, 51
Generic Routing Encapsulation (GRE), Encapsulating Security Payload (ESP), Authentication Header
(AH). These protocols numbers carry encrypted IPSec traffic. They do not constitute a port as
indicated in the column heading.
500/udp
CUCM
CUCM
Gateway
Gateway
CUCM
CUCM
Gateway
Gateway
CUCM (TFTP)
Gatekeeper
Gateway
CUCM
Gateway
CUCM
Gateway
CUCM
Gateway
Gateway
Gateway
Gateway
Gateway
Gateway
Gateway
CUCM
Gateway
CUCM
Gateway
CUCM
CUCM
CUCM
Gateway
CUCM
Gateway
CUCM
Gateway
CUCM
CUCM
CUCM
CUCM
CUCM
CUCM
CUCM
Gateway
CUCM
Gateway
CUCM
Gateway
69, then
Ephemeral/udp
1719/udp
1720/tcp
Ephemeral/tcp
Ephemeral/tcp
2000/tcp
2001 /tcp
2002 /tcp
2427/udp
2428/tcp
2727/tcp
5060/tcp ,udp
5061/tcp ,udp
Secure Session Initiation Protocol (SIPS) gateway and Intercluster Trunk (ICT)
16384 - 32767/udp
Real-Time Protocol (RTP), Secure Real-Time Protocol (SRTP) (Note: CUCM only uses 24576-32767
although other devices use the full range.)
Des Port
CTL Client
CUCM CTL Provider 2444/tcp
Unified Comm. App CUCM
2748/tcp
Unified Comm. App CUCM
2749/tcp
Unified Comm. App CUCM
2789/tcp
CUCM Assistant
CUCM
2912/tcp
Console
CUCM Attendant CUCM
1103 -1129/tcp
Console
CUCM Attendant CUCM
1101/tcp
Console
CUCM Attendant CUCM
1102/tcp
Console
CUCM Attendant CUCM
3223/udp
Console
CUCM Attendant CUCM
3224/udp
Console
CUCM Attendant CUCM
4321/udp
Console
Purpouse
Certificate Trust List (CTL) provider listening service in CUCM
CTI application server
TLS connection between CTI applications (JTAPI/TSP) and CTIManager
JTAPI application server
CUCM Assistant server (formerly IPMA)
CUCM Attendant Console (AC) JAVA RMI Registry server
RMI server sends RMI callback messages to clients on these ports.
Attendant Console (AC) RMI server bind port -- RMI server sends RMI messages on these ports.
CUCM Attendant Console (AC) server line state port receives ping and registration message from,
and sends line states to, the attendant console server.
CUCM Attendant Console (AC) clients register with the AC server for line and device state
information.
CUCM Attendant Console (AC) clients register to the AC server for call control.
Port Usage
Cisco Unified
Communications
App
Marcelo Zanata
CUCM
8443/tcp
AXL / SOAP API for programmatic reads from or writes to the CUCM database that third parties
such as billing or telephony management applications use.
Sender
Listener
CTL Client
2444/tcp
Sender
Listener
Dest Port
Endpoint
Endpoint
Endpoint
Endpoint
HP SIM
HP SIM
HP SIM
Compaq Mgmt
Agent
HP SIM
280/tcp
2301/tcp
2381/tcp
25375, 25376,
25393/udp
50000 - 50004/tcp
Sender
Listener
CUVA
Endpoint
Endpoint
CUVA
Endpoint