FortiEDR
FortiEDR automates the protection against advanced threats, pre and post-execution, with real time orchestrated incident response functionality.
david_pereira
Staff & Editor
Staff & Editor
Article Id 409656
Description This article describes detailed information regarding the communication requirements between the FortiEDR components. 
Scope FortiEDR.
Solution

 

Component Destination TCP/IP Port Purpose
Collector Aggregator 8081 Registration and Status
Collector Core 555 Compressed OS metadata
Core Aggregator 8081 Registration status and Events
Core Threat Hunting Repository 443 Threat Hunting Capabilities
Core FortiEDR Reputation Service: reputation.ensilo.com:443 443 Check Reputation of Applications
Aggregator Manager 443 Events and Configurations
Admin PC Manager 443 GUI Access
Manager Syslog 6514 Syslog messages
Manager SMTP Server 587 eMail capabilities
Manager Threat Hunting Repository 443 Hash and file queries
Manager FortiEDR Cloud Service(FCS): cldsrv.ensilo.com:443
rbq.cldsrv.ensilo.com:443
443 Data to be sent to FCS

 

The table above shows the full network communication requirements for the FortiEDR solution. Those ports are configurable; however, it is convenient to leave them unchanged.