TCP/UDP ports used by GE Products - White Listing
What Common Licensing URL should be whitelisted?
Licensing will try and communicate to https://*.flexnetoperations.com on ports 80 and 443.
In general GE recommends having a policy that will “whitelist” traffic to/from *.flexnetoperations.com.
Is the requested rule to Allow or Deny?
The rule should be set to "Allow".
What port/service or protocol will this traffic be using?
The licensing traffic uses port 80 and 443.
What protocol will be used (TCP or UDP)?
TCP is the protocol that will be used for the communications to the cloud servers.
What is the destination IP or subnet?
The destination address will be: *.flexnetoperations.com
The URL is provided as the IP address could change and GE does not have control over the IP address.
Will the traffic be bidirectional to the cloud?
Initiated internal only, not bidirectional (except in cases where license operations are done - returned/refresh/activated).
Does Advantage Licensing need to maintain internet access?
No, internet access is only needed for initial activation, license refresh and returns.
What is the Local License Server (LLS) default port number?
The local license server server port number is the port all clients will use to internally communicate to the local license server. The default port a Local License Server uses is 3333.
What communications (TCP/UDP) ports do GE Proficy products use?
For Cimplicity, please refer to :
https://digitalsupport.ge.com/communities/en_US/Article/What-Communications-TCP-UDP-Ports-Does-CIMPLICITY-UseB8442
For Plant Application, please refer to:
https://digitalsupport.ge.com/communities/en_US/Article/Proficy-Application-Suite-Port-Firewall-Requirements-Plant-Applications-SOA-Workflow-Vision-Historia
IP Port | Product | Usage | Modifiable |
53014 | iFIX | PDB Synchronization - UDP | No |
2010 | iFIX | iFIX Networking (Including FIX) - TCP | No |
13000 | Historian | WCF network to Data Archiver | Yes, KB16244 |
14000 | Historian | Historian Collector, ClientManager (Mirror System), Remote Collector Management Agent | Yes, KB16245 |
14001 | Historian | Data Archiver (Mirror System) | No |
14003 | Historian | DiagnosticsManager (Mirror System) | No |
491 | Webspace | Proficy WebSpace Server accepts connections | Yes, KB16055 |
492 | Webspace | “Proficy WebSpace Relay Client Manager Service" to centrally manage the WebSpace user count in a Relay Server configuration. | No |
2101 | IGS | Ethernet Encapsulation | Yes, Property window |
4840 | IGS | OPC UA Client - Local Discovery Service | No |
49310 | IGS | OPC UA Server | Yes, 000019505 |
3333 | Common Licensing | Used to connect Local License Server | Yes, 000033940 |
443 | Common Licensing | Used to connect GE Cloud License Server | No |
443 | WEB HMI | External GE Web HMI clients to connect to GE Web HMI. | Yes, 000033822 |
Related content
AutomaTech Inc.