Ports and services
This topic lists the network services and ports used by the device. The information helps network planners and cybersecurity professionals understand the device’s communication requirements, configure firewalls, and plan secure network architectures.
Those tables show the interfaces and services on OSI Level 2 and OSI Level 3 depending on the configuration of the product, through which the device can be accessed.
Note
Packet filtering
Packets are processed based on their importance for network operation. Due to various security-related packet filters, some packets directed to the CPU of the switch may be discarded. As a result, not all ICMP packets may reach the CPU and therefore may remain unanswered.
General interfaces and services
The following table shows the general interfaces and services that are available on all fieldbuses.
Note
For EtherCAT, these interfaces are also available but tunneled via Ethernet over EtherCAT (EoE).
Interface [1] |
Protocol Type |
Transport Protocol & Port |
Direction [2] |
Port state [3] |
Description |
|---|---|---|---|---|---|
Web client - WebUI and REST API |
HTTP |
TCP/80 |
IN / OUT |
Closed |
Access to user interface via username and password. Rate limiting with timeout is implemented. |
Web client - WebUI and REST API |
HTTPS (SSL/TLS) |
TCP/443 |
IN / OUT |
Open |
TLS v1.3. Secure transport and access to UI via username and password. Default: self-signed certificate. FW 1.4.0: customer can upload own certificate chain. Rate limiting with timeout is implemented. |
SNTP Client |
UDP |
UDP/123 |
IN |
Closed |
Activated via WebUI/REST API when configuring a time server. |
MQTT Client |
MQTT / MQTTS |
OS-dependent (e.g. 1883 / 8883) |
OUT |
Closed |
MQTT or MQTTS with TLS. Broker ports configurable (1883 / 8883 with TLS). Client port chosen by OS. MQTTS should be preferred. Communication is encrypted, but server/broker validation depends on configuration. FW 1.4.0: customer can upload certificates and enable broker validation. |
PROFINET
The table below shows the interfaces and services for PROFINET.
Interface / Service |
Protocol Type |
Transport Protocol & Port |
Direction [2] |
Port state [3] |
Description |
|---|---|---|---|---|---|
PROFINET RPC Server (PNIO) |
UDP |
UDP/34964 |
IN |
Open (Fixed) |
Main RPC server port. Receives connect/write/read/control calls from IO controller. |
PROFINET RPC Server (RPC) |
UDP |
UDP/49152 (per instance) |
IN |
Open (Fixed) |
Secondary RPC server port for parallel AR connections. |
PROFINET RPC Client |
UDP |
UDP/53248 (0xD000) |
OUT |
Open (Fixed) |
Local UDP binding for outgoing alarm notifications. |
SNMP Agent |
UDP |
UDP/161 |
IN |
Open |
Provides MIB-II and LLDP-MIB (IEEE 802.1AB + PROFINET) via SNMP. Required for PROFINET compliance (IEC 61158). |
PROFINET RT - Cyclic Data |
PROFINET RT |
EtherType 0x8892, Frame-ID 0x8000-0xBFFF |
IN / OUT |
Open (Fixed) |
Cyclic I/O data exchange between IO device and IO controller. |
PROFINET RTA - Alarms |
PROFINET RT |
EtherType 0x8892, Frame-ID 0xFC01 / 0xFE01 |
IN / OUT |
Open (Fixed) |
Acyclic alarm PDUs (RTA Class 1), raw Ethernet frames. |
PROFINET DCP - Configuration |
PROFINET DCP |
EtherType 0x8892, Frame-ID 0xFEFC-0xFEFF |
IN / OUT |
Open (Fixed) |
Device configuration and diagnostics. |
PROFINET LLDP - Topology |
LLDP |
EtherType 0x88CC |
IN / OUT |
Open (Fixed) |
Topology discovery via LLDP multicast. |
PROFINET MRP - Ring Redundancy |
MRP |
EtherType 0x88E3 |
IN / OUT |
Open (N/A) |
Media Redundancy Protocol for ring topologies. |
VLAN Tagging |
IEEE 802.1Q |
EtherType 0x8100 |
IN / OUT |
Open (Fixed) |
VLAN tagging required for prioritized PROFINET RT traffic. |
ARP / ACD |
ARP |
EtherType 0x0806 |
— |
Open (Fixed) |
Address resolution and collision detection. |
EtherNet/IP
The table below shows the interfaces and services for EtherNet/IP.
Interface / Service |
Protocol Type |
Transport Protocol & Port |
Direction [2] |
Port state [3] |
Description |
|---|---|---|---|---|---|
EtherNet/IP Encapsulation (TCP) |
CIP |
TCP/44818 |
IN |
Open (Fixed) |
TCP server for explicit messaging. |
EtherNet/IP Encapsulation (UDP) |
CIP |
UDP/44818 |
IN |
Open (Fixed) |
UDP server (broadcast/unicast). |
EtherNet/IP I/O |
CIP |
UDP/2222 |
IN |
Open (Fixed) |
Cyclic process data communication. |
Ethernet/IP LLDP |
LLDP |
— |
— |
N/A |
Layer 2 topology discovery. |
DHCP Client |
UDP |
UDP/68 |
IN |
Open |
Only active if DHCP mode enabled. |
BOOTP |
UDP |
UDP/68 |
— |
N/A |
Only active in BOOTP mode. |
ARP / ACD |
ARP |
EtherType 0x0806 |
— |
Open (Fixed) |
Address resolution and collision detection. |
Modbus
The table below shows the interfaces and services for Modbus.
Interface / Service |
Protocol Type |
Transport Protocol & Port |
Direction [2] |
Port state [3] |
Description |
|---|---|---|---|---|---|
Modbus |
TCP |
TCP/502 |
— |
Open (Fixed) |
Modbus communication. |
EtherCAT
The table below shows the interfaces and services for EtherCAT.
Interface / Service |
Protocol Type |
Transport Protocol & Port |
Direction [2] |
Port state [3] |
Description |
|---|---|---|---|---|---|
EtherCAT (AoE, EoE, CoE, cyclic) |
Layer 2 |
— |
— |
Open (N/A) |
All EtherCAT protocols operate on Layer 2. |
EtherCAT |
EtherCAT |
EtherType 0x88A4 |
IN / OUT |
Open (Fixed) |
EtherCAT datagrams. IoT protocols can be tunneled via EoE. |