---
title: Manage Firewall Rules
slug: manufacturing-connect-edge-v2/manage-firewall-rules
docTags: 
createdAt: 2023-11-20T18:32:12.936Z
---

You can manage firewall rules to open specific ports or port ranges for inbound communication by navigating to **System&#x20;**> **Network&#x20;**&#x61;nd clicking the **Firewall&#x20;**&#x74;ab.&#x20;

:::hint{type="info"}
**Notes**:&#x20;

- These firewall rules apply only to IPv4 traffic.&#x20;
- Only Admin users are able to add and edit firewall rules. See [Users](docId\:Tls9-yYfMMtuyr9lRmpPD) to learn more.&#x20;
:::

The **Firewall&#x20;**&#x70;ane allows you to do the following:

- Review what ports are being used by Manufacturing Connect Edge system components, applications, and containers.&#x20;
- Ensure that any DeviceHub drivers and Docker container applications are not running on conflicting ports.&#x20;
- Open ports and port ranges with appropriate protocol (TCP/UDP) for Docker applications, containers, and DeviceHub drivers.
- Manage and close ports as needed.&#x20;

You can review any firewall changes in **System&#x20;**> **Events**.&#x20;

The pane shows a summary of what ports are currently open.&#x20;

![](https://api.archbee.com/api/optimize/SSUUxKZUk9bFTEPNn_6Zo/SdOvWUEjDMhmxVl-N_GQa_image.png)

# List of Reserved Ports

There are some ports that cannot be used for firewall rules because they are reserved for system services.&#x20;

Review the list of reserved ports.&#x20;

| **Reserved Port or Port Range** | **System Service that Uses Port(s)**        |
| ------------------------------- | ------------------------------------------- |
| 21                              | FTP                                         |
| 22                              | SSH                                         |
| 80                              | HTTP                                        |
| 123                             | NTP                                         |
| 389                             | LDAP                                        |
| 443                             | Manufacturing Connect API                   |
| 636                             | LDAP with SSL                               |
| 1880                            | Manufacturing Connect Edge UI REST endpoint |
| 2121                            | FTP                                         |
| 4840                            | OPC UA                                      |
| 5353                            | mDNS                                        |
| 5355                            | LLMNR                                       |
| 8081-8199                       | REST API endpoints                          |
| 9081-9199                       | gRPC API endpoints                          |
| 8883                            | MQTT to Manufacturing Connect               |
| 51280                           | Manufacturing Connect Remote Access         |

# Add Port Rule

1. Navigate to **System&#x20;**> **Network&#x20;**&#x61;nd click the **Firewall&#x20;**&#x74;ab.&#x20;
2. Click **Add Rule**.
   The *Add Inbound Rule&#x20;*&#x64;ialog displays.
   ![](https://api.archbee.com/api/optimize/SSUUxKZUk9bFTEPNn_6Zo/0e-h3d5D0I0knXfUmIYjM_add-firewall-rule.png)
3. Configure the parameters for the firewall rule.
   - **Port or Port Range**: Enter a single port number or a range of port numbers separated by a hyphen (-).&#x20;
   - **Protocol**: Select **TCP&#x20;**(transmission control protocol) or **UDP&#x20;**(user datagram protocol).&#x20;
   - **Interface**: Select **eth0&#x20;**&#x6F;r **eth1**.&#x20;
   - (**Optional) Service Name or Description**: Enter a name for the rule.&#x20;
4. Click **Add**.&#x20;
   The new rule displays on the pane.&#x20;

# Manage Port Rules

To manage port rules, click the **Action menu&#x20;**&#x66;or a rule.&#x20;

![](https://api.archbee.com/api/optimize/SSUUxKZUk9bFTEPNn_6Zo/0Z198HqzF9mnOPGNsEUQx_image.png)

- **Edit**: Update the rule.&#x20;
- **Delete**: Remove the rule and close the port or port range.&#x20;

