Agents installed on the managed machines (end-user machines) need to have access to the hostnames/IP addresses and ports listed in this article.
Most of Acronis components utilize multiple IP addresses, you can find the exact IPs Acronis agents will use in your environment by running the
connection verification tool.
Alternatively, you can provide access to all the hostnames/IP addresses through ports listed below, depending on the respective datacenter.
Acronis Cyber Protect allows partners and customers to store data on partner-hosted Cloud storage. IP addresses of such storages are not listed in this article.
Please white-list those storage's IP range(s) to avoid having backup failures with network-related error messages (for example "Network Disconnected by timeout", described
here)
For successful installation and update of Acronis agents, white-list dl.managed-protection.com (Acronis Cyber Protect Cloud).
Connection to these hosts goes through TCP port 443 for current Agent versions; TCP port 80 might be additionally required for old versions.
SMTP server IP address applicable to all datacenters is listed
here.
For backup to Acronis Cloud storage, the entire IP range should be allowed (whitelisted) in the settings of the Firewall.
For partner-hosted storages, additionally allow the TCP port 40440.
The ports need to be open for outbound connections (except for the statistics server, which requires opening port 44445 for the inbound connection, details in the table).
| Abu Dhabi, United Arab Emirates |
|
Host | IP Addresses | Port (TCP) |
cloud.acronis.com
| 45.11.129.61
45.11.129.62
| 443 |
ae01-cloud.acronis.com | | 443, 8443, 7770-7800 |
branded-ae01-cloud.acronis.com | | |
agents-ae01-cloud.acronis.com | | 443 |
abgw-auh1-aci01.acronis.com | 5.195.206.15
5.195.206.12
5.195.206.11
5.195.206.14 5.195.206.13 | 44445 |
rs-ae01-cloud.acronis.com ae01-cloud.acronis.com | | 8443 |
cloud-wr-ae01.acronis.com ae01-cloud.acronis.com | | 5060 |
Find your storage addresses by checking Management Portal: Settings ->Locations->Storages | | 44445 |
For partner-hosted storages, additionally allow connection from the statistics server: | 5.195.206.3 | 44445 |
For partner-hosted storages, additionally allow connection from DC components for C2C backups: | | 44445 |
For DR P2S and S2S connections, additionally allow outbound connections: | 5.195.206.10 | |
The ports need to be open for outbound connections. The ports and hostnames are checked by an integrated Connection Verification Tool during installation. Later you can check them using the tool or by issuing the telnet command telnet [domain name or ip] [port]. For more information refer to
Using telnet to Test Open Ports. If they are accessible, you will see a blank screen after issuing the command:
Connection is successful
Ports usage
Ports 443 and 8443 are used for agent registration, data center selection, user authorization, certificate download, Web Restore, Backup and File Sync & Share management console access.
Ports 7770-7800 are used for agent communication with Management server (backup plans creation and applying, status reports, activity logging, etc.).
Local port 5905 is used by v.6.1 and older agents for agent communication with Management server.
Port 44445 is used for backup read-write operations.
You can additionally open 80 port for your convenience, so any HTTP requests from the browser will be redirected to https.
When backing up to Acronis Storage located at service provider, make sure storage can be accessed via IP address or DNS name you've assigned through port 44445.
Port 80 is also used for the remote update of agents.
Port 5060 is used for data transfer rate measurements (speedtests).
Several ports are used by Acronis agent to distribute agents updates within the local network thus with reduced utilization of Internet connections:
- Port 6888 is used by BitTorrent protocol for peer-to-peer updates over TCP and UDP. This is client connection port and also data transfer port.
- Port 6771 is a local peer discovery (LSD) port. LSD also opens up to 4 random UDP ports in 50k-65.5k range.
- Port 18018 is used for communication between peer-to-peer update components working in different modes: Updater (receives updates) and UpdaterAgent (distributes updates).
- Port 18019 is a local port, used for internal communication between different parts of Acronis Cyber Protect responsible for peer-to-peer updates.
- Port 1900 is a local port, used by UPnP and NAT-PMP services for dynamic port forwarding. These services ensure that BitTorrent traffic can reach the target agent, and that target agent can be matched with good peers for fast transfers. UPnP + NAT-PMP also opens up to 3 random UDP ports in 50k-65.5k range.
- BitTorrent uses a "distributed sloppy hash table" (DHT) for storing peer contact information for "trackerless" torrents. In effect, each peer becomes a tracker. The protocol is based on Kademila and is implemented over UDP. DHT + peer announcing mechanism opens up to 4 random UDP ports in 50k-65.5k range.
Note: Starting from the 22.09 release, the backup agent gathers certain network statistics, including end-to-end network latency, network latency per Hop in traceroute, TCP_info, and backup/restore operation info.
The backup agent does not collect this information within its own code, and instead spawns an external tool (ping and tracetroute). As a result, the required ports will depend on the particular operating system and traceroute implementation. For example, on Unix-like operating systems, traceroute sends, by default, a sequence of User Datagram Protocol (UDP) packets, with destination port numbers ranging from 33434 to 33534.