Firewall ports for cloud management gateway

Sachin.Panchal 21 Reputation points
2021-02-11T13:31:34.817+00:00

According to MS article https://learn.microsoft.com/en-us/mem/configmgr/core/clients/manage/cmg/data-flow?source=docs#required-ports The firewall ports requirements are given, however I could not get the details about the Server column ( which is destination). Can someone tell me what should i mention(Ip address) in destination(Server Column) for both the services (Azure & CMG service)

Client Protocol Port Server Description
Service connection point HTTPS 443 Azure CMG deployment
CMG connection point TCP-TLS 10140-10155 CMG service Preferred protocol to build CMG channel Note 1

Microsoft Configuration Manager
0 comments No comments
{count} votes

2 answers

Sort by: Most helpful
  1. Pa_D 1,071 Reputation points
    2021-02-12T01:18:26.077+00:00

    Usually 443 is open.
    CMG service is nothing but CMG VM.

    This video may help
    https://www.youtube.com/watch?v=FfMfw4dDq5o (go to 51.59 minutes in the video, that talks about ports)


  2. Simon Ren-MSFT 29,956 Reputation points Microsoft Vendor
    2021-02-12T06:50:09.197+00:00

    Hi,

    Thanks for posting in Microsoft MECM Q&A forum.

    We do not need to open any inbound ports to your on-premises network. The SCCM service connection point and CMG connection point initiate all communication with Azure and the CMG. These two site system roles must be able to create outbound connections to the Microsoft cloud.

    1. The service connection point connects to Azure over HTTPS port 443.
    2. The CMG connection point connects to the CMG in Azure over TCP-TLS or HTTPS. It holds the connection open and builds the channel for future two-way communication.
    3. The client connects to the CMG over HTTPS port 443.
    4. The CMG forwards the client communication over the existing connection to the on-premises CMG connection point. You don’t need to open any inbound firewall ports.
    5. The CMG connection point forwards the client communication to the on-premises management point and software update point.

    For more information, please refer to: How to Setup Co-Management – Firewall Ports Proxy Requirements

    Thanks for your time.

    Best regards,
    Simon


    If the response is helpful, please click "Accept Answer" and upvote it.
    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.