1、概述

1.1 说明

port list摘自citrix官方 kb:CTX101810

本文提供的端口,通过Citrix相关产品或组件使用到的端口而定,如果通信经过一些网络设备,如防火墙或代理服务器,端口必须打开以确保通信顺畅从而保证相关的产品或组件能正常工作。

1.2 包含的citrix产品或组件列表

CitrixCloud

NetScaler

NetScalerGateway

NetScalerSD-WAN

CommandCenter Server

NetScalerInsight Center

NetScalerMAS

StoreFront

XenMobile

PasswordManager/Single Sign-On

AppDNA7.x

CitrixOnline Products

CloudStack/CloudPlatform

CommonCitrix Communication Ports

EdgeSight

FederatedAuthentication Service

ProvisioningServices

SmartAuditor

StageManager

StorageLink

WorkflowStudio

XenAppPrior to Version 7.5

XenDesktop/XenApp7.5 and Later Versions

WorkspaceEnvironment Management (WEM)

XenServer

2Port List

SourceDestinationTypePortDetails
User DeviceStoreFront   ServerTCP80/443Connecting   to the Store or Receiver for Web site hosted on StoreFront server
StoreFront ServerDomain   ControllerTCP/UDP389LDAP   connection to query user-friendly name and email addresses
TCP/UDP88Kerberos 
TCP/UDP464Native   Windows authentication protocol to allow users change expired passwords
Microsoft SQL ServerTCP1433For   StoreFront 1.2 and earlier. TCP port used to connecting StoreFront and SQL   server to read/write application information to the subscription database.
You can use SQL database as an alternative to   the built-in ESE+Mesh from StoreFront 3.0.1 onwards.
StoreFront ServerTCPRandomly   selected unreserved port per service.Used   for Peer-to-peer Services (Credential Wallet, Subscriptions Store (1 per   Store). This service uses MS .Net NetPeerTcpBinding which negotiates a random   port on each server between the peers. Only used for communication within the   cluster.
Scroll down to the end of this table for   configuration of firewalls when you place StoreFront in its own network.
TCP808Used   for Subscription Replication Services. Not installed by default. Used to   replicate subscriptions between associated clusters
XenDesktop Controller, XenApp Controller,   XenMobileTCP80/443For   application and desktop requests.
NetScalerTCP8000For   Monitoring Service used by NetScaler load balancer.
NetScaler GatewayLDAP   ServerTCP636LDAP   SSL connection
TCP3268LDAP   connection to Global Catalog
TCP3269LDAP   connection to Global Catalog over SSL
TCP389LDAP   plain text
RADIUS ServerTCP80/8080/443Application/Desktop   Request via XML Service
TCP\UDP1813RADIUS   Accounting
TCP\UDP1645/1812RADIUS   connection
XenDesktop/XenApp ControllerTCP2598Access   to applications and virtual desktops by ICA/HDX with Session Reliability
Secure Ticketing AuthorityTCP80/8080/443Secure   Ticketing Authority (embedded into XML Service)
XenDesktop–Virtual Desktop/XenApp Worker ServerTCP1494Access   to applications and virtual desktops by ICA/HDX
TCP443Access   to applications and virtual
Desktops by ICA/HDX over SSL
TCP8008Access   to applications and virtual desktops by ICA/HDX from HTML5 Receiver
IP50IPSec   Encapsulating Security Protocol (ESP) traffic
StoreFrontTCP443Callback   URL to reach NetScaler  Gateway virtual server from StoreFront
NetScaler Gateway Plug-in×××/XenApp/XenDesktopUDP3108/3168/3188For ×××  tunnel with   secure ICA connections -Download
TCP/UDP3148
NetScaler GatewayXenDesktop–Virtual   Desktop/XenApp Worker ServerUDP3224-3324Access   to applications and virtual desktops with Framehawk





ControllerCitrix   XenServer Resource Pool MasterTCP80/443Communication   with XenServer infrastructure
Microsoft SCVMM ServerTCP8100Communication   with Hyper-V infrastructure
VMware vCenter ServerTCP443Communication   with vSphere infrastructure
Microsoft SQL ServerTCP1433Microsoft   SQL Server
TCP1434Microsoft   SQL Server.
Note: Named instance connection requires UDP   1434
Virtual DesktopTCP80XenDesktop   7 and later only. Controller initiates the connection when discovering local   applications or for gathering information about local processes,performance   data,etc.
UDP9Wakeon   LAN magic pocket (optional for Microsoft Configuration Manager Wakeon LAN)
TCP135Wake-up   proxy (optional for Microsoft Configuration Manager Wakeon LAN)
Microsoft System Center Configuration ManagerTCP135WMI   connection to ConfigMgr for Wakeon LAN
Director ServerVirtual   Delivery AgentTCP80Only   XenDesktop 5.6 and earlier: Communication between Director and Virtual   Delivery Agent Agent for WinRM1.1
TCP5985Only   XenDesktop 5.6 and earlier: Communication between Director and Virtual   Delivery Agent Agent for WinRM2.0
Desktop Director and Admin WorkstationVirtual   Delivery AgentTCP135Communication   between Desktop Director and Virtual Delivery Agent Agent for Remote   Assistance
3389

TCP389LDAP
Note: For the logon step, Desktop Director does   not contact the AD but does a local logon using the native Windows API–   LogonUser (which might internally be contacting the AD).
Endpoint (Receiver)Virtual   Delivery AgentTCP2598Access   to applications and virtual desktops by ICA/HDX with Session Reliability
TCP1494Access   to applications and virtual desktops by ICA/HDX
TCP443Access   to applications and virtual desktops by ICA/HDX over SSL
TCP8008Access   to applications and virtual desktops by ICA/HDX from HTML5 Receiver
UDP16500-16509Port   range for ICA/HDX audio
UDP3224-3324ICA/HDX   Framehawk
Virtual Delivery Agent (5.x and later)ControllerTCP80Used   by process WorkstationAgent.exe for communicating with Controller
Virtual Delivery Agent (previous versions)ControllerTCP8080Communication   between Desktop Delivery Controller and Virtual Desktop Agent
Virtual  Delivery AgentDomain   ControllerTCP3268Communication   between Virtual Delivery Agent Agent and Microsoft Global Catalog used during   the registration process in order to validate its list of configured

Director   ServerTCP80/443Access   to XenDesktop Director website
Admin WorkstationControllerTCP80/443When   using a locally installed Studio Console or the SDK to   directly access   the Controller. The following services listen on the Controller:
•    General brokering   functionality (BrokerService.exe)
•    ActiveDirectoryIdentity   Service (Citrix.ADIdentity.SdkWcfE ndpoint.exe)
•    Configuration Logging   Service
•    Configuration Service   (Citrix.Configuration.SdkWc fEndpoint.exe)
•    Delegated Admin Service
•    HostService   (Citrix.Host.SdkWcfEndpoi nt.exe)

•    MachineCreationService   (Citrix.MachineCreation.Sdk WcfEndpoint.exe)
•    MachineIdentityService   (Citrix.MachineIdentity.Sdk WcfEndpoint.exe)
•    License Configuration   Service (Citrix.LicensingConfig.Sdk WcfEndpoint.exe)

Virtual   DeliveryAgentTCP/UDPDynamically   allocated high-portWhen   initiating a Remote Assistance session from a Windows 7 machine to a Windows   Vista/ 7 Virtual Delivery
(49152-65535)
TCP3389When   initiating a Remote Assistance session from a Windows 7 machine to a   WindowsXP Virtual Delivery Agent
Endpoint (Receiver) (Internal)Virtual   Delivery AgentUDP3224-3324Access   to applications and virtual desktops with Framehawk
all   vmADTCP/UDP389
TCP135
TCP/UDP53
TCP445
TCP88
TCP49152-65535