Uplivra horizontal light
Ports, computer sizes, security and what to prepare
September 2026

Uplivra IT and security checklist

For the IT and security team: what Uplivra connects to, what to open, what computer to use and what to prepare. Full guides: uplivra.com/docs.html.

Before you install

Computer sizes

ModeMinimumRecommended
Uplivra server (with a collector)
The central server: web interface, database and alerts, plus a collector for this site. Most businesses need only this.
2 CPU, 4 GB, 50 GB disk4 CPU, 8 GB, 100 GB disk
Collector
Checks devices at a site and reports to your Uplivra server.
2 CPU, 2 GB, 16 GB disk2 CPU, 4 GB, 32 GB disk
Log collector
Receives logs (syslog) and keeps them in its own encrypted storage. Best on its own computer with its own disk.
2 CPU, 4 GB, 250 GB disk4 CPU, 8 GB, 500 GB disk
Collector and log collector
Both on one computer. Fine for small sites; give logs their own disk.
4 CPU, 8 GB, 250 GB disk4 CPU, 16 GB, 1000 GB disk
MSP master collector
For managed service providers: customer collectors connect through this one to your Uplivra server.
8 CPU, 16 GB, 250 GB disk16 CPU, 32 GB, 500 GB disk
MSP router
An MSP master collector that also routes to customers (VRFs, BGP, NAT, firewall, IPsec tunnels, router pairs).
4 CPU, 8 GB, 64 GB disk8 CPU, 16 GB, 128 GB disk
Packet capture collector
Records the traffic from switch SPAN (mirror) ports all the time, so your Uplivra server can pull the packets from any moment. Needs 2 or more network ports: 1 for management, the others for SPAN. Licensed by your Uplivra server.
4 CPU, 8 GB, 500 GB disk8 CPU, 16 GB, 2000 GB disk

Security in brief

Ports and firewall rules

"In" means others connect to that computer. Run uplivra ports on an installed computer to print its own list.

Uplivra server (with its own collector)

The central server: web interface, database, alerts, plus a collector for its own site. Most businesses only need this.

DirectionProtocol and portWhoWhat forNeeded
InTCP 443People's browsers; every collector and MSP master collectorThe Uplivra web interface, and collectors reporting results and fetching their checks (HTTPS)Always
InUDP 2055, 6343Routers, switches and firewallsTraffic flow records: NetFlow and IPFIX on 2055, sFlow on 6343 (the site's settings in Uplivra can change these)If you send traffic flows to this collector (Network Pro)
InUDP 162Routers, switches, firewalls, UPSs and serversSNMP traps and informs, v1, v2c and v3 (the site's settings in Uplivra can change the port)If devices send SNMP traps to this collector
InUDP 514Devices and serversLog messages (syslog; the site's settings in Uplivra can change the port)If devices send logs to this collector
InTCP 514Devices and serversLog messages (syslog over TCP)If devices send logs over TCP
InTCP 22Your administrators; Uplivra support when you invite themManaging the Linux system, or a support sessionOnly if you manage the Linux system this way or allow support sessions
OutTCP 443licensing.uplivra.comLicense check-ins (monthly), update downloads, and the Uplivra support connection when you turn it onNot needed for offline licenses and offline updates
OutTCP 587, 465 or 25Your mail serverEmail alertsIf email alerts are set up
OutTCP 443Microsoft Teams, Slack, PagerDuty, webhooks, ticketing systems, cloud accounts (AWS, Azure, Microsoft 365)Alerts and integrations you turn onOnly the ones you use
OutTCP 636 or 389Your domain controllersSign-in with Active Directory or LDAPIf directory sign-in is set up
OutTCP 443Let's Encrypt and CloudflareTrusted certificates for the web interface and management pagesIf you use Let's Encrypt
OutICMP (ping)The devices you monitorPing checks, tracerouteAlways
OutUDP 161The devices you monitorSNMP checks (interfaces, CPU, memory, printers, UPS...)Always
OutTCP 22, 80, 443 and the ports you checkThe devices you monitorService, website, SSH (server health, configuration backups) and port checksOnly for the checks you add
OutTCP/UDP 6514, 514 or 443Your SIEM, syslog server, HTTPS log collector or S3/Azure storageLog forwarding: copies of the logs and traps this collector receivesOnly if you set up log forwarding
OutTCP 22Network devices being upgradedCopying firmware images to devices with SFTP or SCP (Upgrade & Lifecycle). Never TFTP, FTP or TelnetOnly when you use Copy to device
OutUDP 53, 123Your DNS and time serversDNS and time (NTP) checks, and name lookupsAlways
OutTCP 22, 3389, 80, 443 (the ones allowed)Devices on the site's networkRemote support sessions (SSH, Remote Desktop, web apps). They reach the collector inside its HTTPS connection; nothing new is opened incomingIf remote access is turned on for this collector

Collector

Checks devices at a site and reports to the Uplivra server.

DirectionProtocol and portWhoWhat forNeeded
InTCP 443Your administrators' browsersThe collector's management page (HTTPS)Can be turned off; you can also limit it to your management networks
InUDP 2055, 6343Routers, switches and firewallsTraffic flow records: NetFlow and IPFIX on 2055, sFlow on 6343 (the site's settings in Uplivra can change these)If you send traffic flows to this collector (Network Pro)
InUDP 162Routers, switches, firewalls, UPSs and serversSNMP traps and informs, v1, v2c and v3 (the site's settings in Uplivra can change the port)If devices send SNMP traps to this collector
InUDP 514Devices and serversLog messages (syslog; the site's settings in Uplivra can change the port)If devices send logs to this collector
InTCP 514Devices and serversLog messages (syslog over TCP)If devices send logs over TCP
InTCP 22Your administrators; Uplivra support when you invite themManaging the Linux system, or a support sessionOnly if you manage the Linux system this way or allow support sessions
OutTCP 443Your Uplivra server (or your MSP's master collector)Reporting results and fetching checks (HTTPS). The collector always connects out; nothing connects in to it for thisAlways
OutICMP (ping)The devices you monitorPing checks, tracerouteAlways
OutUDP 161The devices you monitorSNMP checks (interfaces, CPU, memory, printers, UPS...)Always
OutTCP 22, 80, 443 and the ports you checkThe devices you monitorService, website, SSH (server health, configuration backups) and port checksOnly for the checks you add
OutTCP/UDP 6514, 514 or 443Your SIEM, syslog server, HTTPS log collector or S3/Azure storageLog forwarding: copies of the logs and traps this collector receivesOnly if you set up log forwarding
OutTCP 22Network devices being upgradedCopying firmware images to devices with SFTP or SCP (Upgrade & Lifecycle). Never TFTP, FTP or TelnetOnly when you use Copy to device
OutUDP 53, 123Your DNS and time serversDNS and time (NTP) checks, and name lookupsAlways
OutTCP 22, 3389, 80, 443 (the ones allowed)Devices on the site's networkRemote support sessions (SSH, Remote Desktop, web apps). They reach the collector inside its HTTPS connection; nothing new is opened incomingIf remote access is turned on for this collector

Log collector

Receives logs (syslog) and keeps them in its own encrypted storage.

DirectionProtocol and portWhoWhat forNeeded
InTCP 443Your administrators' browsersThe collector's management page (HTTPS)Can be turned off; you can also limit it to your management networks
InUDP 514Devices and serversLog messages (syslog; the site's settings in Uplivra can change the port)If devices send logs to this collector
InTCP 514Devices and serversLog messages (syslog over TCP)If devices send logs over TCP
InTCP 22Your administrators; Uplivra support when you invite themManaging the Linux system, or a support sessionOnly if you manage the Linux system this way or allow support sessions
OutTCP 443Your Uplivra server (or your MSP's master collector)Reporting results and fetching checks (HTTPS). The collector always connects out; nothing connects in to it for thisAlways

Customer collector connecting to an MSP over SSH

A collector at a customer site that reaches its MSP's master collector through an SSH tunnel instead of HTTPS.

DirectionProtocol and portWhoWhat forNeeded
InTCP 443Your administrators' browsersThe collector's management page (HTTPS)Can be turned off; you can also limit it to your management networks
InUDP 2055, 6343Routers, switches and firewallsTraffic flow records: NetFlow and IPFIX on 2055, sFlow on 6343 (the site's settings in Uplivra can change these)If you send traffic flows to this collector (Network Pro)
InUDP 162Routers, switches, firewalls, UPSs and serversSNMP traps and informs, v1, v2c and v3 (the site's settings in Uplivra can change the port)If devices send SNMP traps to this collector
InUDP 514Devices and serversLog messages (syslog; the site's settings in Uplivra can change the port)If devices send logs to this collector
InTCP 514Devices and serversLog messages (syslog over TCP)If devices send logs over TCP
InTCP 22Your administrators; Uplivra support when you invite themManaging the Linux system, or a support sessionOnly if you manage the Linux system this way or allow support sessions
OutTCP 22Your MSP's master collectorReporting results and fetching checks, through an SSH tunnelAlways
OutICMP (ping)The devices you monitorPing checks, tracerouteAlways
OutUDP 161The devices you monitorSNMP checks (interfaces, CPU, memory, printers, UPS...)Always
OutTCP 22, 80, 443 and the ports you checkThe devices you monitorService, website, SSH (server health, configuration backups) and port checksOnly for the checks you add
OutTCP/UDP 6514, 514 or 443Your SIEM, syslog server, HTTPS log collector or S3/Azure storageLog forwarding: copies of the logs and traps this collector receivesOnly if you set up log forwarding
OutTCP 22Network devices being upgradedCopying firmware images to devices with SFTP or SCP (Upgrade & Lifecycle). Never TFTP, FTP or TelnetOnly when you use Copy to device
OutUDP 53, 123Your DNS and time serversDNS and time (NTP) checks, and name lookupsAlways
OutTCP 22, 3389, 80, 443 (the ones allowed)Devices on the site's networkRemote support sessions (SSH, Remote Desktop, web apps). They reach the collector inside its HTTPS connection; nothing new is opened incomingIf remote access is turned on for this collector

MSP master collector

Customer collectors connect through it to the MSP's Uplivra server, over HTTPS or SSH (SSH shown on 2222, since the computer's own SSH usually has 22; 22 works when it's free).

DirectionProtocol and portWhoWhat forNeeded
InTCP 443Customer collectors; your administrators' browsersCustomer collectors connecting through this master collector, and its management page (HTTPS)Always
InTCP 2222Customer collectors that connect over SSHCustomer collectors connecting through this master collector over SSH (a tunnel for the same HTTPS connection; registered collector keys only, no shell)Always
InUDP 2055, 6343Routers, switches and firewallsTraffic flow records: NetFlow and IPFIX on 2055, sFlow on 6343 (the site's settings in Uplivra can change these)If you send traffic flows to this collector (Network Pro)
InUDP 162Routers, switches, firewalls, UPSs and serversSNMP traps and informs, v1, v2c and v3 (the site's settings in Uplivra can change the port)If devices send SNMP traps to this collector
InUDP 514Devices and serversLog messages (syslog; the site's settings in Uplivra can change the port)If devices send logs to this collector
InTCP 514Devices and serversLog messages (syslog over TCP)If devices send logs over TCP
InTCP 22Your administrators; Uplivra support when you invite themManaging the Linux system, or a support sessionOnly if you manage the Linux system this way or allow support sessions
OutTCP 443Your Uplivra serverReporting results, and passing customer collectors' connections on (HTTPS)Always
OutICMP (ping)The devices you monitorPing checks, tracerouteAlways
OutUDP 161The devices you monitorSNMP checks (interfaces, CPU, memory, printers, UPS...)Always
OutTCP 22, 80, 443 and the ports you checkThe devices you monitorService, website, SSH (server health, configuration backups) and port checksOnly for the checks you add
OutTCP/UDP 6514, 514 or 443Your SIEM, syslog server, HTTPS log collector or S3/Azure storageLog forwarding: copies of the logs and traps this collector receivesOnly if you set up log forwarding
OutTCP 22Network devices being upgradedCopying firmware images to devices with SFTP or SCP (Upgrade & Lifecycle). Never TFTP, FTP or TelnetOnly when you use Copy to device
OutUDP 53, 123Your DNS and time serversDNS and time (NTP) checks, and name lookupsAlways
OutTCP 22, 3389, 80, 443 (the ones allowed)Devices on the site's networkRemote support sessions (SSH, Remote Desktop, web apps). They reach the collector inside its HTTPS connection; nothing new is opened incomingIf remote access is turned on for this collector

MSP router

An MSP master collector that also routes to customers over GRE/IPsec tunnels. Customer collectors reach it through the tunnels over HTTPS.

DirectionProtocol and portWhoWhat forNeeded
InTCP 443Customer collectors; your administrators' browsersCustomer collectors connecting through this master collector, and its management page (HTTPS)Always
InUDP 2055, 6343Routers, switches and firewallsTraffic flow records: NetFlow and IPFIX on 2055, sFlow on 6343 (the site's settings in Uplivra can change these)If you send traffic flows to this collector (Network Pro)
InUDP 162Routers, switches, firewalls, UPSs and serversSNMP traps and informs, v1, v2c and v3 (the site's settings in Uplivra can change the port)If devices send SNMP traps to this collector
InUDP 514Devices and serversLog messages (syslog; the site's settings in Uplivra can change the port)If devices send logs to this collector
InTCP 514Devices and serversLog messages (syslog over TCP)If devices send logs over TCP
InTCP 179Customer and upstream routersBGP routing (MSP router mode)Always
InUDP 500, 4500Customer routers and firewallsIPsec (GRE over IPsec tunnels to customers). Customer collectors reach the master through these tunnels on its HTTPS portAlways
InTCP 22Your administrators; Uplivra support when you invite themManaging the Linux system, or a support sessionOnly if you manage the Linux system this way or allow support sessions
OutTCP 443Your Uplivra serverReporting results, and passing customer collectors' connections on (HTTPS)Always
OutICMP (ping)The devices you monitorPing checks, tracerouteAlways
OutUDP 161The devices you monitorSNMP checks (interfaces, CPU, memory, printers, UPS...)Always
OutTCP 22, 80, 443 and the ports you checkThe devices you monitorService, website, SSH (server health, configuration backups) and port checksOnly for the checks you add
OutTCP/UDP 6514, 514 or 443Your SIEM, syslog server, HTTPS log collector or S3/Azure storageLog forwarding: copies of the logs and traps this collector receivesOnly if you set up log forwarding
OutTCP 22Network devices being upgradedCopying firmware images to devices with SFTP or SCP (Upgrade & Lifecycle). Never TFTP, FTP or TelnetOnly when you use Copy to device
OutUDP 53, 123Your DNS and time serversDNS and time (NTP) checks, and name lookupsAlways
OutTCP 22, 3389, 80, 443 (the ones allowed)Devices on the site's networkRemote support sessions (SSH, Remote Desktop, web apps). They reach the collector inside its HTTPS connection; nothing new is opened incomingIf remote access is turned on for this collector
OutUDP 500, 4500Customer routers and firewallsIPsec tunnels to customersAlways

Packet capture collector

Records switch SPAN (mirror) ports for Packet Capture. Only the management port has an address; the SPAN ports listen and never send, so they need no rules.

DirectionProtocol and portWhoWhat forNeeded
InTCP 443Your administrators' browsersThe collector's management page (HTTPS)Can be turned off; you can also limit it to your management networks
InTCP 22Your administrators; Uplivra support when you invite themManaging the Linux system, or a support sessionOnly if you manage the Linux system this way or allow support sessions
OutTCP 443Your Uplivra server (or your MSP's master collector)Fetching its license and settings, and sending pulled packet captures (HTTPS). Only from the management port; the SPAN ports have no address and send nothingAlways