This article applies to:
- McAfee for Marshal version 6.x
Question:
What ports need to be open in my firewall for the McAfee for Marshal Virus Scanner?Information:
The table below details the various ports used by the McAfee for Marshal updater software.
The table below details the various ports used by McAfee for Marshal for direct connections. These ports must be available on every processing server where the McAfee for Marshal package is installed.
If you use an active web filtering device upstream of the processing server (such as WebMarshal), you must configure it to pass this traffic.
Port | Direction | Destination | Required for Versions | Explanation |
tcp/80 | Outbound | http://crl.trustwave.com/ | 6.1 and above | HTTPS connection validation for the engine download site requires access to the Certificate Revocation List over HTTP. - This site is hosted on a CDN. IP addresses will differ by geographical location and are subject to change without notice.
|
tcp/80 | Outbound | http://update.nai.com/Products/CommonUpdater | 6.X | McAfee for Marshal 6.x uses this site by default to download new virus signature files. |
tcp/443 | Outbound | https://mcafee.marshal.com/updates | 6.1 and above | McAfee for Marshal uses this site to download new McAfee engine files. - As of 28 February 2022, the IP address of this server is within the block 20.81.78.232/29
- Note that the name resolution of all required servers is subject to change.
- Port 443 (HTTPS) is required from version 6.1
|
tcp/80 | Outbound | http://mcafee.marshal.com/updates | 6.0 | McAfee for Marshal uses this site to download new McAfee engine files. - As of 28 February 2022, the IP address of this server is within the block 20.81.78.232/29
- Note that the name resolution of all required servers is subject to change.
|
udp/53 tcp/53 | Outbound | DNS servers specified in OS configuration | All | McAfee for Marshal must have external DNS access to resolve the domains listed above. |
Notes:
- McAfee for Marshal 5.x updates are no longer available.
- The software can use a HTTP proxy such as WebMarshal to access HTTP/S sites.