Skip to main content

Connectivity Requirements

VKB-1121Reference
📦 Applies to
XCP-ngXen Orchestra
🗓️ Created
2025-04-17
🔄 Updated
2025-04-17

External domains accessed by XCP-ng and Xen Orchestra​

XCP-ng hosts​

XCP-ng hosts require access to the following domains:

DomainPortDirectionDetails
mirrors.xcp-ng.org443OutboundXCP-ng uses mirrorbits to redirect download requests to an appropriate mirror based on their update status and geographical position.

However, please note this mirror system will redirect you to your nearest mirror, which can be any of our third party mirrors, so you will need to allow traffic to these as well. They can be found here: https://mirrors.xcp-ng.org/?mirrorstats

Xen Orchestra​

Xen Orchestra requires access to the following domains:

DomainPortDirectionDetails
xen-orchestra.com443Outbound
tunnel.xen-orchestra.com443OutboundSecure support tunnel
github.com443Outbound
nodejs.org443Outbound
npmjs.org443Outbound
registry.npmjs.org443Outbound
updates.ops.xenserver.com443OutboundXOA polls information on this site to see whether updates are available for XenServer hosts
fileservice.citrix.com443OutboundSource for XenServer patches

Communication ports used by XCP-ng and Xen Orchestra​

The ports listed in the following table are the common ports that are used by XCP-ng and Xen Orchestra. Not all ports need to be open, depending on your deployment and requirements.

SourceDestinationTypePortDetails
XCP-ng hostsXCP-ng hostsTCP80, 443Intra-host communication between members of a resource pool using the management API
NTP ServiceTCP, UDP123Time Synchronization
DNS ServiceTCP, UDP53DNS Lookups
Domain ControllerTCP, UDP389LDAP (for Active Directory user authentication)
TCP636LDAP over SSL (LDAPS)
FileServer (with SMB storage)TCP, UDP139ISOStore:NetBIOSSessionService
SAN ControllerTCP3260iSCSI Storage
NAS Head/File ServerTCP2049NFSv4 Storage
TCP, UDP2049NFSv3 Storage. TCP is the default
TCP, UDP111NFSv3 Storage, connection to rpcbind
TCP, UDPDynamicNFSv3 Storage, a dynamic set of ports chosen by the filer
SyslogUDP514Sends data to a central location for collation
ClusteringTCP8892, 8896, 21064Communication between all pool members in a clustered pool
UDP5404, 5405
Xen OrchestraXCP-ng hostsTCP22SSH
TCP443Management using the management API
Virtual MachineTCP5900VNC for Linux VMs
TCP3389RDP for Windows VMs
Workload Balancing virtual applianceXCP-ng hostsTCP8012By default, the Workload Balancing server uses 8012. However, if you specify a different port during Workload Balancing set up, ensure that communication is allowed on that port.
Other clientsXCP-ng hostsTCP80, 443Any client that uses the management API to communicate with XCP-ng hosts