Skip to content

Mideye Networking: Port & Firewall Setup

The following ports are used for communication with Mideye Server and need to be open in the network. If sharing a platform with other applications, verify that these ports are not already in use.


PortProtocolDirectionPurpose
443 or 8443TCPInboundHTTPS — port is configurable during installation
8080TCPInboundHTTP — default in Docker / Kubernetes deployments

PortProtocolDirectionPurpose
1812UDPInboundRADIUS authentication (default; configurable per RADIUS server)
1813UDPInboundRADIUS accounting (if enabled)
3799UDPOutboundRADIUS Disconnect Messages / CoA to NAS devices

PortProtocolDirectionPurpose
2083TCP/TLSInboundRADSEC — disabled by default

PortProtocolDirectionPurpose
3306TCPOutboundMariaDB / MySQL (if database is on a remote server)
1433TCPOutboundMicrosoft SQL Server (if database is on a remote server)

Directory services (LDAP / Active Directory)

Section titled “Directory services (LDAP / Active Directory)”
PortProtocolDirectionPurpose
636TCPOutboundLDAPS — LDAP over TLS (recommended)
389TCPOutboundLDAP without TLS (not recommended)

PortProtocolDirectionPurpose
Customer-specific TCP portTCPOutboundTLS 1.3 to switch1.mideye.com and switch2.mideye.com. Request the port from support@mideye.com.

PortProtocolDirectionPurpose
443TCPOutboundHTTPS to mas.prod.mideye.com

PortProtocolDirectionPurpose
443TCPOutboundHTTPS to shield.prod.mideye.com (optional)

PortProtocolDirectionPurpose
53UDP/TCPOutboundDNS — required for LDAPS, FQDN-based Switch configuration, and RADIUS Disconnect Messages
25TCPOutboundSMTP — only if email notifications are configured
443TCPOutboundMicrosoft Graph API — only if Azure AD / Entra ID integration is used
443TCPOutboundMideye+ simplified activation (activate01.mideye.com, activate02.mideye.com)

For the canonical list of outbound IP addresses (and how to look them up via DNS), see External Service Issues → Outbound endpoints and IP addresses.