Internet access requirements for the passive identity agent

By default, the passive identity agent is configured to communicate with the Firepower System over the internet using HTTPS on port 443/tcp (HTTPS). If you do not want the passive identity agent to have direct access to the internet, you can configure a proxy server.

If your Cloud-Delivered Firewall Management Center cannot communicate with the machine on which the passive identity agent is installed, you must use a proxy with the HTTPS protocol enabled.

You can choose how to set up the proxy. For example, you can use a commercial proxy and a Windows system proxy with HTTPS enabled to communicate with it.

This section lists the ports the passive identity agent uses to communicate with other agents, the Security Cloud Control, and Microsoft Active Directory.

Passive Identity Agent port requirements

Port

Reason

443

Communicate with the Security Cloud Control.

135

Communicate with Microsoft Active Directory using the MSRPC protocol.

9095

Communicate with other agents using the UDP protocol.