Port requirements
    Before you install or upgrade 
BEMS
, you should familiarize yourself with how BEMS
 uses ports.The 
BEMS
 services use various ports to communicate with the BlackBerry Infrastructure
, the BlackBerry Dynamics NOC
, and internal resources (for example, your organization's messaging software). This section lists the default ports that BEMS
 uses for outbound, inbound, and internal communications. All ports are TCP, unless otherwise specified. The ports must be open and ready for BEMS
 to use and not blocked by a firewall. BEMS
 must be installed in BlackBerry UEM
 environments that use BlackBerry
        Dynamics
. BEMS
 has port requirements for communication with UEM
 and the BlackBerry Dynamics NOC
.BEMS services TCP ports
      
  BEMS
 services TCP ports| Ports | Connection | Service | Purpose | 
|---|---|---|---|
| 8443 | Outbound | Connect, Presence  | To connect to the  CiscoUser Data Service | 
| Presence  | To connect to the Presence Web Service (CIMP server) | ||
| BlackBerry Mail (Push Notifications Service) | Optionally, if your environment uses  Microsoft Graph, 8443 or another configured port to the reverse proxy appliance. For information about how Microsoft Graphcommunicates with BEMS, see Data flow: BEMS notification flow using the Microsoft Graph API. If your environment uses  Microsoft Graph, you can complete the following: 
 | ||
| Inbound | Dashboard | The Dashboard binds to this port and allows  BEMSadministrators and BEMSDocs users to access the Dashboard using a web browser. | |
| BlackBerry Mail (Push Notifications Service), Presence, and Docs | To connect from the  BlackBerry Proxy. | ||
| Docs | To connect from  Microsoft Office Web Appsor Office OnlineServer for Docs. | ||
| Presence | To connect from the  BlackBerry Proxyserver. | ||
| BlackBerry Mail (Push notifications Service), Presence | To connect from the  BlackBerry Proxyserver, and optionally for Microsoft Graph (Push Notifications) to the reverse proxy server appliance. For more information about how Microsoft Graph communicates with BEMS, see Data flow: BEMS notification flow using the Microsoft Graph API. | ||
| BlackBerry Mail (Push Notifications Service), Presence, Docs | To connect from the  BlackBerry Proxyserver, and from Microsoft Office Web Appsor Office OnlineServer (Docs). | ||
| 443 | Outbound | BlackBerry Mail (Push Notifications Service) | To connect to
                   
 | 
| Connect | In a  Skype for Businesson-premises environment that uses non-trusted application mode, to connect to: 
 | ||
| BlackBerry Mail (Push Notifications Service) | In an  Entraenvironment, to connect to the following: 
 | ||
| Docs | In a  SharePoint Onlineenvironment, to connect to: 
 | ||
| Docs | In a  Boxenvironment, to connect to *.box.com. | ||
| 17080 or 17433 (SSL) | Outbound | BlackBerry Mail (Push Notifications Service) | To connect to the  BlackBerry Proxyserver. BEMSrequires visibility of all instances of the BlackBerry Proxyserver (17080 and 17433), regardless of whether KCD is enabled or not, so that if one BlackBerry Proxyfails, BEMScan communicate with the next BlackBerry Proxyin the cluster for authentication tokens. | 
| 1433, 1434 | Outbound | BlackBerry Mail (Push notifications Service), Connect, Presence  | To connect to the  Microsoft SQL
  Serverdatabase (default). To connect to the SQL Browser service when using dynamic ports. | 
Internal TCP ports for internal BEMS communications
      
  BEMS
 communications| Ports | Purpose | 
|---|---|
| 8101  | SSH connectivity to  BEMS. | 
| 8443  | Used by the  BlackBerryMail (Push notifications Service) and Presence service. | 
| 8099  | Used by the .NET Component Manager. | 
| 8060  | Used by the Lync Presence Provider (LPP).  | 
| 6379 | Used by LPP in a  Skype for Businessenvironment and BEMS-Core in a Cisco Unified Communications
  ManagerIM and Presence environments to read and write to the Redis service database. | 
| 1001  | Used by  BEMSfor internal process communications when Active Directory Rights Management Services (AD RMS) and Entra-IP RMS are used in the environment. | 
BlackBerry Push Notifications (Mail) service TCP ports
      BlackBerry Push Notifications
 (Mail
) service TCP portsDevices must be able to connect to the 
Apple
 Push Notification Service (APNS) and cloud messaging servers to receive push notifications from BEMS
. If your Wi-Fi network restricts outbound access, verify that the proper outbound ports are open for your devices.| Ports | Connection | Purpose | 
|---|---|---|
| 61616 or 61617 (SSL) | Bidirectional  | Connection to and from servers that host  BEMSin the same cluster. To support clustering,  BEMSemploys ActiveMQ's enterprise features. By design, network port 61616 and 61617 (SSL) are used for inter- BEMScommunication. Any firewall between BEMSnodes in the same cluster should have rules allowing bi-directional communication between BEMSnodes over port 61616 and/or 61617 (SSL). | 
| 80 | Outbound | To connect to  Microsoft Exchange
  Server(AutoDiscover). | 
| 389 or 636 (SSL) | Outbound | To connect to  Active
  Directoryusing LDAP. | 
| 3268 or 3269 (SSL) | Outbound | To connect to the Global catalog.  | 
| GoogleAuthentication Server URLs | Outbound | To connect to the following URLs:
                   
 | 
BlackBerry Connect and BlackBerry Presence service TCP and UDP ports
      BlackBerry Connect
 and BlackBerry Presence
 service TCP and UDP portsIf you install Connect for 
Skype for Business
, if the Skype for Business
 database server is using a static port, then you must open that port. The range of ports is necessary only when the Skype for Business
 database server is using dynamic ports. | Ports | Connection | Purpose | 
|---|---|---|
| 8080 or 8082 (SSL) | Inbound | Connection from the BlackBerry Proxy server and is used by the  BlackBerry Connectservice. By default, SSL communication is enabled with a new  BEMS2.12.5.6 or later installation and is bound to port 8082. If you upgraded from BEMS2.10 or earlier and SSL communication with the BlackBerry Connectapp is not enabled, use port 8080. For more information, see Configure BlackBerry Connect app settings in BlackBerry UEM" in the BlackBerry Connect administration content. | 
| 49555 | Inbound | Connection from the on-premises  Skype for Businessserver (for BlackBerry Connect) when the Connect service is trusted by Skype for Business. | 
| 49777 | Inbound | Connection from the on-premises  Skype for Businessfor BlackBerry Presence. | 
| 5061 | Outbound | To connect from the  BlackBerry Connectservice to the on-premises Skype for Businessserver configured as trusted mode. | 
| 1434  | Outbound | UDP port to connect to the on-premises  Skype for Businessdatabase. This is used for the initial setup only. | 
| 49152 to 57500 | Outbound | A random port in this range to the  Skype for Businessdatabase. This is used for the initial setup only. | 
| 5222  | Outbound | To connect to the  Cisco JabberXMPP Service. To connect to the Presence Web Service (CIMP server). | 
| 8083  | Outbound | To connect to the  CiscoIM and Presence Service. | 
BlackBerry Docs service TCP ports 
      
  BlackBerry Docs
 service TCP ports | Ports | Connection | Purpose | 
|---|---|---|
| 80 or 443 | Outbound | To connect to your  Microsoft
  SharePointserver. | 
| 443 | Outbound | To connect to  Microsoft Office Web Appsor Office OnlineServer. | 
| 445 or 139 | Outbound | To connect to the CIFS share. | 
| 389 or 636 | Outbound | To connect to  Active
  Directoryusing LDAP. | 
| 137, 138 | Outbound | UDP port to connect to the CIFs share. |