Preparing your corporate network infrastructure for Kaspersky Security 8 for Linux Mail Server

August 21, 2023

ID 151796

Before using Kaspersky Security 8 for Linux Mail Server, you need to prepare your corporate network infrastructure and allow connections over incoming and outgoing protocols.

Incoming protocols:

  • <host>:80 (HTTP) and <host>:443 or <host>:9045 (HTTPS) for operation of the program web interface, if it is installed and enabled (additional package klmsui).
  • <host>:<port> (by default 127.0.0.1:10025) (SMTP) for operation of the mail transfer agent (MTA) filter, if MTA Filter is configured to accept connections, for example, from an external MTA over the TCP (SMTP) protocol.
  • <host>:<port> (by default 127.0.0.1:10025) (Milter) for operation of the mail transfer agent (MTA) filter, if MTA Filter is configured to accept connections, for example, from an external MTA over the Milter protocol.
  • <host>:<port> (by default 127.0.0.1:2711) (FCGI/TLS) for the Facade module to access the program web interface.
  • <host>:<port> (by default 127.0.0.1:5555) (Binary) for operation of the ScanLogic module, if it is configured to accept connections over the TCP protocol.

Outgoing protocols:

  • <host>:<port> (HTTPS) to connect to the program activation server for license verification.
  • <host>:<port> (SNMP) to connect to the SNMP server to relay statistics and event information.
  • <host>:<port> (LDAP, LDAP/TLS) to connect to an external LDAP server and Active Directory and for user authorization.
  • <host>:<port> (DNS) for operation of Mail Sender Authentication technologies (DNSBL, SURBL, SPF) and the Anti-Spam module.
  • <host>:<port> (SMTP) for operation of the mail transfer agent (MTA) filter if MTA Filter is configured to send email messages to an external mail server over the TCP protocol.
  • <host>:<port> (HTTPS) to connect to the program database update server.
  • <host>:<port> (HTTPS) for the connection between the Moebius module (for instantaneous updates of Anti-Spam databases) and the enforced database update service.
  • <host>:<port> (HTTPS) to connect to KSN.
  • <host>:<port> (HTTPS) to connect to the Kaspersky Anti Targeted Attack Platform server.

Did you find this article helpful?
What can we do better?
Thank you for your feedback! You're helping us improve.
Thank you for your feedback! You're helping us improve.