Ports

As Veeam Plug-in for AWS is installed on the same machine where Veeam Backup & Replication runs, it uses the same ports as those described in section Ports —  in addition to the ports listed in the following table.

Ports

From

To

Protocol

Port

Notes

Web browser (local machine)

Backup appliance

TCP

443

Required to access the Web UI component from a user workstation over HTTPS.

TCP

22

[Optional] Required to connect to the backup appliance using SSH.

TCP

11005

[Optional] Default port required to communicate with the public REST API service running on the backup appliance over HTTPS. For more information on Veeam Plug-in for AWS REST API, see the Veeam Plug-in for AWS REST API Reference.

To learn how to change the port number, see the Configuring Security Settings section in the Veeam Plug-in for AWS REST API Reference.

Worker instances

TCP

443

Required to access the file-level recovery browser running on a worker instance during the file-level recovery process over HTTPS.

Backup appliance

SMTP server

TCP

25

Default port used for sending email notifications over SMTP.

Veeam Update Repository (repository.veeam.com), Amazon CloudFront (cloudfront.net, amazonaws.com)

TCP

443

Required to download available product updates, worker deployment packages and restore utilities over HTTPS.

Note: Veeam Update Repository uses the Amazon CloudFront service to distribute traffic when downloading product updates.

Ubuntu Security Repository and OS Update Repository (security.ubuntu.com, archive.ubuntu.com)

TCP

80

Required to get OS security updates over HTTP.

Microsoft Package Repository (packages.microsoft.com, dotnetcli.blob.core.windows.net)

TCP

443

Required to get .NET package updates over HTTPS.

PostgreSQL Apt Repository (apt.postgresql.org, archive.ubuntu.com)

TCP

443

Required to get PostgreSQL updates over HTTPS.

PostgreSQL Website (postgresql.org)

TCP

443

Required to download the PostgreSQL Apt Repository key over HTTPS.

AWS services

TCP

443

Required to perform data protection and disaster recovery operations over HTTPS.

Route 53 Resolver

UDP

53

[Optional] Default port required to perform DNS resolution if you plan to use a custom DNS server for your VPC.

Worker instances

AWS services

TCP

443

Required to perform data protection and disaster recovery operations over HTTPS.

Route 53 Resolver

UDP

53

[Optional] Default port required to perform DNS resolution if you plan to use a custom DNS server for your VPC.

Veeam Plug-in for AWS

Backup appliance, AWS services

TCP

443

Port used for communication with AWS and the backup appliance over HTTPS.

AWS CheckIP service
(DNS name: checkip.amazonaws.com)

TCP

443

Required to get the public IP address of the Veeam Backup & Replication server during the deployment of Veeam Plug-in for AWS over HTTPS.

Veeam Backup & Replication console and Veeam ONE server

Veeam Plug-in for AWS

TCP

443

Port used to connect to Veeam Plug-in for AWS over HTTPS.

To open network ports, you must add rules to security groups associated with solution architecture components:

To learn how to add security groups rules, see AWS Documentation.

Page updated 2026-08-13

Page content applies to build 13.1.1.18