Ports

Veeam Backup & Replication automatically creates firewall rules for the ports required to allow communication between the Citrix XenServer pool, workers and the backup server.

Workers

The following table describes network ports that must be open to ensure proper communication of workers with other backup infrastructure components.

Workers

From

To

Protocol

Port

Notes

Worker


Xen pool

TCP

443

Used to communicate with the XAPI management service running on the Xen pool.

NBD/TLS

10809

Used to communicate with Xen pools when using the NBD transport mode.

Backup server

TCP

10006

Used to communicate with the backup server.

Veeam backup repository or gateway server


TCP


2500-3300

Default range of ports used as transmission channels for jobs and restore sessions. For each TCP connection that a job uses, one port from this range is assigned.

6162

Default port used by Veeam Transport Service (on Linux servers) or Veeam Data Mover Service (on Windows servers)

Veeam Update Repository
(repository.veeam.com)

Amazon CloudFront
(cloudfront.net, amazonaws.com)

TCP

443

Used to download worker deployment packages.

Note: Veeam Update Repository uses the Amazon CloudFront service to distribute traffic when downloading product updates.

NTP server

UDP

123

Used for time synchronization with NTP servers.

[Optional] Used to connect to the helper appliance during file-level restore.

Workers

From

To

Protocol

Port

Notes

Backup server

Worker

TCP

19000

Used to communicate with workers.

TCP

443

Used by the Platform Service to enable communication with the Veeam Updater service on the worker.

Backup server

TCP

6172

Used by the Platform Service to enable communication with the Veeam Backup & Replication database.

Xen pool

TCP

443

Used to communicate with the XAPI management service running on the Xen pool.

File-level recovery (FLR) helper appliance

TCP

22

[Optional] Used to connect to the helper appliance during file-level restore.

Note

For the list of ports used by the backup server to communicate with backup repositories, see Used Ports.

Page updated 2026-08-18

Page content applies to build 13.1.1.18