NextGen Knowledge Center

Opening Network Ports Through a Firewall

When operating a Mirth® Appliance by NextGen Healthcare through a firewall or other device performing access control, it is necessary to allow some network traffic so that certain features can function.

Traffic DirectionPortProtocolServiceNote
Out80tcpSoftware UpdateCan be restricted to mirthhq.mirthcorp.com.
Out443tcpSoftware UpdateCan be locked down to mirthhq.mirthcorp.com.
Out25tcpMail DeliveryNot necessary if you use a mail relay behind the firewall.
Out123udpNTP (time)Not necessary if you use an NTP server behind the firewall.
In80tcpControl PanelOnly necessary to open if you perform administration through the firewall. An alternative is to use VPN service.
In

8080,

8443

tcpMirthOnly necessary to open if you perform administration through the firewall. An alternative is to use VPN service.
Out53tcpDNSNot necessary if there is a local DNS server behind the firewall.
In1194udpVPNThis is the default value. Can be changed. Only necessary if you use the VPN Client Access service.
In22tcp

SFTP,

Console Access

Only necessary if you use the SFTP Server or the Console Service.
Out80tcpVPNOptional. Only used for detecting external IP address. Can be locked down to www.mirthcorp.com
In5432tcpDatabaseOnly necessary if you use the database service and you require access behind the firewall.
In161udpSNMPOnly necessary if you use SNMP.
In389tcp

LDAP

Directory

Only necessary if you are setting up appliance-to-appliance LDAP directory replication through the firewall.
Out

1194

443

udp

tcp

SupportNetUse one of these options. Only needed if SupportNet access is desired.