Skip to content

Network Ports Requirements

In order for Coriolis to be able to perform Replica/Migration tasks, it will require network access to the Endpoints that will be used.
Once the network connection is available, Coriolis will use certain ports to further communicate with the Endpoints, as it is the intermediary between the source and destination Endpoints. No direct communication is established between the source and destination endpoints, all traffic and communication go through the Coriolis Appliance.

The following ports are the default for each endpoint, so the Cloud administrator must verify for any customized ports.
For cloud access of the Endpoints, Coriolis will use the same ports even though the Endpoint will be used as the source or destination.

The temporary worker transfer mechanism for the destination platforms offers two options: HTTPS and SSH. The default one is the HTTPS-based transfer mechanism (TCP/5566), which is faster but might not work if there are firewalls in the way. The SSH-based transfer mechanism (TCP/22) is more costly but will be allowed by most firewalls since SSH access from the Coriolis installation to the temporary worker VM is always required. Coriolis automatically sets security group rules for the temporary VMs accordingly.

Regarding the temporary migration worker for the source platforms, Coriolis uses Replicator port 4433 for performing disk chunking and transferring the backup data to the writer located on the destination platform. This port is used on platforms that require a migration worker machine.

OpenStack

ServiceDefault PortProtocol
Keystone5000TCP
Cinder8776TCP
Nova8774TCP
Glance9292TCP
Neutron9696TCP
Swift8080TCP
Ceph6789TCP
Temporary Migration Worker – Source22, 4433TCP
Temporary Migration Worker – Destination22 4433 5986 5566TCP

VMware

ServiceDefault PortProtocol
vSphere API Access (Management)443TCP
Temporary Migration Worker – Destination22 4433 5986 5566TCP
VM snapshot data transfer via NFC (to all ESXi nodes*)902TCP

* NOTE! In the case of VMware vSphere as the source platform, Coriolis must be able to connect to all the VMware ESXi nodes, not only to the one holding the VM to be migrated. That is due to how VMware manages the data transfer, refer to the VMware plugin documentation for more details.

Amazon Web Services (AWS)

ServiceDefault PortProtocol
Public API80, 443TCP
Temporary Migration Worker – Source22, 4433TCP
Temporary Migration Worker – Destination22 4433 5986 5566TCP

Microsoft Azure

ServiceDefault PortProtocol
Public API80, 443TCP
Temporary Migration Worker – Source22, 4433TCP
Temporary Migration Worker – Destination22 4433 5986 5566TCP

Microsoft Windows Server – Hyper-V

ServiceDefault PortProtocol
Management443TCP
RCT Source6677TCP

Oracle Cloud Infrastructure (OCI)

ServiceDefault PortProtocol
Public API80, 443TCP
Temporary Migration Worker – Destination22 5986 5566TCP

oVirt (OLVM and Red Hat Virtualization)

ServiceDefault PortProtocol
Public API80, 443TCP
Source Image Transfer54322TCP
Temporary Migration Worker – Destination22 4433 5986 5566TCP

SUSE Virtualization (Harvester)

ServiceDefault PortProtocol
Kubernetes API443TCP
KubeVirt API443TCP
Temporary Migration Worker – Destination22 5986 5566TCP

SUSE Linux (KVM)

ServiceDefault PortProtocol
SSH access for libvirt qemu+ssh transport22TCP
Temporary Migration Worker – Destination22 5986 5566TCP

Proxmox VE

ServiceDefault PortProtocol
Management API8006TCP
Temporary Migration Worker – Destination22 4433 5986 5566TCP

CloudStack

ServiceDefault PortProtocol
Management API443TCP
Temporary Migration Worker – Destination22 4433 5986 5566TCP

MicroCloud/LXD

ServiceDefault PortProtocol
Management API8443TCP
Temporary Migration Worker – Destination22 5986 5566TCP

Bare-Metal (Linux p2v)

ServiceDefault PortProtocol
Bare-metal Hub API9900TCP
Snapshot Agent API9999TCP

Nutanix

ServiceDefault PortProtocol
Management API9440TCP

[Legacy] Oracle VM (OVM)

ServiceDefault PortProtocol
Management7002TCP
Temporary Migration Worker – Source22, 4433TCP
Temporary Migration Worker – Destination22 5986 5566TCP
OVM Exporter5544TCP

[Legacy] Oracle Cloud Infrastructure Classic (OCI-C)

ServiceDefault PortProtocol
Public API80, 443TCP
Temporary Migration Worker – Source22, 4433TCP
Temporary Migration Worker – Destination22, 5986TCP

Coriolis API/CLI remote access

When accessing the Coriolis API or CLI from a remote / client machine, the following ports have to be allowed for the Coriolis appliance network. Additional ports are required when scaling out Coriolis with additional Coriolis worker machines:

ServiceDefault PortProtocol
Coriolis API7667TCP
Coriolis API – Keystone5000TCP
Barbican9311TCP
Metal Hub API – required only for Linux p2v9900TCP
Coriolis Licensing37667TCP
Coriolis Logging9998TCP