Ports and Firewall Rules
This is the canonical port reference for ScrewDrivers v7. All listed ports are TCP defaults (configurable unless noted), and Tricerat component connections are TLS 1.2 secured.
Port reference by component
| Component | Listens on (inbound) | Outbound connections |
|---|---|---|
| Microsoft SQL Server | TCP 1433 (Microsoft default; ScrewDrivers connects with a TLS 1.2 enabled driver). Named instances also use UDP 1434 (SQL Server Browser). | None |
| Tricerat License Server | TCP 6200 | HTTPS to X-Formation, only during license activation |
| ScrewDrivers Print Server | TCP 5550–5553, TLS 1.2 | None |
| ScrewDrivers Gateway | TCP 4600, TLS 1.2 — TCP/IP clients, non-Windows platforms, and mobile connections | None |
| ScrewDrivers Secure Release (beta, 7.10+) | TCP 5286 (default, configurable), HTTPS — connections from printers running the Secure Release app | To SQL Server, and to print servers when releasing jobs |
| Cloud Connector (internal) | TCP 5551 (remote connector authentication), TCP 5550 (internal connections). Accepts incoming only. | None |
| Cloud Connector (remote) | None | TCP 5551 to the internal connector (authentication); TCP 5550 or 5553 to print servers |
| Session hosts and desktops | None | To SQL Server, License Server, Print Servers, Gateway, and the internal Cloud Connector as deployed |
| Network printers | The printer's configured port — commonly TCP 9100 (RAW) | — |
One port that isn't here matters too: Essentials printer redirection uses no extra ports at all — traffic between the endpoint and the session host travels inside the remoting protocol's virtual channel (ICA, RDP, or Blast), which is already open if users can connect to their sessions.
Who talks to whom
Arrows point from the connecting side to the listener — the direction your firewall rules need to allow.
Firewall rules by deployment
Essentials — nothing beyond your remoting protocol, plus session hosts → License Server on 6200 if you use concurrent licensing.
Pro, print server architecture — session hosts → SQL (1433), License Server (6200), and Print Servers (5550–5553); Print Servers → printers (typically 9100).
Pro, Direct IP — session hosts → SQL (1433), License Server (6200), and printers directly (typically 9100).
Enterprise — everything above, plus: client networks → Gateway (4600); and for remote/cloud printing, remote Cloud Connectors → internal connector (5551) and → print servers (5550/5553). The internal connector only ever accepts connections; the remote connector only ever makes them — a firewall-friendly design for sites you don't control.
Related pages
- System Requirements — the full pre-installation reference
- Setting Up SQL Server for ScrewDrivers — ports, instances, and aliases in depth
- Installing the ScrewDrivers Gateway and the License Server
- Version 7 TLS 1.2 Support — the encryption behind these connections