ManageEngine Endpoint Central
System Requirement &
Pre-Requisite Document
ManageEngine Endpoint Central System Requirement:
All-in-one endpoint platform
Everything in IT converges into an endpoint. And behind every endpoint, there's an end user
or a technician. Endpoint Central brings your devices, apps, data personnel together in one
place, enabling you to secure your digital workplace and manage your workforce across the
globe.
Hardware Requirements
A dedicated VM/hardware must be provided for installing the ManageEngine Endpoint
Central Server The hardware must be compliant with the specification captured below.
Minimum hardware requirements:
ManageEngine Endpoint Central Server
Processor(s) : Physical Machine: Intel Core i5 (4 core/8 thread) 2.5GHz
Virtual Machine: 8 virtual processors (2.5 Ghz)
Memory : 16 GB
Free Hard Disk Space : 200 GB
OS : Microsoft Windows Server 2019 / 2022 Server
System Requirements
[Link]
Note. Above Resources requirement is minimum requirement and it may wary based on your environment and
infrastructure, if required additional resources should be provided. Database license and support is out of Elitbuzz
scope.
* May increase dynamically according to the frequency of scanning
** May increase dynamically depending on the operations performed on the client computer
Endpoint Central supports the following databases:
PGSQL
MSSQL
SQL Server 2022
SQL Server 2019
Supported Web Browsers
You are required to install any of the following browsers on your computer to access the Endpoint
Central console:
Microsoft Edge
Mozilla Firefox
Google Chrome
Zoho Ulaa
Supported Web Servers
Endpoint Central uses the following web servers:
Nginx(for static file services)
Tomcat (for application related services)
Supported TLS versions
From Endpoint Central version 11.2.2330.1:
Endpoint Central and Secure Gateway Server support TLS version 1.2 by default. However, you
have the option to enable the older TLS versions (TLS 1.0 and TLS 1.1) from the Security
Settings page.
Prior to Endpoint Central version 11.2.2330.1:
Endpoint Central and Secure Gateway Server support TLS versions 1.0, 1.1, and 1.2 by default.
However, you have the option to disable the older TLS versions (TLS 1.0 and TLS 1.1) from the
Security Settings page.
Endpoint Central Architecture
ManageEngine's Endpoint Central is a web-based application for desktop administration and
management. This application enables administrators to manage computers effectively, from a central
point. It comprises features like Software Deployment, Patch Management, Service-pack Installation,
Asset Management, OS Deployment, Remote Control, Configurations, System Tools, Active Directory
Reports and User Logon Reports.
Ports used by Endpoint Central
Note: The ports mentioned under 'Server' must be enabled at all times irrespective of your license
edition. Refer the ports required for specific modules and enable them as per your requirement.
Port Link : [Link]
[Link]#dcports
Server
Port Purpose Type Connection
8020 For communication between the web browser HTTP In bound to server
and the Endpoint Central Server.
Source:Web browser
Destination: Endpoint Central server
8383 For communication between the agent or HTTPS In bound to server
distribution server or the ME MDM app and the
Endpoint Central server.
Source: Agent/Distribution server
Destination: Endpoint Central server
8027 The notification server port is responsible for TCP,TLS In bound to server
communicating on-demand operations from the
server to the agent.
Source: Agent
Destination: Endpoint Central server
Tools and Remote Control
Port Purpose Type Connection
8444 For Sharing remote desktops, System HTTP In bound to
Manager, Chat server
Source: Agent
Destination: Endpoint Central server
8444 For transferring files HTTP In bound to
Source: Agent server
Destination: Endpoint Central server
8443 For Sharing Remote Desktops, System HTTPS/UDP In bound to
Manager, Chat (for voice & server
Source: Agent video chat)
Destination: Endpoint Central server
8443 For transferring files HTTPS In bound to
Source: Agent server
Destination: Endpoint Central server
Distribution
Server
8384 For communication between HTTPS In bound to
(remote)agent and distribution server Distribution
Source: Agent Server
Destination: Distribution Server
MDMP
Port Purpose Type Connection
443 Should be open on the firewall/ proxy for HTTPS Outbound from
Endpoint Central server to reach GCM/APNs Corporate
service Network Firewall
Source: Endpoint Central server
Destination: Apple server, Google server
Ex: *.[Link]
5223 Should be open, if the mobile device HTTPS Outbound from
connects to the internet through the Corporate
Corporate WiFi, it is recommend to Network Firewall
configure the IP range [Link]/8.
Source: Endpoint Central server
Destination: Apple server, Google server
5228 For the GCM to reach the managed mobile HTTPS Outbound from
device Corporate
Source: Endpoint Central server Network Firewall
Destination: Google Playstore server
5229 For the GCM to reach the managed mobile HTTPS Outbound from
device Corporate
Source: Endpoint Central server Network Firewall
Destination: Google Playstore server
5230 For the GCM to reach the managed mobile HTTPS Outbound from
device Corporate
Source: Endpoint Central server Network Firewall
Destination:Google Playstore server
2195 Should be open on the firewall/ proxy for HTTPS Outbound from
Endpoint Central server to reach APNs. Host Server
Address: [Link]
Source: Endpoint Central server
Destination: [Link]-
Apple server
5235 For Firebase Cloud Messaging HTTPS Outbound from
Source: Endpoint Central server Corporate
Destination: Google server Network Firewall
5236 For Firebase Cloud Messaging HTTPS Outbound from
Source: Endpoint Central server Corporate
Destination: Google server Network Firewall
OSD
Port Purpose Type Connection
8444 For communication between the OS HTTP In bound to server
Deployer Components and the server
Source: Target machine
Destination: Endpoint Central server
8443 For communication between the OS HTTPS In bound to server
Deployer Components and the server
Source: Target machine
Destination: Endpoint Central server
8383 For communication between the OS HTTPS In bound to server
Deployer Components/Distribution
Server and the OS Deployer server in
secured mode
8384 For communication between the OS HTTPS In bound to
Deployer Components and distribution server
Distribution server
69, 4011 TFTP PXE Communication between UDP In bound to server
the target machine and Server
Source: Target machine
Destination: Endpoint Central server
Note: Ports 135,139 and 445 should also be kept open and inbound on both agent and
server (and distribution server, if applicable) for pushing agent installation.
Agent Installation Pre-requisites:
1. Account
A domain account is an admin or service account with administrative privilege.
The account used for installation should have access to the agent machine Admin$\temp folder with
read and write permissions.
Note: The account would be added to the local administrator group.
2. Admin$/temp accessibility
To confirm the Admin$/temp accessibility:
Login to the Remote Access Plus server installed machine with the domain account being used.
Open the "run" window.
Type in "remote machine share". For example, \\<client computer-name>\Admin$\temp
Note: If an agent is managed under a distribution server, accessibility should be verified from the
corresponding distribution server installed machine.
Agent
Securing LAN agents and server communication
To secure the LAN network managed by Endpoint Central follow the below
recommendations:
1. Enable secure Agent-Server communication by going to Admin tab→ Security
settings→ Enable Secured communication.
2. For secure remote control connection, enable secure communication for web socket
and file transfer port by going to Tools --> Remote Control --> Settings --> Port
Settings --> Enable Use secure connection.