Ports and Protocols for Amazon Windows AMIs
The following tables list the ports, protocols, and directions by workload for Amazon Windows Amazon Machine Images (AMIs).
Contents
- AllJoyn Router
- Cast to Device
- Core Networking
- Delivery Optimization
- Diag Track
- DIAL Protocol Server
- File and Printer Sharing
- File Server Remote Management
- ICMP v4 All
- Microsoft Edge
- Microsoft Media Foundation Network Source
- Multicast
- Remote Desktop
- WindowsDevice Management
- WindowsFeature Experience Pack
- WindowsFirewall Remote Management
- WindowsRemote Management
AllJoyn Router
OS | Rule | Description | Port | Protocol | Direction |
---|---|---|---|---|---|
Windows Server 2016 Windows Server 2019 Windows Server 2022 |
AllJoyn Router (TCP-In) | Inbound rule for AllJoyn Router traffic [TCP] | Local: 9955 Remote: Any |
TCP | In |
AllJoyn Router (TCP-Out) | Outbound rule for AllJoyn Router traffic [TCP] | Local: Any Remote: Any |
TCP | Out | |
AllJoyn Router (UDP-In) | Inbound rule for AllJoyn Router traffic [UDP] | Local: Any Remote: Any |
UDP | In | |
AllJoyn Router (UDP-Out) | Outbound rule for AllJoyn Router traffic [UDP] | Local: Any Remote: Any |
UDP | Out |
Cast to Device
OS | Rule | Description | Port | Protocol | Direction |
---|---|---|---|---|---|
Windows Server 2016 Windows Server 2019 Windows Server 2022 |
Cast to Device functionality (qWave-TCP-In) | Inbound rule for the Cast to Device functionality to allow use of the Quality Windows Audio Video Experience Service. [TCP 2177] | Local: 2177 Remote: Any |
TCP | In |
Cast to Device functionality (qWave-TCP-Out) | Outbound rule for the Cast to Device functionality to allow use of the Quality Windows Audio Video Experience Service. [TCP 2177] | Local: Any Remote: 2177 |
TCP | Out | |
Cast to Device functionality (qWave-UDP-In) | Inbound rule for the Cast to Device functionality to allow use of the Quality Windows Audio Video Experience Service. [UDP 2177] |
Local: 2177 Remote: Any |
UDP | In | |
Cast to Device functionality (qWave-UDP-Out) | Outbound rule for the Cast to Device functionality to allow use of the Quality Windows Audio Video Experience Service. [UDP 2177] | Local: Any Remote: 2177 |
UDP | Out | |
Cast to Device SSDP Discovery (UDP-In) | Inbound rule to allow discovery of Cast to Device targets using SSDP | Local: Ply2Disc Remote: Any |
UDP | In | |
Cast to Device Streaming Server (HTTP-Streaming-In) | Inbound rule for the Cast to Device server to allow streaming using HTTP. [TCP 10246] | Local: 10246 Remote: Any |
TCP | In | |
Cast to Device Streaming Server (RTCP-Streaming-In) | Inbound rule for the Cast to Device server to allow streaming using RTSP and RTP. [UDP] | Local: Any Remote: Any |
UDP | In | |
Cast to Device Streaming Server (RTP-Streaming-Out) | Outbound rule for the Cast to Device server to allow streaming using RTSP and RTP. [UDP] | Local: Any Remote: Any |
UDP | Out | |
Cast to Device Streaming Server (RTSP-Streaming-In) | Inbound rule for the Cast to Device server to allow streaming using RTSP and RTP. [TCP 23554, 23555, 23556] | Local: 235, 542, 355, 523, 556 Remote: Any |
TCP | In | |
Cast to Device UPnP Events (TCP-In) | Inbound rule to allow receiving UPnP Events from Cast to Device targets | Local: 2869 Remote: Any |
TCP | In |
Core Networking
Delivery Optimization
OS | Rule | Definition | Port | Protocol | Direction |
---|---|---|---|---|---|
Windows Server 2019 Windows Server 2022 |
DeliveryOptimization-TCP-In | Inbound rule to allow Delivery Optimization to connect to remote endpoints. | Local: 7680 Remote: Any |
TCP | In |
DeliveryOptimization-UDP-In | Inbound rule to allow Delivery Optimization to connect to remote endpoints. |
Local: 7680 Remote: Any |
UDP | In |
Diag Track
DIAL Protocol Server
OS | Rule | Definition | Port | Protocol | Direction |
---|---|---|---|---|---|
Windows Server 2016 Windows Server 2019 Windows Server 2022 |
DIAL protocol server (HTTP-In) | Inbound rule for DIAL protocol server to allow remote control of Apps using HTTP. |
Local: 10247 Remote: Any |
TCP | In |
File and Printer Sharing
OS | Rule | Definition | Port | Protocol | Direction |
---|---|---|---|---|---|
Windows Server 2012 Windows Server 2012 R2 |
File and Printer Sharing (Echo Request - ICMPv4-In) | Echo Request messages are sent as ping requests to other nodes. |
Local: 5355 Remote: Any |
ICMPv4 |
In |
File and Printer Sharing (Echo Request - ICMPv4-Out) | Echo Request messages are sent as ping requests to other nodes. |
Local: 5355 Remote: Any |
ICMPv4 |
Out | |
File and Printer Sharing (Echo Request - ICMPv6-In) | Echo Request messages are sent as ping requests to other nodes. |
Local: 5355 Remote: Any |
ICMPv6 |
In | |
File and Printer Sharing (Echo Request - ICMPv6-Out) | Echo Request messages are sent as ping requests to other nodes. |
Local: 5355 Remote: Any |
ICMPv6 |
Out | |
File and Printer Sharing (LLMNR-UDP-In) | Inbound rule for File and Printer Sharing to allow Link Local Multicast Name Resolution. | Local: 5355 Remote: Any |
UDP | In | |
File and Printer Sharing (LLMNR-UDP-Out) | Outbound rule for File and Printer Sharing to allow Link Local Multicast Name Resolution. |
Local: Any Remote: 5355 |
UDP | Out | |
File and Printer Sharing (NB-Datagram-In) | Inbound rule for File and Printer Sharing to allow NetBIOS Datagram transmission and reception. |
Local: 138 Remote: Any |
UDP | In | |
File and Printer Sharing (NB-Datagram-Out) | Outbound rule for File and Printer Sharing to allow NetBIOS Datagram transmission and reception. |
Local: Any Remote: 138 |
UDP | Out | |
File and Printer Sharing (NB-Name-In) | Inbound rule for File and Printer Sharing to allow NetBIOS Name Resolution. |
Local: 137 Remote: Any |
UDP | In | |
File and Printer Sharing (NB-Name-Out) | Outbound rule for File and Printer Sharing to allow NetBIOS Name Resolution. |
Local: Any Remote: 137 |
UDP | Out | |
File and Printer Sharing (NB-Session-In) | Inbound rule for File and Printer Sharing to allow NetBIOS Session Service connections. | Local: 139 Remote: Any |
TCP | In | |
File and Printer Sharing (NB-Session-Out) | Outbound rule for File and Printer Sharing to allow NetBIOS Session Service connections. |
Local: Any Remote: 139 |
TCP | Out | |
File and Printer Sharing (SMB-In) | Inbound rule for File and Printer Sharing to allow Server Message Block transmission and reception via Named Pipes. | Local: 445 Remote: Any |
TCP | In | |
File and Printer Sharing (SMB-Out) | Outbound rule for File and Printer Sharing to allow Server Message Block transmission and reception via Named Pipes. |
Local: Any Remote: 445 |
TCP | Out | |
File and Printer Sharing (Spooler Service - RPC) | Inbound rule for File and Printer Sharing to allow the Print Spooler Service to communicate via TCP/RPC. | Local: RPC Remote: Any |
TCP | In | |
File and Printer Sharing (Spooler Service - RPC-EPMAP) | Inbound rule for the RPCSS service to allow RPC/TCP traffic for the Spooler Service. | Local: RPC-EPMap Remote: Any |
TCP | In |
File Server Remote Management
OS | Rule | Definition | Port | Protocol | Direction |
---|---|---|---|---|---|
Windows Server 2012 Windows Server 2012 R2 |
File Server Remote Management (DCOM-In) | Inbound rule to allow DCOM traffic to manage the File Services role. | Local: 135 Remote: Any |
TCP | In |
File Server Remote Management (SMB-In) | Inbound rule to allow SMB traffic to manage the File Services role. | Local: 445 Remote: Any |
TCP | In | |
WMI-In | Inbound rule to allow WMI traffic to manage the File Services role. | Local: RPC Remote: Any |
TCP | In |
ICMP v4 All
OS | Rule | Port | Protocol | Direction |
---|---|---|---|---|
Windows Server 2012 Windows Server 2012 R2 |
All ICMP v4 | Local: 139 Remote: Any |
ICMPv4 |
In |
Microsoft Edge
OS | Rule | Port | Protocol | Direction |
---|---|---|---|---|
Windows Server 2022 |
Microsoft Edge (mDNS-In) | Local: 5353 Remote: Any |
UDP |
In |
Microsoft Media Foundation Network Source
OS | Rule | Port | Protocol | Direction |
---|---|---|---|---|
Windows Server 2022 |
Microsoft Media Foundation Network Source IN [TCP 554] | Local: 554, 8554-8558 Remote: Any |
TCP |
In |
Microsoft Media Foundation Network Source IN [UDP 5004-5009] | Local: 5000-5020 Remote: Any |
UDP |
In | |
Microsoft Media Foundation Network Source OUT [TCP ALL] | Local: Any Remote: 554, 8554-8558 |
TCP |
In |
Multicast
Remote Desktop
WindowsDevice Management
WindowsFeature Experience Pack
OS | Rule | Definition | Port | Protocol | Direction |
---|---|---|---|---|---|
Windows Server 2022 |
WindowsFeature Experience Pack | WindowsFeature Experience Pack. | Any | Out |
WindowsFirewall Remote Management
OS | Rule | Definition | Port | Protocol | Direction |
---|---|---|---|---|---|
Windows Server 2012 R2 |
WindowsFirewall Remote Management (RPC) | Inbound rule for the WindowsFirewall to be remotely managed via RPC/TCP. |
Local: RPC Remote: Any |
TCP | In |
WindowsFirewall Remote Management (RPC-EPMAP) | Inbound rule for the RPCSS service to allow RPC/TCP traffic for the WindowsFirewall. |
Local: RPC-EPMap Remote: Any |
TCP | In |
WindowsRemote Management
OS | Rule | Definition | Port | Protocol | Direction |
---|---|---|---|---|---|
Windows Server 2012 Windows Server 2012 R2 Windows Server 2016 Windows Server 2019 Windows Server 2022 |
WindowsRemote Management (HTTP-In) | Inbound rule for WindowsRemote Management via WS-Management. | Local: 5985 Remote: Any |
TCP | In |
For more information about Amazon EC2 security groups, see Amazon EC2 Security Groups for WindowsInstances.