Loading...
Port | Protocol | Direction | Configurable | Default scope Purpose | |
|---|---|---|---|---|---|
4440 (HTTP, default) | TCP | Inbound to Buttons | Yes: Environment Settings | localhost only, until you widen itThe editor UI, and the web frontend | |
4443 (HTTPS, default) | TCP | Inbound to Buttons | Yes: Environment Settings | Same as HTTP HTTPS for the same traffic, defaults to the HTTP port plus three | |
5353 | UDP (multicast) | Bidirectional | Network | mDNS: discovering NMOS nodes and third-party network surfaces, and being discovered by them. Standard mDNS, not configurable. It needs to actually reach whatever subnet your NMOS devices or network surfaces sit on. mDNS doesn't route across VLANs by itself. | |
Tip:4440and4443are defaults, not fixed: both can be changed. For the packaged app, change them live from its own Environment Settings screen. For headless Linux, set them on first launch with theWWW_PORT/WWW_HTTPS_PORTenvironment variables or a different port argument towatchdog-cli. See the Startup configuration reference for every option. Whatever port you actually end up running on (not necessarily4440/4443) is the one your firewall rule and any port forwarding need to match.
By default, neither port is reachable from the network: nothing but the local machine can reach Buttons until you explicitly widen the listen address to all interfaces, covered in "Allow access from other computers" (First-time setup guide).
3040 TCP by default. Its default server mode listens for Buttons to find and connect to it: open 3040 on that machine, not the Buttons host, for this default case. It can instead be set to an outbound mode (-buttonsAddress), where the relay machine connects out to Buttons itself. In that mode, 3040 isn't used at all, and the connection is inbound to Buttons on its own editor port instead, same as the first table above. Check which mode a given relay is actually running in rather than assuming.12001 TCP by default, outbound from Buttons only (see "Connect to Bitfocus Listener" in the main documentation). The inbound rule for this one belongs on the Listener's machine, not the Buttons host.443), needing no special firewall rule beyond normal internet access: updates.bitfocus.io for update checks, and api.bitfocus.io for license activation and validation.80/443): that's the one pair of ports a facility firewall needs to know about for this deployment path. Every other port on this page, including Postgres, Redis, and the internal leader-election endpoints, stays inside the cluster network in both directions and needs no facility-network firewall rule.Was this helpful?
0 of 0 users found this page helpful