- Getting Started
- Requirements
- Best Practices
- Installation
- Updating
- Identity Server
- Troubleshooting startup errors
Configuring the Firewall
Required firewall ports and network communication settings for a functioning Orchestrator deployment
For a properly functioning Orchestrator deployment, you must ensure all required ports are open in your firewall to allow communication between all components, as shown in this architecture diagram:
Figure 1. UiPath Orchestrator network diagram
Each port and its use is described below:
443- Communication between Users and Orchestrator with the connected Robots. You can select a different HTTPS port for Orchestrator, if desired.Note:This port is open by default, unless closed by your security administrator.
1433- The default port for communication between Orchestrator and the SQL Server machine. You can select a different port, ensuring that it is open in the firewall.10000- Communication between Orchestrator and the HAA.9200- Communication between Orchestrator and the Elasticsearch server.Note:This port can be opened for Orchestrator only, as no other machine can access the Elasticsearch server directly.
9300- Communication between Elasticsearch nodes.5601- Default port used by Kibana. It must be opened on the machine where Kibana is installed.
Not pictured above
3389- Required for RDP automation, needed for HD Robots.80- Required for the Webhooks web service.
Outbound connections
A standalone Orchestrator installation serves the host Libraries feed from inside Orchestrator, using the activity packages that come with the installer, and needs no outbound internet access for it. If you point the Libraries feed at the official UiPath® feed instead, Orchestrator and the robot machines reach that feed over the internet. If your network restricts outbound traffic to an allowlist, the following hostnames must then be on it.
| Hostname | Protocol | Port | Application | Used for |
|---|---|---|---|---|
pkgs.uipath.com | TCP | 443 | HTTPS | The official UiPath® package feed, at https://pkgs.uipath.com/official/index.json. This is the new address of the feed. |
pkgs.dev.azure.com | TCP | 443 | HTTPS | The previous, Azure DevOps-hosted address of the official UiPath® package feed, at https://pkgs.dev.azure.com/uipath/Public.Feeds/_packaging/UiPath-Official/nuget/v3/index.json. The same feed also answers on uipath.pkgs.visualstudio.com, so allow the address your Libraries feed is configured with. It stays required until your deployment moves to the new address. |
These rules apply to the Orchestrator server nodes, which read the feed to list packages on the Libraries page, and to the robot machines, which download packages directly from the feed address that Orchestrator sends them.
You set the feed from the Deployment tab of the host or tenant settings. For the available feed types, see About Libraries and Settings - Tenant Level.
pkgs.uipath.com is the specific host that serves the official feed, and it is the entry used across the UiPath® documentation. A broader *.uipath.com rule also covers it, along with every other UiPath® endpoint, if your network policy favors domain-level rules.