Bitdefender GravityZone (cloud console) is a cloud-based malware protection service developed by Bitdefender for computers running Microsoft Windows and Macintosh operating systems. It uses a centralized Software-as-a-Service multiple deployment model suitable for enterprise customers, while leveraging field-proven malware protection technologies developed by Bitdefender for the consumer market.
The following table provides information on the ports used by Bitdefender GravityZone components:
| Component | Direction | Port | Source / Destination | Description | ||||
| Web Console | Inbound | 80 (HTTP) | Any | Access to the Control Center web console, redirect to 443 | ||||
| 443 (HTTPS) | Any | Access to the Control Center web console | ||||||
| Endpoint Security / Bitdefender Endpoint Security Tools (BEST) | Outbound | 80 | submit.bitdefender.com | Port used for submitting endpoint dumps in case of crashes | ||||
| upgrade.bitdefender.com update.cloud.2d585.cdn.bitdefender.net |
The official Bitdefender update servers | |||||||
| lv2.bitdefender.com | License validation | |||||||
| 53 | *.v1.bdnsrt.org | DNS requests for signature update checks | ||||||
| 389 | Domain Controller | Integration with Active Directory (for Active Directory Integrator only) | ||||||
| 7074 | Update Server | Downloading updates from Update Server | ||||||
| Endpoint Security Relay / BEST Relay (if available) | Downloading installation packages in the deployment phase from Endpoint Security Relay / BEST Relay Communication messages received from endpoints linked to Endpoint Security Relay / BEST Relay |
|||||||
| 7076 | Bitdefender Cloud Servers: nimbus.bitdefender.net/elam/blob |
Encrypted communication messages (when Endpoint Security Relay / BEST Relay is used as a proxy) | ||||||
| 443 | Web Server | Downloading installation packages during deployment (Setup Downloader) | ||||||
| Communication Server | Link between Endpoint Security/BEST and Communication Server | |||||||
| nimbus.bitdefender.net/elam/blob | Early Launch Anti-Malware (ELAM) cloud server | |||||||
| nimbus.bitdefender.net | Antimalware, antiphishing and content control scanning with Bitdefender Cloud Servers | |||||||
| Inbound | N/A | N/A | N/A | |||||
| Endpoint Security Relay / Bitdefender Endpoint Security (BEST) Relay | Outbound | 80 | submit.bitdefender.com | Port used for submitting endpoint dumps in case of crashes | ||||
| upgrade.bitdefender.com update.cloud.2d585.cdn.bitdefender.net |
The official Bitdefender update servers | |||||||
| lv2.bitdefender.com | License validation | |||||||
| 53 | *.v1.bdnsrt.org | DNS requests for signature update checks | ||||||
| 389 | Domain Controller | Integration with Active Directory (for Active Directory Integrator only) | ||||||
| 7074 | Update Server | Downloading updates from Update Server | ||||||
| Endpoint Security Relay / BEST Relay* (if available) | Downloading installation packages in the deployment phase from Endpoint Security Relay / BEST Relay Communication messages received from endpoints linked to Endpoint Security Relay / BEST Relay |
|||||||
| 7076 | Bitdefender Cloud Servers: nimbus.bitdefender.net/elam/blob |
Encrypted communication messages received from endpoints linked to Endpoint Security Relay / BEST Relay | ||||||
| 443 | Web Server | Downloading installation packages during deployment (Setup Downloader) | ||||||
| Communication Server | Link between Endpoint Security/BEST Relay and Communication Server | |||||||
| nimbus.bitdefender.net/elam/blob | Early Launch Anti-Malware (ELAM) cloud server | |||||||
| nimbus.bitdefender.net | Antimalware, antiphishing and content control scanning with Bitdefender Cloud Servers | |||||||
| Inbound | 7074 | Endpoint Security, BEST | Communication messages (such as settings and events) received from endpoints linked to Endpoint Security Relay / BEST Relay | |||||
| 7076 | Bitdefender Cloud Servers: nimbus.bitdefender.net/elam/blob |
Encrypted communication messages received from endpoints linked to Endpoint Security Relay / BEST Relay | ||||||
| Security Server (Multi-Platform) | Outbound | 443 | nimbus.bitdefender.net | Periodical verification of antimalware detections with Bitdefender Cloud Servers | ||||
| Communication Server | Link between Security Server and Communication Server | |||||||
| 7074 | Update Server | Downloading updates from Update Server | ||||||
| Inbound | 7081 | Any | Antimalware traffic scanning sent by Bitdefender Tools / BEST | |||||
| 7083 | Any | Antimalware traffic scanning sent by Bitdefender Tools / BEST over SSL |
* Since the relay is an update server that needs to listen all the time on a port, Bitdefender provides a mechanism able to automatically open a random port on localhost (127.0.0.1), so that the update server can receive proper configuration details. This mechanism applies when the default port 7074 is used by another application. In this case, the update server tries to open the 7075 port to listen on localhost. If 7075 port is also unavailable, the update server will search for another port that is free (in range of 1025 to 65535) and successfully bind to listen on localhost.
