The tables below detail the firewall rules required for Docbox. Rules marked Required must be in place for Docbox to function. Rules marked Optional are only needed if the relevant feature is in use.
All ports are configurable — contact CFH if you need to use non-standard ports.
Core Rules
These rules are required for all Docbox deployments.
| Service | Port | Direction | Required / Optional | Purpose |
|---|---|---|---|---|
| SSH | 22 | Inbound | Required | Server administration and Docbox configuration or support access. Used by your IT team for ongoing server administration and Docbox configuration. Access should be restricted to trusted, approved administrative networks, including CFH's network where applicable. |
| HTTPS | 443 | Inbound | Required | Users submitting print jobs via the Print Driver / File Agent and accessing the Docbox Dashboard. We recommend restricting access to internal traffic only. |
| DNS | 53 | Outbound | Optional | Resolving CFH service addresses. Optional but recommended. |
Print processing
The rules required depend on how your organisation submits jobs to CFH for fulfilment. CFH will confirm which applies to your setup.
Docmail integration
| Service | Port | Direction | Required / Optional | Purpose |
|---|---|---|---|---|
| HTTPS | 443 | Outbound | Required | Docbox submitting print jobs to CFH Docmail for printing and posting. |
SFTP (CFH Managed)
| Service | Port | Direction | Required / Optional | Purpose |
|---|---|---|---|---|
| SFTP | 22 | Outbound | Required | Docbox uploading print job batches to CFH for fulfilment. |
HSCN
| Service | Port | Direction | Required / Optional | Purpose |
|---|---|---|---|---|
| SFTP | 22 | Outbound | Required | Docbox uploading print job batches to CFH via the HSCN network. Contact CFH for the specific endpoint details. |
Email Notifications (optional)
Required only if email notifications are enabled in the Control Panel.
| Service | Port | Direction | Required / Optional | Purpose |
|---|---|---|---|---|
| SMTP | 25, 465, or 587 | Outbound | Optional | Docbox sending job status notifications to users. Connects to the server configured in Email Settings. |
Active Directory integration (optional)
Required only if LDAP / Active Directory integration is enabled. All communication is internal to your network and does not require access to external resources. See LDAP Settings.
| Service | Port | Direction | Required / Optional | Purpose |
|---|---|---|---|---|
| LDAP | 389 | Outbound | Optional | Querying the local AD catalogue. |
| LDAP | 3268 | Outbound | Optional | Querying the Global Catalogue. |
| LDAPS | 636 | Outbound | Optional | Securely querying the local AD catalogue. |
| LDAPS | 3269 | Outbound | Optional | Securely querying the Global Catalogue. |