Firewall Requirements

The tables below detail the firewall rules required for Docbox. Rules marked Required must be in place for Docbox to function. Rules marked Optional are only needed if the relevant feature is in use.

All ports are configurable — contact CFH if you need to use non-standard ports.

Core Rules

These rules are required for all Docbox deployments.

Service Port Direction Required / Optional Purpose
SSH 22 Inbound Required Server administration and Docbox configuration or support access. Used by your IT team for ongoing server administration and Docbox configuration. Access should be restricted to trusted, approved administrative networks, including CFH's network where applicable.
HTTPS 443 Inbound Required Users submitting print jobs via the Print Driver / File Agent and accessing the Docbox Dashboard. We recommend restricting access to internal traffic only.
DNS 53 Outbound Optional Resolving CFH service addresses. Optional but recommended.

The rules required depend on how your organisation submits jobs to CFH for fulfilment. CFH will confirm which applies to your setup.

Docmail integration

Service Port Direction Required / Optional Purpose
HTTPS 443 Outbound Required Docbox submitting print jobs to CFH Docmail for printing and posting.

SFTP (CFH Managed)

Service Port Direction Required / Optional Purpose
SFTP 22 Outbound Required Docbox uploading print job batches to CFH for fulfilment.

HSCN

Service Port Direction Required / Optional Purpose
SFTP 22 Outbound Required Docbox uploading print job batches to CFH via the HSCN network. Contact CFH for the specific endpoint details.

Email Notifications (optional)

Required only if email notifications are enabled in the Control Panel.

Service Port Direction Required / Optional Purpose
SMTP 25, 465, or 587 Outbound Optional Docbox sending job status notifications to users. Connects to the server configured in Email Settings.

Active Directory integration (optional)

Required only if LDAP / Active Directory integration is enabled. All communication is internal to your network and does not require access to external resources. See LDAP Settings.

Service Port Direction Required / Optional Purpose
LDAP 389 Outbound Optional Querying the local AD catalogue.
LDAP 3268 Outbound Optional Querying the Global Catalogue.
LDAPS 636 Outbound Optional Securely querying the local AD catalogue.
LDAPS 3269 Outbound Optional Securely querying the Global Catalogue.