Ports and encryption
The Front-end server is accessed by a variety of clients and from multiple locations. For performance and security reasons, they are divided into two groups:
- Clients inside the firewall (LAN)
- Clients outside the firewall (WAN)
To support these groups, the Front-end server has two ports: an internal port and a public port, shown below as I and P1. The two ports deliver the same functionality to all clients, but the public port doesn’t allow access to statistics (/statistics), the log file (/log), and the info page (/Info/all). The internal port is the main port of the Front-end server and is used to access the server from within the organization.

The base agents are given one or two addresses for communication with the Front-end server:
- An address to the internal port I (FrontendServiceInternalUrl). This is the main and preferred port.
- An address to the public port P2 (FrontendServicePublicUrl). The base agent fails over to this port if the internal port is unavailable, for example when the employee works from home or the computer is at a remote location without a VPN connection.
The firewall must redirect incoming calls on P2 to the Front-end P1.
Default ports
Section titled “Default ports”When you deploy a new Front-end service, the Service Deployment wizard suggests port 5021 for the internal URL. If no public URL is configured, the service uses port 5022 for the public port. For HTTPS, the default port is 443. Existing installations keep the ports they were set up with.
To change the ports, edit the URLs in System Administration: right-click the Front-end service, select Service Settings, and open the Communication tab. The Internal Url(s) and Public Url(s) fields hold the URLs, including the port. Restart the service after you change them.
For all CapaInstaller ports, see CapaInstaller Network Port Reference.

Encryption
Section titled “Encryption”To protect the traffic between agents and the Front-end server, use HTTPS URLs with an SSL certificate. See Use HTTPS in Backend, Frontend & OS Deployment Service.
The command-line arguments /internalencryption and /publicencryption from earlier versions are no longer supported.