Spotfire® Server and Environment Security

Outbound Connections

The following outbound connections might differ from your deployed system, because connections depend on the configuration of the particular environment. For example, the Spotfire Server creates LDAP connections only if the system is configured to use LDAP.

Table 1. Spotfire Server
Type of connection Default port Function Secure/ Encrypted
Database communication Oracle database: 1521

SQL Server: 1433

PostgreSQL: 5432

The Spotfire database server monitors this port. If configured
LDAP LDAP over TLS: 389

LDAPS: 636.

An optional number that indicates the TCP port that the LDAP service is monitoring. If configured
LDAP > Global Catalog LDAP: 3268

LDAPS: 3269

Active Directory LDAP servers also provide a Global Catalog that contains forest-wide information, instead of domain-wide information only. If configured
TIBCO Enterprise Message Service (EMS) Non-secure connection: 7222

Secure connection: 7243

This service can be used to trigger scheduled updates. EMS monitors this port. If configured
Kerberos/GSSAPI Fixed port 88 on the Active Directory domain controllers Used by the Kerberos authentication method, as well as when authenticating to an LDAP server using the GSSAPI method. Yes
Microsoft Net Logon, SMB, and CIFS Fixed port 445 on the Active Directory domain controllers Used by the NTLM v2 authentication method. Yes
Open ID Connect providers 443 Used by the web authentication method. Yes
Data sources (Information Services) Oracle database: 1521

SQL Server: 1433

Netezza: 5480

Otherwise, varies.

JDBC-compliant data sources and other services used by Information Services monitor these ports. Varies
Spotfire Community authorization 443 Used for obtaining access tokens to be used when the Spotfire Web Player service connects to the Spotfire Community via the assets.spotfire.com host. Yes
Table 2. Node manager/Services
Type of connection Default Function Secure/ Encrypted
Spotfire Web Player & Spotfire Automation Services > Map/tiles server connections The default map layer uses https://geoanalytics.tibco.com/ The map chart downloads map tiles and other information from external servers. Yes
Spotfire Web Player & Spotfire Automation Services > SMTP 25, 2525, or 587

Secure SMTP: 465, 25, or 587

Used by Spotfire Automation Services for sending e-mails. Secure if configured
Spotfire Web Player & Spotfire Automation Services > Data sources (Connectors) Varies For information on available connectors, see 'Supported data sources' in the Spotfire User Guide. Data connectors listen to these ports. Varies
Spotfire Web Player > Spotfire Community 443 Used for browsing for add-ons such as visualization mods, action mods, and demos on the Spotfire Community via the assets.spotfire.com host. Yes
Table 3. Spotfire application for Windows
Type of connection URL Function Secure/ Encrypted
TERR Tools and TERR console CRAN access The tools requires access to the URL https://cran.r-project.org/CRAN_mirrors.csv or http://cran.r-project.org/CRAN_mirrors.csv.

One of these URLs must be available from the computer running the client and cannot be blocked by firewalls.

Used for downloading CRAN packages from CRAN or a repository site mirror, to be used in TERR or R data functions.

See also TERR tools – Package Management in the Spotfire® User Guide.

Varies (yes if https works, no if the backup http is used)