diff --git a/en/docs/install-and-setup/setup/deployment-best-practices/security-guidelines-for-production-deployment.md b/en/docs/install-and-setup/setup/deployment-best-practices/security-guidelines-for-production-deployment.md index a7582338f8..d322dd7c9c 100644 --- a/en/docs/install-and-setup/setup/deployment-best-practices/security-guidelines-for-production-deployment.md +++ b/en/docs/install-and-setup/setup/deployment-best-practices/security-guidelines-for-production-deployment.md @@ -909,7 +909,8 @@ This section provides a list of security guidelines for configuring the network
Check open ports and services
Periodically check for open ports using port scanning tools and make sure that only the necessary ports are open to both internal and external networks. Be sure that only the ports relevant to your WSO2 products are open for communication. If there are other ports started, be sure to monitor them.
-For the full list of ports in all WSO2 products, see Default Product Ports.
For the full list of ports in all WSO2 products, see Default Product Ports.
+Note: Some ports may be dynamically allocated during server operations. When monitoring open ports, verify that any dynamic ports are expected and properly secured according to your deployment requirements. Dynamic port allocation can occur due to specific runtime configurations, JMX monitoring, clustering, and other operational requirements.
Configure device-level security
10711
+ 9099
@@ -93,6 +101,38 @@ Listed below are the ports used by the API-M runtime when the [port offset]({{ba
Web Socket ports.
8099
+ 9021
+ 8021
+ 8672
+ 8000