Home
EN
Location
Documentation Home
Palo Alto Networks
Support
Live Community
Knowledge Base
>
Clear
Ports Used for IPSec
Updated on
Aug 28, 2025
Focus
Download PDF
Updated on
Aug 28, 2025
Focus
Home
Next-Generation Firewall
Firewall Administration
Reference: Port Number Usage
Ports Used for IPSec
Download PDF
Next-Generation Firewall
Ports Used for IPSec
Table of Contents
Filter
Expand All
|
Collapse All
Next-Generation Firewall Docs
Getting Started
Administration
Networking
Quick Start
Reference
Incidents & Alerts
Release Notes
Select a Document
PAN-OS 12.1
PAN-OS 11.2
PAN-OS 11.1
PAN-OS 11.0 (EoL)
PAN-OS 10.2
PAN-OS 10.1
PAN-OS 10.0 (EoL)
PAN-OS 9.1 (EoL)
PAN-OS 9.0 (EoL)
PAN-OS 8.1 (EoL)
Help
Select a Document
PAN-OS 12.1
PAN-OS 11.2
PAN-OS 11.1
PAN-OS 10.2
PAN-OS 10.1
Previous
Ports Used for User-ID
Next
Ports Used for Routing
Ports Used for IPSec
Ports used by IPSec protocols including IKE (Internet Key Exchange) and keymgr for VPN tunnel establishment and management.
The firewall and Panorama use the following ports for IPSec functions.
Destination Port
Protocol
Description
500
UDP
Port used by IKE on the management plane to connect with remote IKE peers.
4500
UDP
Port used by IKE on the management plane to connect with remote IKE peers.
4510
UDP
Port used by the dataplane to send requests to IKE.
4511
UDP
Port used by the dataplane to send requests to
keymgr
.
Previous
Ports Used for User-ID
Next
Ports Used for Routing