SysAdminDoc/ESET
GitHub: SysAdminDoc/ESET
ESET 端点安全产品的完整端口与地址参考库,提供结构化数据和多种防火墙平台的即用型导出配置,解决托管环境下的网络策略精确配置与连通性验证问题。
Stars: 0 | Forks: 0
# ESET 端口与地址参考


完整的 ESET endpoint 安全端口和地址参考列表,用于防火墙配置和网络策略管理。系统管理员在托管环境中部署 ESET 的必备指南。
## 目录
### 原始列表
- `Addresses.txt` -- 按 ESET 服务类别分组的所有 IP 地址
- `Domains.txt` -- 按 ESET 服务类别分组的所有 FQDN
### 各服务文件 (`services/`)
按逻辑 ESET 服务层级拆分,用于制定针对性的防火墙规则:
| 文件 | 涵盖范围 |
|------|--------|
| `services/updates.txt` | 检测引擎更新、微型更新 (pico updates)、产品安装程序 |
| `services/endpoint.txt` | 反垃圾邮件、Web 控制、防盗、密码管理器、ESA、SSL 检查 |
| `services/protect-console.txt` | 本地部署与云端的 PROTECT、EPNS、MDM、MSP、Syslog、ESET Connect |
| `services/livegrid.txt` | LiveGrid 信誉评估、高级机器学习 (Augur) |
| `services/edtd.txt` | EDTD/LiveGuard 沙盒、威胁遥测、ESET Inspect (XDR) |
| `services/activation.txt` | 授权许可、激活、版本检查、PKI、遥测 |
### 机器可读数据
- `eset-endpoints.json` -- 结构化 JSON,包含以下字段:`service`、`category`、`hosts`、`ips`、`ipv6`、`ports`、`protocol`、`direction`、`notes`、`source`
### 防火墙导出格式 (`exports/`)
适用于常见防火墙平台的即用型导入文件:
| 文件 | 平台 |
|------|----------|
| `exports/pfsense-aliases.xml` | pfSense / OPNsense 别名导入 |
| `exports/fortigate-addresses.conf` | FortiGate 地址对象 + 用户组 CLI |
| `exports/paloalto-addresses.xml` | Palo Alto Networks 地址组 XML |
| `exports/mikrotik-addresslist.rsc` | MikroTik RouterOS `/ip firewall address-list` 脚本 |
| `exports/cisco-asa-objects.txt` | Cisco ASA / Firepower object-group 配置 |
| `exports/windows-firewall.cmd` | Windows 防火墙 `netsh advfirewall` 批处理脚本 |
| `exports/eset-allowlist-hosts.txt` | 用于 DNS 白名单 / 代理绕过的纯 FQDN 列表 |
### 工具
- `Generate-Exports.ps1` -- 从 `eset-endpoints.json` 重新生成所有导出文件
- `Test-ESETReachability.ps1` -- 从当前主机测试与每个列出 endpoint 的连通性
## 用法
### 快速入门
直接使用各服务文件或导出文件。将其导入您的防火墙管理工具,或在 ESET 部署期间作为参考。
### 重新生成导出文件
在编辑 `eset-endpoints.json` 后,重新生成所有导出格式:
```
.\Generate-Exports.ps1
```
### 测试连通性
验证您的网络是否能访问所有必需的 ESET endpoint:
```
# 测试所有端点 (TCP connect)
.\Test-ESETReachability.ps1
# 仅测试 update servers
.\Test-ESETReachability.ps1 -Service updates
# 快速仅 DNS 检查
.\Test-ESETReachability.ps1 -DnsOnly
```
### 架构
- `architecture.mmd` -- Mermaid 图表,展示了 Endpoint 到 PROTECT、再到 LiveGrid、最后到 Update 的流程,并标注了每一跳的端口。可使用任何兼容 Mermaid 的查看器进行渲染,或将其粘贴到 [mermaid.live](https://mermaid.live)。
## 故障排除清单
### 更新失败
1. 测试 DNS 解析:`nslookup update.eset.com`
2. 测试到更新服务器的 TCP 443 端口连接:`Test-NetConnection update.eset.com -Port 443`
3. 测试 TCP 80 回退连接:`Test-NetConnection update.eset.com -Port 80`
4. 如果使用 ESET Bridge/代理,请验证 `login.microsoftonline.com:443` 是否可访问
5. 检查 `pico.eset.com:443` 以获取微型更新分发
6. 运行 `.\Test-ESETReachability.ps1 -Service updates` 进行全面检查
### LiveGrid 无法工作
1. 测试 DNS:`nslookup livegrid.eset.systems`
2. 测试 TCP 443 端口连接:`Test-NetConnection c.eset.com -Port 443`
3. 测试基于 DNS 的查询:`nslookup e5.sk`(必须解析成功)
4. 验证到 ESET DNS 服务器的出站 UDP 53 未被阻止
5. 运行 `.\Test-ESETReachability.ps1 -Service livegrid`
### 激活 / 许可证问题
1. 测试 `expire.eset.com:443`
2. 测试 `proxy.eset.com:443`(激活代理)
3. 测试 `pki.eset.com:443`(证书验证)
4. 对于移动设备:测试 `reg01.eset.com` 到 `reg04.eset.com`
5. 运行 `.\Test-ESETReachability.ps1 -Service activation`
### PROTECT 控制台无法连接到 Agent
1. 验证 EPNS broker 连通性:`Test-NetConnection h1-epnsbroker01.eset.com -Port 8883`
2. 对于云端:测试 `protect.eset.com:443` 和您所在区域的 endpoint(例如 `us02.protect.eset.com`)
3. 对于 MDM:测试 `checkin..mdm.eset.com:443`
4. 运行 `.\Test-ESETReachability.ps1 -Service protect-console`
### EDTD / LiveGuard 沙盒未处理
1. 测试 `r.edtd.eset.com:443`(结果检索)
2. 测试 `d.edtd.eset.com:443`(文件提交)
3. 验证威胁遥测:`Test-NetConnection tsm09.eset.com -Port 443`
4. 运行 `.\Test-ESETReachability.ps1 -Service edtd`
## 端口参考摘要
| 端口 | 协议 | 使用者 |
|------|----------|---------|
| 80/tcp | HTTP | 更新(回退)、仓库下载 |
| 443/tcp | HTTPS | 所有服务(主要) |
| 53/udp | DNS | LiveGrid 信誉评估、反垃圾邮件查询 |
| 8883/tcp | MQTT/TLS | EPNS 推送通知 |
| 8443/tcp | HTTPS | PROTECT Cloud agent 通信 |
| 5228/tcp | FCM | 通过 Firebase Cloud Messaging 的 Android 推送 |
| 2195-2196/tcp | APNs | 通过 Apple Push Notification service 的 iOS 推送 |
| 6710-6711/tcp | TCP | 反垃圾邮件灰名单数据库 |
| 514/tcp | Syslog | PROTECT Cloud syslog 转发 |
| 601/tcp | Syslog/TCP | PROTECT Cloud syslog(可靠传输) |
| 6514/tcp | Syslog/TLS | PROTECT Cloud syslog(加密) |
| 21/tcp | FTP | 旧版 FTP 访问 (ftp.eset.sk) |
| 25/tcp | SMTP | 来自 ESET 通知服务器的入站电子邮件 |
## 来源
根据 ESET 官方文档编写,并已在生产环境中验证。主要来源:[ESET KB332](https://support.eset.com/en/kb332)。
## 许可证
MIT 许可证
标签:AI合规, ESET, Homebrew安装, 系统运维, 网络安全, 网络策略, 网络配置, 防火墙, 隐私保护