This article outlines the required minimum firewall openings for default Peppol components.
This list does not consider application specific firewall requirements.
Please also remember the "connect once, connect everywhere" principle of Peppol, meaning that every
Peppol AccessPoint (AP) MUST be capable of exchanging business documents with any other Peppol AP.
443 to * (all IPs) - for sending messages to another AP80 to * (all IPs) - for querying any SMP and to download CRL files from http://crl.one.nl.digicert.com/:
http://crl.one.nl.digicert.com/PEPPOLACCESSPOINTTESTCA-G3.crlhttp://crl.one.nl.digicert.com/PEPPOLSERVICEMETADATAPUBLISHERTESTCA-G3.crlhttp://crl.one.nl.digicert.com/PEPPOLACCESSPOINTCA-G3.crlhttp://crl.one.nl.digicert.com/PEPPOLSERVICEMETADATAPUBLISHERCA-G3.crl80 to download CRL files from http://crl.one.nl.digicert.com/ (see AP section above for specific URLs)443 to Peppol Directory
directory.peppol.eutest-directory.peppol.eu443 to SMK/SML
participant.sml.prod.tech.peppol.orgparticipant.sml.test.tech.peppol.org443 from * (all IPs) - for receiving messages from another AP443 from * (all IPs) - for being queried from any AP