Configuring the firewall
As of Eplan License Manager Version 2026 no port ranges are required anymore for the configuration of the firewall. A maximum of three ports are required. Default values are set at them during installation and in Eplan License Manager - Configurator Version 2026. You can customize these preset ports.
Default port for communication between server and client: | 9363 |
Default port for communication between the server and failover: | 9364 |
Default port for reporting (only contained in the Eplan License Manager Professional module package): | 9365 |
Depending on the functions used, you set up a rule for each port in the firewall. The following section describes two ways to configure the Windows Defender Firewall for the server / client connection.
Configuring Windows Firewall with advanced security
- Open the configuration program for the Windows Defender Firewall via Start > Run.
- In the Run dialog enter the
wf.msc command. - Select Incoming rules and the New rule... action.
- Select the Port rule type. Continue clicking.
- Select TCP and enter Port 9363 in the Specific local ports field. Continue clicking.
- Select Allow connection. Continue clicking.
- Activate the selection Domain and Private. Continue clicking.
- Assign a name for the rule and confirm the settings.
The Windows Defender Firewall with Advanced Security dialog opens.
The wizard for new incoming rules is opened.
Repeat this process for the outgoing rule and, if further functions are used, for further ports.
Configuring the permission of an app
- Open the Windows security dialog in Windows.
- Select the Firewall & network protection menu item.
- Select the Allow an app through firewall menu item.
- Click on Allow another app....
- Navigate to the installation directory of the Eplan License Manager C:\Program Files\EPLAN\ELM and select the file Elm.exe
- Click on Add and allow communication.
The Allowed apps dialog opens.
Repeat steps 4 to 5 for the other four applications in the Eplan License Manager installation directory.
Optional: Activating logging of the accesses
In the case of a blocked access a log file is written which is stored in the following file path:
If this file does not exist, you must enable logging in the Windows Defender Firewall as follows:
- Open the configuration program for the Windows Defender Firewall via Start > Run.
- In the Run dialog enter the
wf.msc command. - Open the popup menu of Windows Defender Firewall with Advanced Security on Local Computer and select the Properties menu item.
- Use the Customize button to activate the logging.
- Select the Yes setting in both drop-down lists Log dropped packets and Log successful connections.
- Also select these firewall settings for the Private profile and the Public profile profiles.
- Open the
pfirewall.log. file and check which entry is identified by the firewall as "DROP".
The Windows Defender Firewall with Advanced Security dialog opens.
The domain profile is displayed.
Example
An entry generated by the Eplan License Client can look like this:
Configuring the firewall (up to Version 2025)
Two variants are described in the following sections. It is assumed that a group called "
Configuring the firewall for the Eplan License Manager "ELM.exe " ("Windows Security")
Port 135 is used to contact the "Distributed Component Object Model" (DCOM). Using a handshake method, this determines a dynamic port that is foreseen for use with the Eplan License Manager.
The
When a failover is used, you must also configure the
You can carry out a simple configuration via the settings of the "Windows security":
- Open the Windows settings via Start > Settings.
- Open the Update and security settings.
- Click Windows security.
- Click the Open Windows Security button.
- Select Firewall & network protection and Allow an app through rirewall.
- Click the Change settings button.
- Click the Allow another app button.
- Click Browse.
- Change to the
C:\Program Files\Eplan\ELM directory. - Select the
ELM.exe file. - Click the Open button.
- Click the Add button.
- Activate the Private and Public check boxes.
- Click OK.
- The firewall for the
ELM.exe file is configured.
The Add app dialog opens.
The Eplan Remote Dongle Service entry is added.
Configuring the firewall for the failover
When a failover is used, you must also configure the
You can carry out a simple configuration via the settings of the "Windows security":
1. Configuring "ELMConfig.exe "
- Open the Windows settings via Start > Settings.
- Open the Update and security settings.
- Click Windows security.
- Click the Open Windows Security button.
- Select Firewall & network protection and Allow an app through rirewall.
- Click the Change settings button.
- Click the Allow another app button.
- Click Browse.
- Change to the
C:\Program Files\Eplan\ELM directory. - Select the
ELMConfig.exe file. - Click the Open button.
- Click the Add button.
- Activate the Private and Public check boxes.
- Click OK.
- The firewall for the
ELMConfig.exe file is configured.
The Add app dialog opens.
The Eplan Remote Dongle Service entry is added.
2. Activate ICMPv4 and ICMPv6
- Open the configuration program for the Windows Defender Firewall via Start > Run.
- In the Run dialog enter the
wf.msc command. - Open Incoming rules.
- Select the following entries from the Incoming rules list:
- Core network diagnostics - ICMP echo request (
ICMPv4 incoming) - Core network diagnostics - ICMP echo request (
ICMPv6 incoming) - File and printer release (echo request -
ICMPv4 incoming) - File and printer release (echo request -
ICMPv6 incoming) - Open the Properties.
- Activate the Activated check box.
- The firewall for
ICMPv4 andICMPv6 is configured.
The Windows Defender Firewall with Advanced Security dialog opens.
Configuring the firewall for "COM+ - network access (DCOM)"
You can carry out a simple configuration via the settings of the "Windows security":
- Open the configuration program for the Windows Defender Firewall via Start > Run.
- In the Run dialog enter the
wf.msc command. - Open Incoming rules.
- Select the "Object COM+ network access (DCOM-In)" entry in the Incoming rules list.
- Open the Properties.
- Activate the Activated check box.
- The firewall for COM+ - network access (DCOM) is configured.
The Windows Defender Firewall with Advanced Security dialog opens.
Optional: Activating logging of the accesses
In the case of a blocked access a log file is written which is stored in the following file path:
If this file does not exist, you must enable logging in the Windows Defender Firewall as follows:
- Open the configuration program for the Windows Defender Firewall via Start > Run.
- In the Run dialog enter the
wf.msc command. - Open the popup menu of Windows Defender Firewall with Advanced Security on Local Computer and select the Properties menu item.
- Use the Customize button to activate the logging.
- Select the Yes setting in both drop-down lists Log dropped packets and Log successful connections.
- Also select these firewall settings for the Private profile and the Public profile profiles.
- Open the
pfirewall.log. file and check which entry is identified by the firewall as "DROP".
The Windows Defender Firewall with Advanced Security dialog opens.
The domain profile is displayed.
Example
An entry generated by the Eplan License Client can look like this:
Important
Make sure to select the "Yes" setting for the profiles of the firewall rules "Domain", "Private" and "Public".
For further information on the configuration of the "Port range" for external firewalls, please refer to the manufacturer's documentation, for example here.