关于Corda中消息队列通信所需开放防火墙端口的技术咨询
Corda节点消息队列通信的防火墙端口配置
Great question! When working with Corda's inter-node communication via its embedded Artemis message queue, the ports you need to open depend on your configuration (default vs customized). Let’s break this down step by step:
默认配置下的必备端口
These are the out-of-the-box ports you’ll need to open for node-to-node message queue communication:
- 节点P2P通信端口: 默认是
10002。这是所有普通Corda节点之间通过Artemis消息队列交换交易、状态等数据的核心端口,必须双向TCP开放(节点既要发送也要接收消息)。 - Notary节点P2P端口: 如果你的网络包含一个Notary(公证节点),它的默认P2P端口是
10003。所有需要与Notary交互的节点都需要能访问这个端口,同样要双向开放。
小提醒:如果你的业务需要通过RPC客户端连接节点(比如运维工具或自定义应用),默认RPC端口是
10006,但这不属于节点间消息队列通信的范畴,只是额外的访问需求。
自定义配置场景
If you’ve modified your node.conf file to use non-default ports, you’ll need to open the ports specified in these key configuration entries:
p2pAddress: This field defines the node’s P2P endpoint (format:hostname:port). The port here is what you need to open for inter-node messaging.notaryAddress: For Notary nodes, this configuration sets the port that other nodes will use to reach the Notary’s message queue.
防火墙规则最佳实践
- Always set restricted IP whitelists instead of opening ports to the entire internet. Only allow traffic from trusted nodes in your Corda network.
- Ensure all required ports are open for bidirectional TCP traffic—Corda’s message queue communication is two-way, so nodes need to both send and receive messages.
- If you’re using TLS encryption (strongly recommended for production), the port remains the same—TLS just encrypts the traffic passing through the open port, it doesn’t change the port itself.
内容的提问来源于stack exchange,提问作者Joel
相关产品推荐
相关产品推荐

