Rapid Recovery ACL rules

We have a Rapid Recovery 6.10 with multiple Rapid Recovery 6.10 agents round the network, they're all connecting to the Core through port 8006.  I've read some guides that says make sure 8006-8009 are unblocked, which they are but when i block all traffic, apart from those 4 ports, all the agents go offline.

Am i missing a port that also needs unblocking please?