Hi,
So, in Production instances, I'd highly recommend using HTTPS + port 443 (i.e. proxy behind Apache). Otherwise, you are welcome to use port 4000 if you wish.
(Keep in mind, even if you setup a proxy via HTTPS + port 443, the UI process technically will run on localhost on port 4000...however, in that scenario port 4000 does NOT need to be open to the world, only port 443 would need to be opened).
Hopefully that helps more, but let us know on this list if you have further questions.
Tim