Table 7-7
Other Firewall rules for traffic between the 5620 SAM Server(s) and
the managed network
Protocol
From port
On
To port
On
Notes
ICMP
N/A
Managed Network
N/A
Server(s)
Only used if Ping Policy
is enabled.
TCP
5001
7701 CPAA Elements
> 32768
Server(s)
–
Table 7-8
Firewall rules for remote user authentication
Protocol
From port
On
To port
On
Notes
TCP/UDP
Any
SAM Server
389
LDAP Server
For LDAP
authentication
TCP/UDP
Any
SAM Server
636
LDAP Server
For LDAP
authentication (SSL)
UDP
Any
SAM Server
1812
RADIUS Server
For RADIUS
authentication
When there is a firewall at the interface that reaches the 5620 SAM Client(s) (NIC 3 on
) the following rules need to be applied.
Table 7-9
Firewall rules for traffic coming into the 5620 SAM Server(s) from the
5620 SAM Client(s) (GUI/OSS)
Protocol
From port
On
To port
On
Notes
TCP
Any
SAM-O Client
21
Server(s)
If FTP is required
TCP
Any
SAM-O Client
22
Server(s)
If SFTP/SCP is required
TCP
> 1023
SAM-O Client
> 1023
Server(s)
If FTP is required
TCP
Any
SAM-O/SAM GUI
Client
1097
Server(s)
JMS
TCP
Any
SAM-O/SAM GUI
Client
1099
Server(s)
JNDI
TCP
Any
SAM-O/SAM GUI
Client
4447
Server(s)
JMS
UDP
Any
SAM GUI Client
6100-6119
Server(s)
NEM Proxy
TCP
Any
SAM-O Client
8080
Server(s)
HTTP
TCP
Any
SAM GUI Client
8085
Server(s)
HTTP
TCP
Any
SAM GUI Client
8087
Server(s)
HTTP(S)
TCP
Any
SAM GUI Client
8088
Server(s)
HTTP(S)
TCP
Any
SAM GUI Client
8089
Server(s)
HTTP(S)
Security
Firewall and NAT rules
....................................................................................................................................................................................................................................
....................................................................................................................................................................................................................................
5620 SAM
3HE-09809-AAAG-TQZZA 13.0 R7
Issue 1
December 2015
7-19