the Device Server and the devices managed in your network. SSP offers strong encryption
and authentication mechanisms, so management traffic is protected and kept
confidential. SSP utilizes RSA public key cryptography, AES symmetric encryption, and
HMAC-SHA-1 hashing.
Communications with Devices Running ScreenOS 5.X and Later
If you are deploying NSM in a network with security devices running ScreenOS 5.0 and
later, note that SSP uses two TCP ports for communication:
•
Port 7800 between the Device Server and the devices
•
Port 7801 between the GUI Server and the Device Server.
You must allow TCP port 7800 on firewalls deployed between the NSM management
system and the devices managed in your network. You must also configure firewalls
between the GUI Server and UI clients to permit TCP port 7808.
Table 24 on page 198 lists and describes the ports used specifically in communications
between NSM and ScreenOS 5.0 devices.
Table 24: Management System Communications With Devices Running
ScreenOS
Description
Port
Server
Component
Accepts incoming connections from
devices running ScreenOS 5.0 and
later.
Inbound TCP: 7800
Device Server
Communicates with the GUI Server.
Outbound TCP: 7801
Device Server
SSH/Telnet to import initial
configurations of devices running
ScreenOS 5.0 and later.
Outbound TCP: 22/23
Device Server
Accepts communication from the
GUI client.
Inbound TCP: 7808
GUI Server
NOTE:
The Device Server can use port 22 (SSH) to perform an initial
connection to security devices running ScreenOS 5.0 and later, enabling you
to set the NSM agent. The agent enables the device to communicate back
to the Device Server using SSP port 7800. Security devices running ScreenOS
5.0 and later, also support SSH v2.
Copyright © 2010, Juniper Networks, Inc.
198
Network and Security Manager Installation Guide
Summary of Contents for NETWORK AND SECURITY MANAGER 2010.4 - REV1
Page 6: ...Copyright 2010 Juniper Networks Inc vi...
Page 14: ...Copyright 2010 Juniper Networks Inc xiv Network and Security Manager Installation Guide...
Page 22: ...Copyright 2010 Juniper Networks Inc xxii Network and Security Manager Installation Guide...
Page 24: ...Copyright 2010 Juniper Networks Inc 2 Network and Security Manager Installation Guide...
Page 42: ...Copyright 2010 Juniper Networks Inc 20 Network and Security Manager Installation Guide...
Page 70: ...Copyright 2010 Juniper Networks Inc 48 Network and Security Manager Installation Guide...
Page 92: ...Copyright 2010 Juniper Networks Inc 70 Network and Security Manager Installation Guide...
Page 152: ...Copyright 2010 Juniper Networks Inc 130 Network and Security Manager Installation Guide...
Page 214: ...Copyright 2010 Juniper Networks Inc 192 Network and Security Manager Installation Guide...
Page 239: ...PART 3 Index Index on page 219 217 Copyright 2010 Juniper Networks Inc...
Page 240: ...Copyright 2010 Juniper Networks Inc 218 Network and Security Manager Installation Guide...
Page 244: ...Copyright 2010 Juniper Networks Inc 222 Network and Security Manager Installation Guide...