
8
©
SOLIDA SYSTEMS INTERNATIONAL 2017
2.4 Required Open Network Ports
The appliance needs to be able to connect with Solida Systems cloud server to retrieve threat
intelligence updates and occasional software updates. It is very important that this connection
is working correctly. Without a proper connection, the appliance will still function, but the
threat intelligence will not be updated and the remote monitoring tools will not be functional.
The domain name for this cloud server is
cloudhost.solidasystems.com
. The server is set up
with a fixed IP address. This IP address can be obtained by using nslookup (windows) or the dig
tool (Linux), if it needs to be provided to a firewall.
In case a firewall is deployed in the network, it is not required to open up any ports for incoming
traffic from the Internet. All communication is initiated from within the appliance. The only
exception to this would be if the user elects to access the GUI applications from outside the
network over the Internet without the use of a VPN connection. This is possible but not
recommended. When several ports are opened up in the firewall it might result in a security
weakness.
The “reputation threat list updates” configuration window includes a button labeled “Test
Connection”. When pressing this button, the appliance will try to connect with Solida’s cloud
server the exact same way it would do for an update of the threat intelligence. If this test fails,
the installation must be checked to identify the cause of the failure. This test must complete
successfully for the appliance to be able to download the threat intelligence data and function
as designed.
Threat Intelligence Updates
The threat intelligence updates are performed as follows:
If port 22 (SSH port) is opened in the network for outgoing traffic towards the Internet, all
threat intelligence data will be downloaded over this port.
If outgoing traffic over port 22 is blocked by a firewall, then the appliance will default to using
port 443 (HTTPS) port for its threat intelligence download.
It is VERY IMPORTANT that one of these two paths are opened. Otherwise the appliance will not
be able to perform its hourly threat feed updates.
Solida Monitor
Solida Monitor GUI application is using port 443 for its communication with the appliance. It
supports an option that performs a WhoIs lookup of a selected IP address. These WhoIs
accesses are initiated from within the appliance and take place over port 43. Port 43 must be
opened for outgoing requests to the Internet for the WhoIs feature to work properly.