Ports the storage system may contact
The storage system functions as a network client in several circumstances, for
example, in communicating with an LDAP server. In these instances, the storage
system initiates communication and the network infrastructure will need to support
these connections.
Table 11
on page 39 describes the ports that a storage system
must be allowed to access for the corresponding service to function properly. This
includes the Unisphere CLI.
Table 11 Network connections that may be initiated by the storage system
Service
Protocol
Port
Description
FTP
TCP
20
Port used for FTP data transfers. This port can be opened by
enabling FTP as described in the next row. Authentication is
performed on port 21 and defined by the FTP protocol.
SFTP
TCP
22
Allows alert notifications through SFTP (FTP over SSH).
SFTP is a client/server protocol. Users can use SFTP to
perform file transfers on a storage system on the local subnet.
Also provides outgoing FTP control connection. If closed, FTP
will not be available.
SSH/SSHD, VSI
TCP
22
Allows SSH access (if enabled). Also used for VSI plugin. If
closed, management connections using SSH and VSI plugin
will not be available.
SMTP
TCP
25
Allows the system to send email. If closed, email notifications
will be unavailable.
DNS
TCP/UDP
53
DNS queries. If closed, DNS name resolution will not work.
DHCP
UDP
67-68
Allows the storage system to act as a DHCP client. If closed,
dynamic IP addresses will not be assigned using DHCP.
HTTP
TCP
80
Redirect for HTTP traffic to Unisphere and the Unisphere CLI.
If closed, management traffic to the default HTTP port will be
unavailable.
Kerberos
TCP/UDP
88
Provides outgoing Kerberos ticket. If closed, Kerberos
authentication and all protocols that use it; for example, SMB,
LDAP, GPO, secNFS, and such, will not be available.
Portmapper,
rpcbind (Network
infrastructure)
TCP/UDP
111
Opened by the standard portmapper or rpcbind service and is
an ancillary storage system network service. It cannot be
stopped. By definition, if a client system has network
connectivity to the port, it can query it. No authentication is
performed.
NTP
UDP
123
NTP time synchronization. If closed, time will not be
synchronized among arrays.
NETBIOS Name
Service (SMB)
TCP/UDP
137
The NETBIOS Name Service is associated with the storage
system SMB file sharing services and is a core component of
that feature (Wins). If disabled, this port disables all SMB-
related services.
Communication Security
Ports the storage system may contact
39
Содержание EMC Unity All Flash
Страница 32: ...Logging 32 EMC Unity All Flash EMC Unity Hybrid EMC UnityVSA 4 0 Security Configuration Guide...
Страница 60: ...Security Maintenance 60 EMC Unity All Flash EMC Unity Hybrid EMC UnityVSA 4 0 Security Configuration Guide...
Страница 70: ...TLS cipher suites 70 EMC Unity All Flash EMC Unity Hybrid EMC UnityVSA 4 0 Security Configuration Guide...