Chapter 10
449
Tuning, Troubleshooting, Security, and Maintenance
ITO Security
NOTE
Although the allowed port range of given managed nodes may differ if
the managed nodes are connected to the ITO management server
through a different router, all managed nodes that use the same router
must use the same port range.
Figure 10-2
Compulsory Firewall Port Ranges in ITO
The DCE environment variable RPC_RESTRICTED_PORTS controls
the DCE RPC server runtime’s tendency occasionally to open additional
ports outside the range specified in ITO, when called by clients using
UDP. Since the managed nodes may make DCE RPC calls (using UDP) to
the rpcd on the management server, it is important that the
rpcd
/
dced
runs in an environment (on the management server) where the value of
RPC_RESTRICTED_PORTS is set to match the port range defined both
on the ITO management server and at the firewall. The value of
RPC_RESTRICTED_PORTS needs to be set in the following way in the
DCE system startup files. For example:
RPC_RESTRICTED_PORTS=tcp[range]1:udp[range1]
NOTE
Whatever protocol you choose in the ITO GUI for RPC connections, the
allowed port range you define must always be open for TCP in both
directions at the firewall to allow for bulk data transmission.
ITO Management Server
ITO Managed Node
[*]
135
Range 2
[*]
135
Range 1
Содержание -UX B6941-90001
Страница 6: ...6 ...
Страница 8: ...8 ...
Страница 27: ...27 1 Prerequisites for Installing ITO Agent Software ...
Страница 43: ...43 2 Installing ITO Agents on the Managed Nodes ...
Страница 115: ...115 3 File Tree Layouts on the Managed Node Platforms ...
Страница 162: ...162 Chapter3 File Tree Layouts on the Managed Node Platforms File Tree Layout on Windows NT Managed Nodes ...
Страница 163: ...163 4 Software Maintenance on Managed Nodes ...
Страница 183: ...183 5 Configuring ITO ...
Страница 298: ...298 Chapter5 Configuring ITO Variables ...
Страница 299: ...299 6 Installing Updating the ITO Configuration on the Managed Nodes ...
Страница 315: ...315 7 Integrating Applications into ITO ...
Страница 333: ...333 8 ITO Language Support ...
Страница 352: ...352 Chapter8 ITO Language Support Flexible Management in a Japanese Environment ...
Страница 353: ...353 9 An Overview of ITO Processes ...
Страница 372: ...372 Chapter9 An Overview of ITO Processes Secure Networking ...
Страница 373: ...373 10 Tuning Troubleshooting Security and Maintenance ...
Страница 481: ...481 A ITO Managed Node APIs and Libraries ...
Страница 499: ...499 B Administration of MC ServiceGuard ...
Страница 512: ...512 AppendixB Administration of MC ServiceGuard Troubleshooting ITO in a ServiceGuard Environment ...
Страница 513: ...513 C ITO Tables and Tablespaces in the Database ...
Страница 520: ...520 AppendixC ITO Tables and Tablespaces in the Database ITO Tables and Tablespace ...
Страница 521: ...521 D ITO Man Pages Listing ...