Chapter 2: Client Connections
Port
Protocol
Feature
Configurable
Session Initiation
22
TCP
Secure Shell (SSH)
Yes
inbound
123
UDP
Network Time Protocol (NTP)
No
outbound
161 / 162
UDP
Simple Network Management Protocol (SNMP)
Yes
outbound
514
UDP
Remote Syslog Service
Yes
outbound
1503
TCP
Remote PED multi-factor authentication
Yes
inbound / outbound
1792
TCP
NTLS (Network Trust Link Service)
*
No
inbound
5656
TCP
Secure Trusted Channel (STC)
*
No
inbound
8443
TCP
REST API webserver
Yes
inbound / outbound
*
Applications use the client connection to obtain service from the HSM. Service is available only to client
systems that are registered with HSM partitions.
SafeNet Luna Network HSM Appliance Port Bonding
SafeNet Luna Network HSM has four physical network interface devices: eth0, eth1, eth2, and eth3. You can
bond eth0 and eth1 into a single virtual interface, bond0, or eth2 and eth3 into bond1, to provide a redundant
active/standby interface. The primary purpose of the service is a hot standby mode for network interface
failure, no performance or throughput gains are intended.
The following conditions and recommendations apply to the port bonding feature:
>
Bonded interfaces must both be attached to the same network segment. For example, if a bonded interface
of IP 192.168.9.126 is chosen, both interfaces must be connected to devices that can access the
192.168.9.* network.
>
Bonded interfaces must use static addressing.
>
Avoid executing bonding commands while clients are running applications against the SafeNet Luna
Network HSM. Where a bonding interface has the same IP as the IP of eth0 or eth2, no ill effects have been
observed on running clients other than normal fail-over/recover behavior.
>
Avoid executing bonding commands over SSH, which can result in the closure of the active SSH session.
Once bonding is configured, client connections as well as SSH connections continue uninterrupted if either of
the bonded interfaces fails.
Using Port Bonding
Use LunaSH to configure, enable, or disable port bonding, and to display the current port bonding status. See
"network interface bonding" on page 1
in the
LunaSH Command Reference Guide
for a list of the port bonding
commands.
SafeNet Luna Network HSM 7.3 Appliance Administration Guide
007-013576-005 Rev. A 13 December 2019 Copyright 2001-2019 Thales
34