A.05.70 HP Insight Remote Support Advanced and Remote Device Access Security Overview (October 2011, 5900-1735)
C.3 Integrity Linux Managed Systems
Table C-3 Integrity Linux Connectivity - Firewall/Port Requirements
OptionalConfigurableFunctionDestinationSourcePortsProtocol
RequiredYesSecured WBEM CI-MOM protocol
over HTTPS/SOAP. This port is used
to communicate with WBEM end
point nodes.
Managed
Systems
CMS5989TCP
RequiredNoSecure HTTP (HTTPS) port used by the
listener running in the Director's Web
Interface. The Web browser connects
to this port in the URL (e.g.
https://target.sys.name.here:7906)
CMSManaged Systems7906TCP
RecommendedNoProvides system reachability (ping)
check during system discovery and
before other operations. Note that HP
SIM can be configured to use TCP
port 5989 to simplify firewall settings.
Managed
Systems
CMSN/AICMP
OptionalNoSNMP. This is the standard port used
by SNMP agents on managed
systems. The CMS sends requests to
devices on this port.
Managed
Systems
CMS161UDP
OptionalNoHP SIM HTTPS/SOAPCMSManaged Systems50001TCP
OptionalNoHP SIM HTTPS/SOAP with client
certificate authentication
CMSManaged Systems50002TCP
OptionalYesWBEM event receiver (HTTP and
HTTPS)
CMSManaged Systems50004TCP
C.4 Integrity Windows Server 2003 Managed Systems
Table C-4 Integrity Windows Server 2003 Connectivity - Firewall/Port Requirements
OptionalConfigurableFunctionDestinationSourcePortsProtocol
RequiredYesSecured WBEM CI-MOM protocol
over HTTPS/SOAP. This port is used
to communicate with WBEM end
point nodes.
Managed
Systems
CMS5989TCP
RequiredNoThe WEBES ELMC (formerly
WCCProxy) process communicates
with the Director on this port. This is
a proprietary protocol. Any
connections that exchange username
and passwords use SSL. Not all
connections are SSL.
Managed
Systems
CMS7920TCP
RequiredNoSNMP. This is the standard port used
by SNMP agents on managed
systems. The CMS sends requests to
devices on this port.
Managed
Systems
CMS161UDP
RequiredNoDCE endpoint resolution. Used by
DCOM, and hence, Windows
Management Interface (WMI) and
WEBES
CMSManaged Systems135TCP
RequiredNoNETBIOS Session Service. Used by
DCOM, and hence, Windows
Management Interface (WMI) and
WEBES
CMSManaged Systems139TCP
RequiredNoWindows Server 2003 Windows
Management Interface (WMI)
Communications DCOM dynamic
port assignment. Note that the CMS
can be configured to limit this range.
The source port will always be 135.
CMSManaged Systems1024-65535TCP
C.3 Integrity Linux Managed Systems 57