A.05.70 HP Insight Remote Support Advanced and Remote Device Access Security Overview (October 2011, 5900-1735)
G Summary of Network Ports for Remote Device Access
The following tables summarize all ports that might be used in Remote Device Access. See Table B-1 for
ports that are required for basic system operation.
G.1 Customer Access System (CAS)
Table G-1 CAS Connectivity - Firewall/Port Requirements
OptionalConfigurableFunctionDestinationSourcePortsProtocol
Required for
SSH-Direct
NoSSH Tunnel (SSH-Direct only)CASHP Remote Access
Connectivity
System (RACS)
22TCP
RecommendedNoProvides system reachability
(ping) check during installation.
Customer CorVPN
and hpVPN Routers
CASN/AICMP
RecommendedNoProvides system reachability
(ping) check during installation
Target System
Including CMS
CASN/AICMP
RecommendedNoProvides system reachability
(ping) check during installation
CASCustomer CorVPN
and hpVPN
Routers
N/AICMP
RecommendedNoProvides system reachability
(ping) check during installation.
CASTarget System
Including CMS
N/AICMP
OptionalYesHTTPS connection forwarded
from HP through CAS to CMS
or managed system
Customer hpVPN
Router
CAS443TCP
OptionalYesSSH command-line accessTarget System
Including CMS
CAS22TCP
OptionalYesTelnet command-line access if
SSH is not available.
Target System
Including CMS
CAS23TCP
OptionalYesHTTP connection forwarded
from HP through CAS to CMS
or managed system
Target System
Including CMS
CAS80TCP
OptionalYesMS RDP. Remote Desktop
Connection forwarded from HP
through CAS to CMS or
managed system
Target System
Including CMS
CAS3389TCP
OptionalYesVNC Web accessTarget System
Including CMS
CAS5800TCP
OptionalYesVNC accessTarget System
Including CMS
CAS5900TCP
OptionalYesCustomer-specified port and
application protocol
SSH-forwarded from HP
Target System
Including CMS
CASotherTCP
OptionalYesOther access methods for CAS
administration
CASCustomer ClientsotherTCP
OptionalYesSSH Command-line accessTarget System
Including CMS
Customer's SSH
Client
22TCP
G.2 Additional Ports for Virtual CAS
Table G-2 Additional Ports for Virtual CAS Connectivity - Firewall/Port Requirements
OptionalConfigurableFunctionDestinationSourcePortsProtocol
RequiredNoHTTPS port for web UI for
managing Virtual CAS
Virtual CASCustomer's Web
Browser
443TCP
RequiredNoDomain Name Service (DNS) -
Host name resolution
DNS ServerVirtual CAS53UDP
G.1 Customer Access System (CAS) 75