A.05.70 HP Insight Remote Support Advanced and Remote Device Access Security Overview (October 2011, 5900-1735)

OptionalConfigurableFunctionDestinationSourcePortsProtocol
RecommendedNoNetwork Time ProtocolNetwork Time ServerVirtual CAS123UDP
RecommendedNoHTTP (Unencrypted) Daily fetch
of HP Class 2 CA certificate
revocation list (CRL)
onsitecrl.verisign.com
or Web Proxy
Virtual CAS80 or web
proxy port
TCP
RecommendedNoOCSP (Online Certificate Status
Protocol) for certificate
revocation check
onsite-ocsp.verisign.comVirtual CAS80TCP
OptionalNoSSH command-line access for
Virtual CAS management
Virtual CASCustomer's SSH
Client
22TCP
OptionalNoEmail notificationsCustomer-Designated
SMTP Server
Virtual CAS25TCP
OptionalNoHTTPS connection to the HP RDA
CAS Kit server to download
updates
h20529.www2.hp.com
or Web Proxy
Virtual CAS443 or
web proxy
port
TCP
OptionalYesSyslog remote logging
(unencrypted)
Logging ServerVirtual CAS514TCP
OptionalYesSyslog remote logging
(unencrypted)
Logging ServerVirtual CAS514UDP
OptionalYesCustomer-specified TCP port and
application protocol
SSH-forwarded from HP via the
relay application
Target SystemVirtual CASotherTCP
OptionalYesCustomer-specified UDP port
and application protocol
SSH-forwarded from HP via the
relay application
Target SystemVirtual CASotherUDP
G.3 Additional Ports for iCAS
Table G-3 Additional Ports for iCAS Connectivity - Firewall/Port Requirements
OptionalConfigurableFunctionDestinationSourcePortsProtocol
RequiredNoDomain Name Service (DNS) -
Host name resolution
DNS ServeriCAS Host53UDP
RequiredNoHTTP Tunnelling for SSHHP Regional RAMS
Server or Web Proxy
iCAS Host80 or web
proxy port
TCP
RequiredNoHTTPS to retrieve iCAS plug-inHP Regional RAMS
Server or Web Proxy
iCAS Host443 or
web proxy
port
TCP
OptionalYesCustomer-specified TCP port and
application protocol
SSH-forwarded from HP
Target SystemiCAS HostotherTCP
OptionalYesCustomer-specified UDP port
and application protocol
SSH-forwarded from HP
Target SystemiCAS HostotherUDP
G.4 Additional Ports for P9000/XP Storage Array
Table G-4 Additional Ports for P9000/XP Storage Array Connectivity - Firewall/Port Requirements
OptionalConfigurableFunctionDestinationSourcePortsProtocol
OptionalNoMicrosoft Remote Desktop
Connection (RDC) used for
remote management by HP or
customer
XP SVPCAS3389TCP
76 Summary of Network Ports for Remote Device Access