7.0.8 Insight Remote Support Security White Paper

43
Appendix C: Summary of Network Ports for Storage
The following tables summarize all ports that might be used in Insight Remote Support for Storage. See Table A-1 for
ports that are required for basic system operation.
C.1 StorageWorks MSA15XX/2XXX G1 Storage Systems
Table C.1 StorageWorks MSA15XX/2XXX G1 Storage Systems Connectivity - Firewall/Port Requirements
Protocol
Ports
Source
Destination
Function
Configurable
Optional
TCP
2301
Customer's
Web Browser
Hosting
Device
HP SMH port for Insight Manager Web Agents; HTTP
(unencrypted) ? redirected to 2381 (HTTPS)
Yes
Required
UDP
161
Hosting
Device
Monitored
Systems
SNMP. This is the standard port used by SNMP agents
on monitored systems. The Hosting Device sends
requests to devices on this port.
No
Required
UDP
162
Monitored
Systems
Hosting
Device
SNMP Trap. This is the standard port used by SNMP
managers for listening to traps.
No
Required
ICMP
N/A
Hosting
Device
Monitored
Systems
Provides system reachability (ping) check during
system discovery and before other operations.
No
Recommended
C.2 StorageWorks MSA23xx G2 Storage Systems
Table C.2 StorageWorks MSA23xx G2 Storage Systems Connectivity - Firewall/Port Requirements
Protocol
Ports
Source
Destination
Function
Configurable
Optional
TCP
2301
Customer's
Web Browser
Hosting
Device
HP SMH port for Insight Manager Web Agents; HTTP
(unencrypted) ? redirected to 2381 (HTTPS)
Yes
Required
UDP
161
Hosting
Device
Monitored
Systems
SNMP. This is the standard port used by SNMP agents
on monitored systems. The Hosting Device sends
requests to devices on this port.
No
Required
TCP
7905
Monitored
Systems
Hosting
Device
Secure HTTP (HTTPS) port used by the listener
running in the Director's Web Interface. The
monitored host connects to the Hosting Device on
this port (e.g. https://target.sys.name.here:7905)
No
Required
UDP
162
Monitored
Systems
Hosting
Device
SNMP Trap. This is the standard port used by SNMP
managers for listening to traps.
No
Required
ICMP
N/A
Hosting
Device
Monitored
Systems
Provides system reachability (ping) check during
system discovery and before other operations.
No
Recommended
TCP
5989
Hosting
Device
Monitored
Systems
Secured WBEM CI-MOM protocol over HTTPS/SOAP.
This port is used to communicate with WBEM end
point nodes.
Yes
Optional