Guardium port requirements
Each Guardium® system requires specific ports to be open for several types of communication between its components depending on specific use cases and technical configuration.
Ports for Guardium application access
| Source | Destination | Destination Port | Protocol | Function |
|---|---|---|---|---|
| Aggregator | Collector | 22 | TCP | Data transfer |
| Collector | Aggregator | 22 | TCP | Data transfer |
| Collector or aggregator | Central manager | 22, 8443, 3306, 8447, 8983, 9983 | TCP | Central management |
| Central Manager | Collector or aggregator | 22, 8443, 3306, 8447, 8983, 9983 | TCP | Central management |
| User | Guardium Appliance | 22, 8443, 8445 | TCP | Application usage and administration |
| Guardium Data Security Center | Central manager | 8586 | TCP | Integration. Close the port if not using Guardium Data Security Center. |
Ports for database servers
| Source | Destination | Destination Port | Protocol | Function |
|---|---|---|---|---|
| DB Server | Collector | 8444 | TCP | File upload |
| DB Server | Central manager or managed units that are proxy servers | 8443 | TCP | Enterprise load balancing |
| DB Server | Guardium Appliances that are Guardium installation manager (GIM) servers | 8446 | TCP | GIM |
| DB Server | Collector | 16016 | TCP | S-TAP
Port 16016 carries unencrypted (non-TLS) two-way communication between S-TAP and the collector, including registration, heartbeat, and data traffic. This port must be open in both directions for S-TAP operations to function correctly. If it is blocked in either direction, S-TAP operations that depend on collector-initiated communication — such as control operations and collector coordination — will fail. |
| DB Server | Collector | 16017 | TCP | CAS |
| DB Servers | Collector | 16018 | TCP | S-TAP (TLS) |
| DB Server | Collector | 16019 | TCP | CAS (TLS) |
| Guardium Appliances that are GIM servers | DB Server | 8445 | TCP | GIM listening mode |
| UNIX™ DB Servers and S-TAP | Collector | 16020 | TCP | S-TAP pooling |
| UNIX DB Servers and S-TAP | Collector | 16021 | TCP | S-TAP pooling (TLS) |
| Windows™ DB Servers | Collector | 9500 | TCP | S-TAP, V7 protocol |
| Windows DB Servers | Collector | 9501 | TCP | S-TAP, V7 protocol (TLS) |
| Windows DB Servers | Collector | 9800 | TCP | S-TAP, V8 protocol |
| Windows DB Servers | Collector | 9801 | TCP | S-TAP, V8 protocol (TLS) |
Outbound ports to monitor Azure streaming
The following ports must be open to support IPv4 connections to Azure services.
| Port | Protocol | Function |
|---|---|---|
| 443 | SSL | Azure Namespace |
| 5671, 5672 | AMQP | Azure Namespace |
| 443 | SSL | Azure Storage |
Outbound ports to monitor AWS streaming
The following ports must be open to support IPv4 connections to AWS.
| Port | Protocol | Function |
|---|---|---|
| 443 | SSL | AWS Kinesis, AWS DynamoDB, AWS CloudWatch, and AWS KMS |
Ports for long term retention
12.2 and later The following ports must be open to support long term retention functionality.
| Source | Destination | Destination port | Protocol | Function |
|---|---|---|---|---|
| Central Manager | Long term retention appliance (all-in-one) | 8843, 9083 | TCP | Long term retention management |
| Central Manager, collector, Long term retention appliance (all-in-one) | S3 | Depends on S3 configuration (for example, the default for MinIO is 9000) | TCP | Long term retention data |
| User | S3 | Depends on S3 configuration (for example, the default for MinIO is 9000) | TCP | Download report from long term retention S3 storage |
Default ports used for other features
| Port | Protocol | Function |
|---|---|---|
| 20, 21 | TCP |
FTP Server for backups/archiving |
| 22 | TCP | SSH/SCP data transfers, both directions |
| 25 | TCP | SMTP (email server) for alerts and other notification |
| 53 | TCP | DNS Servers |
| 323 | UDP | NTP (Time Server) for time synchronization |
| 161 | TCP, UDP |
SNMP Polling |
| 162 | TCP, UDP |
SNMP Traps |
| 389 | TCP | LDAP, for example, Active Directory or Sun One Directory |
| 443 | TCP | Default outbound port from External S-TAP® GUI to Kubernetes API |
| 514 | TCP | Syslog Server (optional) |
| 636 | TCP |
LDAP, for example, Active Directory or Sun One Directory over SSL |
| 1500 | TCP |
Tivoli® Storage Manager backup hosts |
| 2183 | TCP | ZooKeeper, for universal connector Kafka cluster management |
| 3218 | TCP, UDP |
EMC Centera backup hosts |
| 3306 | TCP | MySQL, opened to specific sources (for instance, the central manager is open to all managed units; a managed unit is open to the central manager) |
| user-defined | TCP |
Database Server listener ports, for example, 1521 for Oracle or 1433 for MS-SQL, for Guardium datasource access. Use this port for S-TAP verification and Discovery. |
| 16022/16023 | TCP/TLS | Universal Feed - File Activity Monitoring (FAM) |
| 18027 | FAM using IBM® Content Classification locally (serverSettings.icm URL=http://localhost:18027) | |
| 8445 |
GIM client listener, both directions. The GIM client is doing the listening. Any GIM server on either the central manager or the collector can reach out to it (the GIM client). |
|
| 8446 | TLS |
GIM authenticated TLS, both directions Use between the GIM client and the GIM server (on the central manager or collector). |
| 8447 | TLS |
Used for remote messaging service infrastructure (and profile distribution infrastructure) for communication between Guardium systems in the federated environment/centrally managed environment. Configuration profiles allow the definition of configuration and scheduling settings from a central manager and conveniently distribute those settings to managed unit groups without altering the configuration of the central manager itself. |
| 8443 | TLS |
Enterprise load balancer. This port is needed for UNIX/Linux® S-TAPs to communicate instances to the collector. However, this port is also used for the central manager load balancer. If the installation wants to use Enterprise load balancer, then the S-TAP initiates a request to the central manager on port 8443 by sending an HTTPS message. If you do not want an open port directly from database to central manager, you can use a proxy server between the database server and central manager. |
| 8983 | TCP |
Used for establishing communication between the central manager and every managed unit, and between each managed unit and the central manager that is required in default mode. Communication between all managed units is required only in 'all machines' mode. |
| 9093 | TCP | Kafka, for universal connector Kafka cluster management |
| 9983 | TCP | Used for establishing communication from the managed unit to the central manager. |
Ports for connections to z/OS® database servers
| Port | Protocol | Purpose |
|---|---|---|
| 16022 | TCP | Connects to S-TAP for Db2® z/OS, S-TAP for IMS, S-TAP for Data Sets |
| 16023 | TCP | TLS connections, specifically IBM's Application Transport Layer Security (AT-TLS) |
| 41500 | TCP | Default starting port for internal message logging communications – LOG_PORT_SCAN_START |
| 39987 | TCP | Default agent-specific communications port between the agent and the agent secondary address spaces – ADS_LISTENER_PORT |