Guardium port requirements

Each Guardium® system requires specific ports to be open for several types of communication between its components depending on specific use cases and technical configuration.

Ports for Guardium application access

Source Destination Destination Port Protocol Function
Aggregator Collector 22 TCP Data transfer
Collector Aggregator 22 TCP Data transfer
Collector or aggregator Central manager 22, 8443, 3306, 8447, 8983, 9983 TCP Central management
Central Manager Collector or aggregator 22, 8443, 3306, 8447, 8983, 9983 TCP Central management
User Guardium Appliance 22, 8443, 8445 TCP Application usage and administration
Guardium Data Security Center Central manager 8586 TCP Integration. Close the port if not using Guardium Data Security Center.

Ports for database servers

Source Destination Destination Port Protocol Function
DB Server Collector 8444 TCP File upload
DB Server Central manager or managed units that are proxy servers 8443 TCP Enterprise load balancing
DB Server Guardium Appliances that are Guardium installation manager (GIM) servers 8446 TCP GIM
DB Server Collector 16016 TCP S-TAP

Port 16016 carries unencrypted (non-TLS) two-way communication between S-TAP and the collector, including registration, heartbeat, and data traffic. This port must be open in both directions for S-TAP operations to function correctly. If it is blocked in either direction, S-TAP operations that depend on collector-initiated communication — such as control operations and collector coordination — will fail.

DB Server Collector 16017 TCP CAS
DB Servers Collector 16018 TCP S-TAP (TLS)
DB Server Collector 16019 TCP CAS (TLS)
Guardium Appliances that are GIM servers DB Server 8445 TCP GIM listening mode
UNIX™ DB Servers and S-TAP Collector 16020 TCP S-TAP pooling
UNIX DB Servers and S-TAP Collector 16021 TCP S-TAP pooling (TLS)
Windows™ DB Servers Collector 9500 TCP S-TAP, V7 protocol
Windows DB Servers Collector 9501 TCP S-TAP, V7 protocol (TLS)
Windows DB Servers Collector 9800 TCP S-TAP, V8 protocol
Windows DB Servers Collector 9801 TCP S-TAP, V8 protocol (TLS)

Outbound ports to monitor Azure streaming

The following ports must be open to support IPv4 connections to Azure services.

Port Protocol Function
443 SSL Azure Namespace
5671, 5672 AMQP Azure Namespace
443 SSL Azure Storage

Outbound ports to monitor AWS streaming

The following ports must be open to support IPv4 connections to AWS.

Port Protocol Function
443 SSL AWS Kinesis, AWS DynamoDB, AWS CloudWatch, and AWS KMS

Ports for long term retention

12.2 and later The following ports must be open to support long term retention functionality.

Source Destination Destination port Protocol Function
Central Manager Long term retention appliance (all-in-one) 8843, 9083 TCP Long term retention management
Central Manager, collector, Long term retention appliance (all-in-one) S3 Depends on S3 configuration (for example, the default for MinIO is 9000) TCP Long term retention data
User S3 Depends on S3 configuration (for example, the default for MinIO is 9000) TCP Download report from long term retention S3 storage

Default ports used for other features

Port Protocol Function
20, 21 TCP

FTP Server for backups/archiving

22 TCP SSH/SCP data transfers, both directions
25 TCP SMTP (email server) for alerts and other notification
53 TCP DNS Servers
323 UDP NTP (Time Server) for time synchronization
161 TCP, UDP

SNMP Polling

162 TCP, UDP

SNMP Traps

389 TCP LDAP, for example, Active Directory or Sun One Directory
443 TCP Default outbound port from External S-TAP® GUI to Kubernetes API
514 TCP Syslog Server (optional)
636 TCP

LDAP, for example, Active Directory or Sun One Directory over SSL

1500 TCP

Tivoli® Storage Manager backup hosts

2183 TCP ZooKeeper, for universal connector Kafka cluster management
3218 TCP, UDP

EMC Centera backup hosts

3306 TCP MySQL, opened to specific sources (for instance, the central manager is open to all managed units; a managed unit is open to the central manager)
user-defined TCP

Database Server listener ports, for example, 1521 for Oracle or 1433 for MS-SQL, for Guardium datasource access.

Use this port for S-TAP verification and Discovery.

16022/16023 TCP/TLS Universal Feed - File Activity Monitoring (FAM)
18027 FAM using IBM® Content Classification locally (serverSettings.icm URL=http://localhost:18027)
8445

GIM client listener, both directions.

The GIM client is doing the listening. Any GIM server on either the central manager or the collector can reach out to it (the GIM client).

8446 TLS

GIM authenticated TLS, both directions

Use between the GIM client and the GIM server (on the central manager or collector).

8447 TLS

Used for remote messaging service infrastructure (and profile distribution infrastructure) for communication between Guardium systems in the federated environment/centrally managed environment. Configuration profiles allow the definition of configuration and scheduling settings from a central manager and conveniently distribute those settings to managed unit groups without altering the configuration of the central manager itself.

8443 TLS

Enterprise load balancer.

This port is needed for UNIX/Linux® S-TAPs to communicate instances to the collector.

However, this port is also used for the central manager load balancer. If the installation wants to use Enterprise load balancer, then the S-TAP initiates a request to the central manager on port 8443 by sending an HTTPS message.

If you do not want an open port directly from database to central manager, you can use a proxy server between the database server and central manager.

8983 TCP

Used for establishing communication between the central manager and every managed unit, and between each managed unit and the central manager that is required in default mode.

Communication between all managed units is required only in 'all machines' mode.

9093 TCP Kafka, for universal connector Kafka cluster management
9983 TCP Used for establishing communication from the managed unit to the central manager.

Ports for connections to z/OS® database servers

Port Protocol Purpose
16022 TCP Connects to S-TAP for Db2® z/OS, S-TAP for IMS, S-TAP for Data Sets
16023 TCP TLS connections, specifically IBM's Application Transport Layer Security (AT-TLS)
41500 TCP Default starting port for internal message logging communications – LOG_PORT_SCAN_START
39987 TCP Default agent-specific communications port between the agent and the agent secondary address spaces – ADS_LISTENER_PORT