Planning firewall access

Determine the firewalls that are set and the ports that must be open for the IBM Storage Protect solution to work.

Table 1 describes the ports that are used by the server, client, and Operations Center.

Table 1. Ports that are used by the server, client, and Operations Center
Item Default Direction Description
Base port (TCPPORT) 1500 Outbound/inbound Each server instance requires a unique port. You can specify an alternative port number. The TCPPORT option listens for both TCP/IP and SSL-enabled sessions from the client. You can use the TCPADMINPORT option and ADMINONCLIENTPORT option to set port values for administrative client traffic.
RESTHTTPSPORT 8443 Inbound/outbound This port is used for secure communications between the hub server and the Operations Center.
SSL-only port (SSLTCPPORT) No default Outbound/inbound This port is used if you want to restrict communication on the port to SSL-enabled sessions only. A server can support both SSL and non-SSL communication by using the TCPPORT or TCPADMINPORT options.
SMB 45 Inbound/outbound This port is used by configuration wizards that communicate by using native protocols with multiple hosts.
SSH 22 Inbound/outbound This port is used by configuration wizards that communicate by using native protocols with multiple hosts.
SMTP 25 Outbound This port is used to send email alerts from the server.
Replication No default Outbound/inbound

The port and protocol for the outbound port for replication are set by the DEFINE SERVER command that is used to set up replication.

The inbound ports for replication are the TCP ports and SSL ports are specified for the source server on the DEFINE SERVER command.

Client schedule port Client port: 1501 Outbound The client listens on the port that is named and communicates the port number to the server. The server contacts the client if server prompted scheduling is used. You can specify an alternative port number in the client options file.
Long-running sessions KEEPALIVE setting: YES Outbound When the KEEPALIVE option is enabled, keepalive packets are sent during client/server sessions to prevent the firewall software from closing long-running, inactive connections.
Operations Center HTTPS: 11090 Inbound These ports are used for the Operations Center web browser. You can specify an alternative port number.
Client management service port Client port: 9028 Inbound If you plan to use IBM Storage Protect client management services, the client management service port must be accessible from the Operations Center. Ensure that firewalls cannot prevent connections. The client management service uses the TCP port of the server for the client node for authentication by using an administrative session.