Planning firewall access
Determine the firewalls that are set and the ports that must be open for the IBM Storage Protect solution to work.
Table 1 describes the ports that are used by the server, client, and Operations Center.
| Item | Default | Direction | Description |
|---|---|---|---|
| Base port (TCPPORT) | 1500 | Outbound/inbound | Each server instance requires a unique port. You can specify an alternative port number. The TCPPORT option listens for both TCP/IP and SSL-enabled sessions from the client. You can use the TCPADMINPORT option and ADMINONCLIENTPORT option to set port values for administrative client traffic. |
| RESTHTTPSPORT | 8443 | Inbound/outbound | This port is used for secure communications between the hub server and the Operations Center. |
| SSL-only port (SSLTCPPORT) | No default | Outbound/inbound | This port is used if you want to restrict communication on the port to SSL-enabled sessions only. A server can support both SSL and non-SSL communication by using the TCPPORT or TCPADMINPORT options. |
| SMB | 45 | Inbound/outbound | This port is used by configuration wizards that communicate by using native protocols with multiple hosts. |
| SSH | 22 | Inbound/outbound | This port is used by configuration wizards that communicate by using native protocols with multiple hosts. |
| SMTP | 25 | Outbound | This port is used to send email alerts from the server. |
| Replication | No default | Outbound/inbound |
The port and protocol for the outbound port for replication are set by the DEFINE SERVER command that is used to set up replication. The inbound ports for replication are the TCP ports and SSL ports are specified for the source server on the DEFINE SERVER command. |
| Client schedule port | Client port: 1501 | Outbound | The client listens on the port that is named and communicates the port number to the server. The server contacts the client if server prompted scheduling is used. You can specify an alternative port number in the client options file. |
| Long-running sessions | KEEPALIVE setting: YES | Outbound | When the KEEPALIVE option is enabled, keepalive packets are sent during client/server sessions to prevent the firewall software from closing long-running, inactive connections. |
| Operations Center | HTTPS: 11090 | Inbound | These ports are used for the Operations Center web browser. You can specify an alternative port number. |
| Client management service port | Client port: 9028 | Inbound | If you plan to use IBM Storage Protect client management services, the client management service port must be accessible from the Operations Center. Ensure that firewalls cannot prevent connections. The client management service uses the TCP port of the server for the client node for authentication by using an administrative session. |