Video Screencast Help
Search Video Help Close Back
to help
New in the Rewards Catalog: Vouchers for "Symantec Technical Specialist" and "Symantec Certified Specialist" exams.

ports needed to open

Updated: 21 May 2010 | 1 comment
pete_4u2002's picture
0 0 Votes
Login to vote

Hi,

As understand from the KB article the firewall must support bidirectional communication through ports 5600 and 5601 to successfully communicate between ESM manager and Agents.

 

Query 1)

If firewall between ESM manager and Agents do we still require this port range 1024-5000 must also be opened for the specified manager and agents?

2) if we use static NAt will it work?

 

 

Pete!

discussion Filed Under:

Comments

Tim White's picture
07
Jan
2009
0 Votes 0
Login to vote

Ports 1024-5000 are the source port and need to be open, but most stateful firewalls manage this for you automatically when you define the destination port.

 

Static NAT generally will be problematic, but may work if you use hostfiles and set DNS up VERY CAREFULLY.

 

Many customers put an ESM manager into the DMZ and only open the console ports from the internal network to the manager.  This is much easier, and the manager doesn't need to be on a dedicated box if there are only a handful of agents.