[ Applies to ] StorageGuard 9.x and later / Master server, collector servers, and scanned systems
This article lists the default network ports StorageGuard uses for web UI and REST API access, for communication between StorageGuard components, for scanning storage and backup systems, and for external services. Use it to plan a deployment and to configure firewalls where needed.
All ports are TCP unless stated otherwise. Where a port is configurable, the default is shown.
In this article
StorageGuard components and users
| Source | Destination | Protocol | Default port | Notes |
|---|---|---|---|---|
| End-user workstations | StorageGuard master server | HTTPS | 8443 | Web UI and REST API. Configurable. |
| StorageGuard master server | Database server | JDBC | 1521 (Oracle) or 5432 (PostgreSQL) | Only when an external database server is used. |
| StorageGuard master server | StorageGuard collector server | TCP | 27000 | Only when a collector server is used. Configurable. |
| StorageGuard master server | LDAP / AD server | LDAP / LDAPS | 389, 636 | |
| StorageGuard master server | Email server | SMTP | 25, 587 | |
| StorageGuard master server | ServiceNow | HTTPS | 443 | Only when the ServiceNow integration is used. |
Scanned systems
All connections in this table are from the StorageGuard master server or collector server to the scanned system. Click a system name to open its scan requirements article, where available.
| System | Protocol | Default port | Notes |
|---|---|---|---|
| Amazon Web Services (AWS) | HTTPS | 443 | Outbound to the AWS API endpoints for the target Region |
| Brocade FC switch | SSH | 22 | |
| Brocade SANnav | HTTPS | 443 | |
| Cisco FC switch | SSH | 22 | |
| Cisco NDFC | HTTPS | 443 | Formerly Cisco DCNM-SAN. Scanned through the NDFC REST API |
| Cohesity DataPlatform | HTTPS SSH |
443 22 |
Same credentials for both |
| Commvault proxy | HTTPS | 443 | |
| CTERA Portal | HTTPS | 443 | |
| Dell Avamar | SSH | 22 | To the Avamar Utility Server and the MCCLI proxy |
| Dell ECS / ObjectScale | HTTPS SSH |
4443 22 |
SSH is optional (additional checks and custom collection) |
| Dell NetWorker server | HTTPS SSH |
9090 22 |
SSH is optional (CLI access) |
| Dell PowerFlex Manager (MDM) | HTTPS SSH |
443 22 |
SSH is optional (CLI commands) |
| Dell PowerMax / VMAX – Unisphere | HTTPS | 8443 | |
| Dell PowerMax / VMAX – Solutions Enabler host (Linux / UNIX) | SSH | 22 | Optional. For eMGMT, use a SYMCLI client host |
| Dell PowerMax / VMAX – Solutions Enabler host (Windows) | WinRM + CIFS, or WMI | See Windows host ports | Optional |
| Dell PowerProtect Cyber Recovery | HTTPS SSH |
14778 22 |
SSH is recommended |
| Dell PowerProtect Data Manager (PPDM) | HTTPS | 8443 | |
| Dell PowerProtect DD (Data Domain, DDMC, DDVE) | SSH | 22 | |
| Dell PowerScale (Isilon) | SSH | 22 | |
| Dell PowerStore | HTTPS | 443 | |
| Dell RecoverPoint | SSH | 22 | RecoverPoint appliance (RPA) or RecoverPoint VM |
| Dell Secure Connect Gateway (SCG) | HTTPS | 5700 | REST API must be enabled on the gateway |
| Dell Unity – Unisphere | HTTP / HTTPS | 443 | |
| Dell VPLEX / Metro Node | HTTPS SSH |
443 22 |
|
| Dell VxRail Manager | HTTPS | 443 | |
| Hitachi Content Platform (HCP) | HTTP / HTTPS | 9090 | HCP management API |
| Hitachi Content Platform for Cloud Scale (HCPCS) | HTTPS | 8000, 9099 | |
| Hitachi NAS Platform (HNAS) | HTTPS | 8444 | Admin EVS (REST API server) IP address |
| Hitachi VSP – Configuration Manager | HTTPS | 23451 | StorageGuard 10.1 and later, Options B and C |
| Hitachi VSP – VSP One Block (SVP, GUM, or controller) | HTTPS | 443 | StorageGuard 10.1 and later, Option A |
| Hitachi Ops Center Common Services | HTTPS | 443 | StorageGuard 10.1 and later, Option C |
| Hitachi Ops Center Administrator | HTTPS | 443 | StorageGuard 10.1 and later, Option C |
| HPE 3PAR / Primera / Alletra 9000 | SSH HTTPS |
22 443 |
443 is for future use. With an InForm CLI proxy: SSH to the proxy |
| HPE Alletra 6000 / Nimble | HTTPS SSH |
5392 22 |
SSH is optional, recommended (CLI access) |
| HPE Alletra MP | HTTPS | 443 | |
| HPE OneView | HTTPS | 443 | |
| HPE StoreOnce | HTTPS SSH |
443 22 |
|
| HPE XP – through IMS | HTTPS | 443, 23451, 23450 | IMS is an OEM of Hitachi Ops Center |
| HPE XP – directly through the SVP | HTTPS | 443 | Not available on older XP models |
| IBM DS8000 – DSCLI proxy | SSH | 22 | The proxy connects to each DS8000 system |
| IBM FlashSystem / SVC / Storwize | SSH | 22 | |
| IBM Storage Protect – hub server (Linux / UNIX) | SSH | 22 | Server with the Administrative Client installed |
| IBM Storage Protect – hub server (Windows) | WinRM + CIFS, or WMI | See Windows host ports | Server with the Administrative Client installed |
| Infinidat InfiniBox | HTTPS | 443 | |
| Microsoft Azure | HTTPS | 443 | Outbound to the Azure management and sign-in endpoints |
| Nasuni Management Console (NMC) | HTTPS | 443 | |
| NetApp Active IQ Unified Manager | HTTPS | 443 | |
| NetApp ONTAP cluster | HTTPS SSH |
443 22 |
SSH is optional (custom collection) |
| NetApp StorageGRID Admin Node | HTTP / HTTPS | 443 | |
| Oracle ZFS Storage Appliance (ZFSSA) | HTTPS | 215 | |
| Pure Storage FlashArray / FlashBlade | HTTPS SSH |
443 22 |
Same credentials for both |
| Rubrik CDM | HTTPS | 443 | |
| VAST Data (VMS) | HTTPS | 443 | |
| Veeam Backup & Replication (VBR) server | WinRM + CIFS, or WMI HTTPS |
See Windows host ports 9419 |
9419 is the VBR REST API port |
| Veritas NetBackup primary server | HTTPS | 1556 | Formerly master server |
| Veritas NetBackup Flex Appliance | HTTPS SSH |
443 22 |
SSH is for future use |
| Veritas NetBackup 52x0 Appliance | SSH | 22 | Appliance shell menu |
| VMware vSAN – vCenter | HTTPS | 443 |
Windows host ports
For Windows hosts (for example Solutions Enabler, Hitachi CCI, Storage Protect hub, Veeam VBR, and Windows management hosts), open either WinRM and CIFS, or WMI:
| Method | Protocol | Default ports |
|---|---|---|
| WinRM (preferred) | WinRM + CIFS | 80, 5985 (WinRM), 445 (CIFS) |
| WMI (if WinRM isn't used) | WMI | All TCP ports, and UDP 135, 137, 138, 139 |
Management hosts (optional)
StorageGuard can also scan the hosts that run storage and backup management software, for complementary configuration collection. This is optional but recommended. See Storage / Backup Management host | Scan Requirements.
| Host OS | Protocol | Default port |
|---|---|---|
| Linux / UNIX | SSH | 22 |
| Windows | WinRM + CIFS, or WMI | See Windows host ports |
Examples of management hosts: Cisco NDFC, PowerMax Unisphere, NetApp Active IQ Unified Manager, NetBackup, Hitachi Ops Center, Hitachi CCI, Brocade SANnav, PowerFlex Manager, Cyber Recovery, PPDM, Unity Unisphere, and HPE IMS / SVP hosts.
[ Still need help? ]
Our support team is here for you. Submit a request
Comments
0 comments
Please sign in to leave a comment.