Skip to main content
Version: 3.25

Firewall Requirements

Listed below are the ports required to release firewall rules in each senhasegura instance of the architecture:

Source or Destination:

  • SSAPLPRD: senhasegura Production Appliance
  • SSAPLMBR: senhasegura Secondary Members

Between senhasegura and management systems

PermissionProtocolSourceSource PortDestinationDestination Port
ALLOWUDPSSAPLPRDANYNTP server123
ALLOWUDPSSAPLPRDANYDNS server53
ALLOWTCPSSAPLPRDANYMAIL serverSMTP
ALLOWTCPSSAPLPRDANYLDAP serverLDAP
ALLOWTCPSSAPLPRDANYLDAP serverLDAPS
ALLOWUDPSSAPLPRDANYRADIUS serverRADIUS
ALLOWTCPSSAPLPRDANYTACACS serverTACACS
ALLOWUDPSSAPLPRDANYTACACS serverTACACS
ALLOWTCPSSAPLPRDANYLOG serverSYSLOG
ALLOWUDPSSAPLPRDANYLOG serverSYSLOG
ALLOWTCPSSAPLPRDANYBACKUP serverTFTP
ALLOWTCPSSAPLPRDANYBACKUP serverSFTP
ALLOWTCPSSAPLPRDANYBACKUP serverNFS
ALLOWTCPSSAPLPRDANYBACKUP serverSMB

Between management systems and senhasegura

PermissionProtocolSourceSource PortDestinationDestination Port
ALLOWTCPBACKUP serverANYSSAPLPRDTFTP
ALLOWTCPBACKUP serverANYSSAPLPRDSFTP
ALLOWTCPBACKUP serverANYSSAPLPRDNFS
ALLOWTCPBACKUP serverANYSSAPLPRDSMB

Between the users with senhasegura

PermissionProtocolSourceSource PortDestinationDestination Port
ALLOWTCPit_usersANYSSAPLPRDHTTPS
ALLOWTCPit_usersANYSSAPLPRDHTTP
ALLOWTCPit_usersANYSSAPLPRDSSH
ALLOWTCPit_usersANYSSAPLPRDRDP

Between senhasegura and managed devices

PermissionProtocolSourceSource PortDestinationDestination Port
ALLOWTCPSSAPLPRDANYtarget_deviceSSH
ALLOWTCPSSAPLPRDANYtarget_deviceTELNET
ALLOWTCPSSAPLPRDANYtarget_deviceORACLE
ALLOWTCPSSAPLPRDANYtarget_deviceMS-SQL
ALLOWTCPSSAPLPRDANYtarget_devicePOSTGRE
ALLOWTCPSSAPLPRDANYtarget_deviceMySQL
ALLOWTCPSSAPLPRDANYtarget_deviceRDP
ALLOWTCPSSAPLPRDANYtarget_deviceRPC
ALLOWTCPSSAPLPRDANYtarget_deviceRM
ALLOWTCPSSAPLPRDANYtarget_deviceSMB
ALLOWTCPSSAPLPRDANYtarget_deviceHTTP
ALLOWTCPSSAPLPRDANYtarget_deviceHTTPS

Between senhasegura instances, if applicable

PermissionProtocolSourceSource PortDestinationDestination Port
ALLOWTCPSSAPLPRDANYSSAPLMBRSSH
ALLOWTCPSSAPLPRDANYSSAPLMBRMySQL
ALLOWTCPSSAPLPRDANYSSAPLMBR9300
ALLOWTCPSSAPLPRDANYSSAPLMBR4567
ALLOWTCPSSAPLPRDANYSSAPLMBR4568
ALLOWTCPSSAPLPRDANYSSAPLMBR4444
ALLOWUDPSSAPLPRDANYSSAPLMBR4567
ALLOWTCPSSAPLPRDANYSSAPLMBRHTTP
ALLOWTCPSSAPLPRDANYSSAPLMBRHTTPS
ALLOWTCPSSAPLMBRANYSSAPLPRDSSH
ALLOWTCPSSAPLMBRANYSSAPLPRDMySQL
ALLOWTCPSSAPLMBRANYSSAPLPRD9300
ALLOWTCPSSAPLMBRANYSSAPLPRD4567
ALLOWTCPSSAPLMBRANYSSAPLPRD4568
ALLOWTCPSSAPLMBRANYSSAPLPRD4444
ALLOWUDPSSAPLMBRANYSSAPLPRD4567
ALLOWTCPSSAPLMBRANYSSAPLPRDHTTP
ALLOWTCPSSAPLMBRANYSSAPLPRDHTTPS