|
||||
LDMS Components | Platform Applicability | |||||||||
Protocol | Port | Component | Direction | Component | Description | Version | PC | Mac | Linux | |
UDP | 67 | Client | --> | PXE Rep | PXE (Broadcast) | 8.7 - 8.8 | Y | N | Y | |
UDP | 68 | PXE Rep | --> | Client | PXE | 8.7 - 8.8 | Y | N | N | |
UDP | 69 | Client | --> | PXE Rep | TFTP | 8.7 - 8.8 | Y | N | Y | |
TCP | 80 | Client | --> | Core | Vulscan | 8.7 - 8.8 | Y | Y (ldpatch) | Y | |
TCP | 443 | Console,Client | --> | Core | HTTPS Mgmt | 8.7 - 8.8 | Y | Y | Y | |
TCP | 139(445) | Console | --> | Core | Remote Console Login | 8.7 - 8.8 | Y | N | N | |
UDP | 1758 | PXE Rep | --> | Client | MTFTP | 8.7 - 8.8 | Y | N | N | |
UDP | 1759 | Client | --> | PXE Rep | MTFTP | 8.7 - 8.8 | Y | N | Y | |
UDP | 4011 | Client | --> | PXE Rep | PXE (Unicast) | 8.7 - 8.8 | Y | N | Y | |
TCP | 5007 | Client | --> | Core | Inventory | 8.7 - 8.8 | Y | Y | Y | |
TCP | 9535 | Core,Console | --> | Client | Remote Mgmt | 8.7 - 8.8 | Y | Y | Y | |
UDP | 9535 | XDD Client | --> | XDD Client | Device Discovery | 8.7 - 8.8 | Y | N | N | |
TCP | 9593 | Core | --> | Client | Software Dist | 8.7 - 8.8 | Y | Y | Y | |
TCP | 9594 | Core | <--> | Client | Software Dist | 8.7 - 8.8 | Y | Y | Y | |
UDP/TCP | 9595 | Core,Console | <--> | Client | Agent Discovery | 8.7 - 8.8 | Y | Y | Y | |
TCP | 9971 | Core | --> | Client | Agentless AMT Discovery | 8.7 - 8.8 | Y | N | N | |
TCP | 9982 | Client | --> | Core | AMT Discovery (VPro) | 8.7 - 8.8 | Y | N | N | |
TCP | 12174 | Core | --> | Client | Remote Execute | 8.7 - 8.8 | Y | Y | Y | |
TCP | 12175 | Client | --> | Core | Policy Based SW Dist | 8.7 - 8.8 | Y | Y | N | |
TCP | 12176 | Client | --> | Core | Policy Based SW Dist | 8.7 - 8.8 | Y | Y | N | |
TCP | 16992 | Core | <--> | Client | HTTP AMT Mgmt | 8.7 - 8.8 | Y | N | N | |
TCP | 16993 | Core | <--> | Client | HTTPS AMT Mgmt | 8.7 - 8.8 | Y | N | N | |
TCP | 16994 | Core | <--> | Client | AMT Hello Packets | 8.7 - 8.8 | Y | N | N | |
TCP | 33354 | Client | --> | Client | Peer Download | 8.7 - 8.8 | Y | Y | N | |
UDP/TCP | 33354 | Core | --> | Subnet Rep | Multicast | 8.7 - 8.8 | Y | N | N | |
UDP | 33355 | Subnet Rep | --> | Client | Multicast | 8.7 - 8.8 | Y | Y | N | |
**This traffic is on the local subnet only | ||||||||||
Non-LDMS Components | Platform Applicability | |||||||||
Protocol | Port | Component | Direction | Component | Description | Version | ||||
TCP | 80 | Client | --> | Source | URL Download | * | Y | Y | Y | |
TCP | 80 | Console | --> | Core | HTTP Mgmt | * | Y | Y | Y | |
TCP | 389 | Core | --> | Directory | LDAP Queries | * | Y | Y | Y | |
TCP | 443 | Console,Client | --> | Core | HTTPS Mgmt | * | Y | Y | Y | |
TCP | 445 | Client | --> | Source | UNC Download | * | Y | N | N | |
TCP | 1433 | Console,Core | --> | Database | MS-SQL | * | Y | Y | Y | |
TCP | 1521 | Console,Core | --> | Database | Oracle | * | Y | Y | Y | |
***Denotes default setting. User can customize port number information. | ||||||||||
Legacy LDMS Components | Platform Applicability | |||||||||
Protocol | Port | Component | Direction | Component | Description | Version | ||||
TCP | 1761 | Console | --> | Client | Remote Control | < 8.5 | Y | Y | N | |
TCP | 1762 | Console | --> | Client | Remote Control | < 8.5 | Y | Y | N | |
TCP | 1761 | Console | --> | Client | MAC Remote Control | < = 8.7 - 8.8 | N | Y | N | |
TCP | 1762 | Console | --> | Client | MAC Remote Control | < = 8.7 - 8.8 | N | Y | N | |
TCP/UDP | 33353 | Core | --> | Subnet Rep | Multicast | < 8 | Y | N | N | |
TCP | 38292 | Client | <--> | All | CBA | < 8 | Y | Y | Y | |
UDP | 38293 | Client | <--> | All | Agent Discovery | < 8 | Y | Y | Y | |
you're right, read core as "any console/web console"
Merge with doc 2523 and add the following
Intel AMT Ports that must be open to function properly.
Intel AMT Ports (These ports cannot be changed)
16992 (non-TLS)
16993 (TLS)
16994 (non-TLS Redirection)
16995 (TLS Redirection)
LANDesk Ports
9971 (Agentless AMT Discovery)
Could we update this list to 8.8 -
I guess that alerting and SWD Policy are now on different ports (assuming a pure 8.8 environment)?
it should be webservice based (80) for both.
NetBIOS:139/TCP is missing, please confirm then add it in the list, if it’s required.
We saw LANDesk traffic over port 38293 on our firewalls in LDMG 8.8. Are you sure this port isn't used anymore? We never had the legacy versions...
I think we may try to use the old ports if we are looking for a device and it doesn't respond to the new ports.
So you don't need to enable those ports as they are only fall back methods which you would never need unless you actually had older stuff.
|
|||||
Should there not also be a connection from the Console --> Client for port 9535 for remote management? Right now it only lists Core --> Client.