
62
This appendix contains network requirements, including addresses,
protocols, and ports, of a typical CC-SG deployment. It includes
information about how to configure your network for both external access
and internal security and routing policy enforcement. Details are provided
for the benefit of a TCP/IP network administrator. The TCP/IP
administrator's role and responsibilities may extend beyond that of a
CC-SG administrator. This appendix will assist the administrator in
incorporating CC-SG and its components into a site's security access
and routing policies.
The tables contain the protocols and ports that are needed by CC-SG
and its associated components.
In This Chapter
Required Open Ports for CC-SG Networks: Executive Summary...........62
CC-SG Communication Channels...........................................................63
Required Open Ports for CC-SG Networks: Executive Summary
The following ports should be opened:
Port Number Protocol Purpose Details
80 TCP HTTP Access to CC-SG Not encrypted.
443 TCP HTTPS (SSL) Access to CC-SG SSL/AES128 encrypted.
8080 TCP CC-SG to PC Client SSL/AES128 encrypted if
configured.
2400 TCP Node Access (Proxy Mode) SSL/AES128 encrypted if
configured.
5000 TCP Node Access (Direct Mode) These ports need to be opened per
Raritan device that will be
externally accessed. The other
ports in the table need to be
opened only for accessing CC-SG.
AES128 encrypted if configured.
80 and 443 for Control
System nodes
80, 443, 902, and 903 for
Virtual Host and Virtual
Machine Nodes
TCP Virtual Node Access N/A
Appendix C
CC-SG and Network Configuration
Komentáře k této Příručce