Firewall rules are very important as LibraCyber ESG needs to communicate with updated servers and DNS over the internet. This tool allows checking if required ports are correctly opened.
Required ports
Required ports are as follows:
- SMTP Traffic port (TCP 25) (bi-directional)
- Network Checks:
- Razor2 (TCP port 2703 outbound)
- Pyzor (UDP port 24441 outbound)
- DCC (UDP port 6277 outbound)
- HTTPS (TCP port 443 outbound)
- DNS (port 53 outbound)
- HTTP (TCP port 80 outbound)
- SaneSecurity Signatures Ports (TCP 873 outbound)
Some other incoming ports may be opened:
- LDAP (TCP 389 from ESG to LDAP Server) for LDAP queries
- LDAPS (TCP 686 from ESG to LDAPS Server) for LDAPS queries
Note: you can simply reload the page if you want to restart firewall checks (if you are still setting up the firewall).
Cluster scenario
In a cluster scenario, in addition to the above requirements, the following ports must be opened between nodes:
- SSH traffic (TCP port 22)
- HTTPS traffic (TCP port 443)
- MySQL database replication traffic (TCP port 3306)
- PING via ICMP