Skip to main content

LevelBlue Completes Acquisition of Cybereason.  Learn More

LevelBlue Completes Acquisition of Cybereason.  Learn More

Services
Cyber Advisory
Managed Cloud Security
Data Security
Managed Detection & Response
Email Security
Managed Network Infrastructure Security
Exposure Management
Security Operations Platforms
Incident Readiness & Response
SpiderLabs Threat Intelligence
Solutions
BY TOPIC
Offensive Security
Solutions to maximize your security ROI
Operational Technology
End-to-end OT security
Microsoft Security
Unlock the full power of Microsoft Security
Securing the IoT Landscape
Test, monitor and secure network objects
Why LevelBlue
About Us
Awards and Accolades
LevelBlue SpiderLabs
LevelBlue Security Operations Platforms
Security Colony
Partners
Microsoft Security
Unlock the full power of Microsoft Security
Technology Alliance Partners
Key alliances who align and support our ecosystem of security offerings
Loading...
Loading...

INFO: What are the different installation scenarios for WebMarshal?

Expand / Collapse


This article applies to:

  • WebMarshal 6.X and 7.X

Question:

  • What are the different ports that need to be opened when installing the WebMarshal Array Nodes in the DMZ? 
  • Can WebMarshal be installed in a DMZ?
  • What are the different installation scenarios for WebMarshal?

Information:

There are two different installation scenarios for WebMarshal. They are:

  • The Array Manager and Array Nodes are installed on the Internal Network (recommended)
  • The Array Manager is installed on the Internal Network and the Array Nodes in the DMZ
Note: LevelBlue recommends that the WebMarshal Array Manager and Array Nodes are all installed on the Internal Network.
  • WebMarshal authentication requires access to user information from AD or Novell.
  • As best security practice the required ports should not be open to the DMZ.

Ports Required:

The following ports needs to be opened (outbound from the trusted network unless noted otherwise) for the different installation scenarios:

  

Array Manager and Array Nodes installed on the Internal Network

Array Manager installed on the Internal Network and the Array Nodes in the DMZ

TCP (HTTP) outbound

80

 

TCP (Alternative HTTP) outbound

8080 (or other alternate ports - some content delivery sites require this)

8080
(or other proxy port as configured)

TCP (HTTPS) outbound

443 (occasionally other ports are also used)

  

TCP/UDP (DNS) inbound (to resolve AD)

 

53

TCP/UDP (NetBIOS) - Windows Authentication inbound

 

137, 138, 139

TCP/UDP (SMB) - Windows Authentication inbound

 

445

TCP (Array Manager-node communication): Internal Network to DMZ)

 

19102

TCP (Array Manager-Node communication): TCP - DMZ to Internal Network

 

19101

If Novell authentication in use (User Authentication TCP/NCP)

 

 427

If Novell authentication in use (User Authentication SLP TCP/UDP) 

 

 524


To contact LevelBlue about this article or to request support:


Rate this Article:
     
Tags:

Related Articles



Add Your Comments


Comment submission is disabled for anonymous users.
Please send feedback to Trustwave Technical Support or the Webmaster
.