HostMon behind firewall

All questions related to installations, configurations and maintenance of Advanced Host Monitor (including additional tools such as RMA for Windows, RMA Manager, Web Servie, RCC).
Post Reply
Thore
Posts: 23
Joined: Thu Nov 26, 2009 7:08 am

HostMon behind firewall

Post by Thore »

Hi all

Can somebody tell me which ports are needed to open on a firewall so HostMon is able to proceed it's test?
Currently we are not using any RMAs on the servers which should be tested by HostMon
Thanks for your comments

Best regards
Thorsten
KS-Soft
Posts: 12825
Joined: Wed Apr 03, 2002 6:00 pm
Location: USA
Contact:

Post by KS-Soft »

We got this question everyday. Somehow a lot of people do not understand - in order to check standard Windows and Internet services HostMonitor should use standard ports assigned for these services.
This means everything depends on what exactly service you are checking.

E.g.
FTP protocol uses TCP ports 20 and 21
SMTP protocol uses TCP port 25
DNS protocol uses port 53
POP3 protocol uses port 110
IMAP protocl uses port 143
NTP protocol uses port 123
HTTP protocl uses port 80
HTTPS protocl uses port 443
LDAP protocol uses port 389
SNMP protocol uses port 161 (162 for SNMP Traps)
Sure, some specific servers can be configured to use non-standard TCP/UDP ports. If you don't know what ports are used by your servers, you should ask your network administrator.

HostMonitor calls network client installed on your system to perform the following tests:
- UNC
- Drive free space
- File/Filder availability
- Folder/file size
- Count files
- File integrity
- Text log
- Compare file, etc.
This means used ports and protocols depend on network client you are using.
E.g. NETBIOS over TCP uses ports 137-139, 445. If you are using different network client, please check the manual that comes with your network client.

HostMonitor uses Windows RPC for the following test methods:
- NT eventlog test
- Services test
- Process
- Dominant Process
- Performance counter test
- CPU usage
- WMI test
Windows RPC calls may use any port above 1024.

How to configure RPC dynamic port allocation to work with firewalls
http://support.microsoft.com/kb/154596

Another useful article from Microsoft: network port requirements for the Windows Server system
http://support.microsoft.com/kb/832017

On the other hand, firewall that passes thru NETBIOS, RPC, DCOM traffic does not have much sense. If you need to monitor remote network protected by firewall, we strongly recommend using RMA
http://www.ks-soft.net/hostmon.eng/rma-win/index.htm

Regards
Alex
Thore
Posts: 23
Joined: Thu Nov 26, 2009 7:08 am

Post by Thore »

Hi Alex

That's exactly the info I expected. So it really might be better to use RMA and then only 1 Ports must be opened. Am I correct with this?
Thanks so far

Best regards
Thorre
KS-Soft
Posts: 12825
Joined: Wed Apr 03, 2002 6:00 pm
Location: USA
Contact:

Post by KS-Soft »

Yes, RMA uses just 1 TCP port and encrypts all traffic.

Regards
Alex
User avatar
greyhat64
Posts: 246
Joined: Fri Mar 14, 2008 9:10 am
Location: USA

Post by greyhat64 »

Yes, but you'll need an additional port for RMA Manager communication (default 5057/TCP)
KS-Soft
Posts: 12825
Joined: Wed Apr 03, 2002 6:00 pm
Location: USA
Contact:

Post by KS-Soft »

Passive RMA does not require additional port.
Active RMA does not need any port to be opened on system where agent is running (it connects to HostMonitor so port should be opened on HostMonitor/RMA Manager side)

Regards
Alex
Post Reply