Skip to main content

Proxy Mode as a Service Port Requirements

The following are the firewall settings are required when executing the Access Auditing (FSAA) and/or Sensitive Data Discovery Auditing scans in proxy mode as a service for communication between Access Analyzer and the proxy server:

Communication DirectionProtocolPortsDescription
Between Access Analyzer Console and Windows Proxy ServerTCP8766FSAA Applet HTTPS communication security
Between Access Analyzer Console and Windows Proxy ServerTCP8767FSAA Applet Certificate Exchange

NOTE: The FSAA applet https requests configuration port 8766 and the FSAA Applet Certificate Exchange port 8767 can be customized on the Applet Settings page of the File System Access Auditor Data Collector Wizard.

The following are the firewall settings are required when executing the Access Auditing (FSAA) and/or Sensitive Data Discovery Auditing scans in proxy mode as a service for communication between the proxy server and the target host:

Communication DirectionProtocolPortsDescription
Windows Proxy Server to File Server/DeviceTCP445SMB

Additional Firewall Rules for NetApp Data ONTAP Devices

Remember, NetApp communication security is configured on the Scan Settings page of the File System Access Auditor Data Collector Wizard. One additional firewall setting is required when targeting either a NetApp Data ONTAP 7-Mode device or a NetApp Data ONTAP Cluster-mode device. The required setting is dependent upon how the NetApp communication security option is configured:

Communication DirectionProtocolPortsDescription
Access Analyzer Console to NetApp DeviceTCP80HTTP NetApp communication security
Access Analyzer Console to NetApp DeviceTCP443HTTPS NetApp communication security

Additional Consideration for Windows File Servers

The following firewall setting is also required when targeting a Windows file server:

Communication DirectionProtocolPortsDescription
Access Analyzer Console to Windows ServerTCP135for pre-scan access checks

RECOMMENDED: Configure target hosts to respond to ping requests.