NAICE ports used for external communication

Default port values are provided


Source Source portDestinationDestination portTransport protocolNotes
RADIUS traffic processing
NASanyNAICE1812UDPAccess-Request authorization requests 
NASanyNAICE1813UDPAccounting-Request accounting requests 
TACACS+ traffic processing
TACACS+ clientsanyNAICE49TCPSending TACACS+ requests and accounting
DHCP fingerprint processing for profiling
Supplicant  / DHCP Relay Agent67/68NAICE67UDPDHCP client requests for fingerprint collection
Portal-based authorization
client networkanyNAICE8443TCP Access to the web portal for portal-based authorization
NAICE administration
administrative networkanyNAICE22TCP

Server access for management via CLI over SSH or configuration using Ansible playbooks

administrative networkanyNAICE80TCP

Access to the server over HTTP (used only for redirection to secure port 443)

administrative networkanyNAICE443TCP

Access to the server web GUI over HTTPS

administrative networkanyNAICE8000TCP

Access to the NAICE administration web GUI deployed from OVA/QCOW2 images

Sending logs via the Syslog protocol
NAICEanySyslog server514UDP

Sending logs and TACACS+ accounting via Syslog to an external Syslog server

Interaction with an external MS AD data source
NAICEanyDNS53UDP

Server responsible for domain name resolution, including MS AD domain

NAICEanyMS AD server389TCP/UDPAccess to MS AD server over LDAP
NAICEanyMS AD server636TCP

Access to MS AD server over LDAPS (TLS encryption is used)

NAICEanyMS AD server3268TCP/UDP

Access to MS AD server over LDAP (may be used instead of port 389)

NAICEanyMS AD server3269TCP

Access to MS AD server over LDAPS (may be used instead of port 636)

NAICEanyMS AD server49152-65535TCP/UDP

Access to MS AD server for netlogon requests

Interaction with an external LDAP data source
NAICEanyLDAP server389TCP/UDPAccess to LDAP server
NAICEanyLDAP server636TCP

Access to LDAPS server (TLS encryption is used)

Interaction with an external SMS gateway
NAICEanySMS gateway80TCP

Access to SMS gateway over HTTP

NAICEanySMS gateway443TCP

Access to SMS gateway over HTTPS

Interaction with an external SMTP server
NAICEanySMTP server25TCP

Access to SMTP server

NAICEanySMTP server465TCP

Access to SMTP server (TLS encryption is used)

NAICEanySMTP server587TCPAccess to SMTP server (TLS encryption is used)
Ports used by NAICE nodes in a high-availability deployment
PostgreSQL databaseanyNAICE5432TCP

Access to the database from NAICE services

PostgreSQL databaseanyneighboring PostgreSQL node15432TCP

Port used by Replication Manager for PostgreSQL for data synchronization between database nodes

NAICE nodeanyneighboring NAICE node5701TCP

Port used for data synchronization between naice-ovis services

NAICE nodeanyneighboring NAICE node5702TCP

Port used for data synchronization between naice-vulpus services

NAICE nodeanyneighboring NAICE node5703TCP

Port used for data synchronization between naice-aquila services

NAICE nodeanyneighboring NAICE node5704TCP

Port used for data synchronization between naice-bubo services

NAICE nodeanyneighboring NAICE node5705TCP

Port used for data synchronization between naice-castor services

NAICE nodeanyneighboring NAICE node5706TCP

Port used for data synchronization between naice-mustela services

NAICE nodeanyneighboring NAICE node6222TCP

Port used for data exchange between nodes via the naice-nats service

Interaction between NAICE and the Peeper monitoring system

NAICE

anymonitoring server443TCP

Sending monitoring data to Peeper using the Peeper Client installed on the NAICE server

List of ports used by NAICE containers

 Container nameExternal portInternal portTransport protocolInternal/ExternalNotes
epg-service81008100TCPinternal 
naice-aquila

49

49TCPexternal
57035703TCPexternal

Used only in a high-availability deployment. In a single-host installation, it is bound to 127.0.0.1

8091-80928091-8092TCPinternal 
naice-bubo80938093TCPinternal 
57045704TCPexternal

Used only in a high-availability deployment. In a single-host installation, it is bound to 127.0.0.1

naice-castor 80958095TCPinternal 
57055705TCPexternal

Used only in a high-availability deployment. In a single-host installation, it is bound to 127.0.0.1

naice-cetus80998099TCPinternal 
naice-gavia80808080TCPinternal 
naice-gulo80898089TCPinternal 
naice-lemmus80838083TCPinternal 
naice-lepus80878087TCPinternal 
671024UDPexternal
naice-mustela80708070TCPinternal 
naice-nats42224222TCPinternal 
62226222TCPexternal

Used only in a high-availability deployment

77777777TCPinternal 
82228222TCPexternal

Web GUI, may be used by an administrator for diagnostics

naice-ovis57015701TCPexternal

Used only in a high-availability deployment. In a single-host installation, it is bound to 127.0.0.1

80848084TCPinternal 
naice-phoca80978097TCPinternal 
naice-postgres54325432TCPinternal/externalExternal access is required in a high-availability deployment
1543215432TCPexternal

Used only in a high-availability deployment

naice-radius1812-18131812-1813UDPexternal
98129812TCPinternal 
naice-sterna844380 / 444TCPexternal

The internal port depends on the selected portal access mode: HTTP or HTTPS

naice-ursus80818081TCPinternal 
naice-vulpus57025702TCPexternal

Used only in a high-availability deployment. In a single-host installation, it is bound to 127.0.0.1

80868086TCPinternal 
80888088TCPinternal 
naice-web804200TCPexternal

Used only for redirection to secure port 443

443443TCPexternal

List of ports used by Peeper monitoring system containers installed on the NAICE server

Container nameExternal portInternal portTransport protocolInternal/ExternalNotes
naice-aquila80918091TCPinternal 
naice-bubo80938093TCPinternal 
naice-castor80958095TCPinternal Access via HTTPS
naice-cetus80998099TCPinternal 
naice-gavia80808080TCPinternal Access via HTTPS
naice-gulo80898089TCPinternal 
naice-lemmus80838083TCPinternal Access via HTTPS
naice-lepus80878087TCPinternal 
naice-mustela80708070TCPinternal 
naice-ovis80848084TCPinternal 
naice-radius98129812TCPinternal 
naice-ursus80818081TCPinternal 
naice-vulpus80868086TCPinternal 
naice-nats77777777TCPinternal 


  • Нет меток