Firewall Considerations

Keyfactor Command must be able to communicate with the servers and services required by the deployment. Depending on the environment, this may include communication between Keyfactor Command components installed on different servers, the Microsoft SQL Server database, certificate authorities, identity providers, centralized logging servers, and other configured integrations.

If firewalls or network security controls restrict internal traffic, configure them to allow the required communication between each source and target. Table 91: Protocols Keyfactor Command Uses for Communication lists the common Keyfactor Command communication paths and the protocols and ports used for each one.

Table 91: Protocols Keyfactor Command Uses for Communication

Source

Target

Protocols and Ports

Client browser (for example, Microsoft Edge) Keyfactor Command Management Portal HTTP/HTTPS: TCP 80/443, or configured ports

Keyfactor Command

Certificate revocation list (CRL) distribution points

HTTP/HTTPS: TCP 80/443, or configured ports

Keyfactor Command

EJBCA Certificate Authorities

HTTP/HTTPS: TCP 80/443, or configured ports

Keyfactor Command

Microsoft Certificate Authorities

RPC/DCOM: TCP 135 plus random high ports typically in the range 49152 – 65535

Keyfactor Command

Keyfactor REST CA Gateways

HTTP/HTTPS: TCP 80/443, or configured ports

Keyfactor Command

Keyfactor DCOM CA Gateways

RPC/DCOM: TCP 135 plus random high ports typically in the range 49152 – 65535

Keyfactor Command

Microsoft SQL Server database, including named instances

  • TCP 1433 or configured SQL Server listener port

  • UDP 1434 for SQL Server Browser, if used

Keyfactor Command

Centralized logging solution

Varies depending on the implemented solution. For example, some standard defaults are:

  • TCP 514 for rsyslog

  • TCP 5000 for Logstash

Keyfactor Command OAuth/OIDC identity provider, if OAuth authentication is used HTTPS: TCP 443, or configured port
Keyfactor Command

Microsoft Active Directory domain controllers, if Active Directory authentication is used

Note:  If Keyfactor Command is installed in a child domain, this communication is also required to the domain controllers in the forest root domain.
  • LDAP: TCP/UDP 389

  • Kerberos: TCP/UDP 88

  • NetBIOS Session Service: TCP 139

  • SMB /Microsoft-DS: TCP 445

Keyfactor Command SSH Management Microsoft Active Directory for group membership enumeration Active Directory Web Services: TCP 9389

All Orchestrators and Agents

Keyfactor Command Orchestrator API endpoint

HTTP/HTTPS: TCP 80/443, or configured ports

Keyfactor Universal Orchestrator with Extension Relying on PowerShell Remoting and WinRM
(IIS and Remote File Extensions)

Windows Servers to which certificate files will be distributed

PowerShell Remoting: TCP 5985 and 5986, or configured ports

Keyfactor Universal Orchestrator
(SSL Endpoint Management)

The SSL endpoint being scanned by the SSL discovery or monitoring job

Any configured for scanning

Keyfactor Universal Orchestrator with Extension Relying on HTTP/HTTPS
(F5 and Citrix NetScaler Certificate Store Management)

F5 or NetScaler Devices

HTTP/HTTPS: TCP 80/443, or configured ports

Keyfactor Universal Orchestrator
(Remote Certificate Authority)

Microsoft Certificate Authorities

RPC/DCOM: TCP 135 plus random high ports typically in the range 49152 – 65535

Keyfactor Bash Orchestrator Remote control targets for SSH management SSH: TCP 22, or configured port

Keyfactor DCOM and REST CA Gateways to Cloud CAs

Cloud providers (for example, Entrust, Symantec)

HTTP/HTTPS: TCP 80/443, or configured ports

Keyfactor Cloud Gateway Microsoft Active Directory for group membership enumeration Active Directory Web Services: TCP 9389