Firewall Considerations
Keyfactor Command must be able to communicate with the servers and services required by the deployment. Depending on the environment, this may include communication between Keyfactor Command components installed on different servers, the Microsoft SQL Server database, certificate authorities, identity providers, centralized logging servers, and other configured integrations.
If firewalls or network security controls restrict internal traffic, configure them to allow the required communication between each source and target. Table 91: Protocols Keyfactor Command Uses for Communication lists the common Keyfactor Command communication paths and the protocols and ports used for each one.
Table 91: Protocols Keyfactor Command Uses for Communication
|
Source |
Target |
Protocols and Ports |
|---|---|---|
| Client browser (for example, Microsoft Edge) | Keyfactor Command Management Portal | HTTP/HTTPS: TCP 80/443, or configured ports |
|
Keyfactor Command |
Certificate revocation list (CRL) distribution points |
HTTP/HTTPS: TCP 80/443, or configured ports |
|
Keyfactor Command |
EJBCA Certificate Authorities |
HTTP/HTTPS: TCP 80/443, or configured ports |
|
Keyfactor Command |
Microsoft Certificate Authorities |
RPC/DCOM: TCP 135 plus random high ports typically in the range 49152 – 65535 |
|
Keyfactor Command |
Keyfactor REST CA Gateways |
HTTP/HTTPS: TCP 80/443, or configured ports |
|
Keyfactor Command |
Keyfactor DCOM CA Gateways |
RPC/DCOM: TCP 135 plus random high ports typically in the range 49152 – 65535 |
|
Keyfactor Command |
Microsoft SQL Server database, including named instances |
|
|
Keyfactor Command |
Centralized logging solution |
Varies depending on the implemented solution. For example, some standard defaults are:
|
| Keyfactor Command | OAuth/OIDC identity provider, if OAuth authentication is used | HTTPS: TCP 443, or configured port |
| Keyfactor Command |
Microsoft Active Directory domain controllers, if Active Directory authentication is used Note: If Keyfactor Command is installed in a child domain, this communication is also required to the domain controllers in the forest root domain.
|
|
| Keyfactor Command SSH Management | Microsoft Active Directory for group membership enumeration | Active Directory Web Services: TCP 9389 |
|
All Orchestrators and Agents |
Keyfactor Command Orchestrator API endpoint |
HTTP/HTTPS: TCP 80/443, or configured ports |
|
Keyfactor Universal Orchestrator with Extension Relying on PowerShell Remoting and WinRM |
Windows Servers to which certificate files will be distributed |
PowerShell Remoting: TCP 5985 and 5986, or configured ports |
|
Keyfactor Universal Orchestrator
|
The SSL endpoint being scanned by the SSL discovery or monitoring job |
Any configured for scanning |
|
Keyfactor Universal Orchestrator with Extension Relying on HTTP/HTTPS |
F5 or NetScaler Devices |
HTTP/HTTPS: TCP 80/443, or configured ports |
|
Keyfactor Universal Orchestrator
|
Microsoft Certificate Authorities |
RPC/DCOM: TCP 135 plus random high ports typically in the range 49152 – 65535 |
| Keyfactor Bash Orchestrator | Remote control targets for SSH management | SSH: TCP 22, or configured port |
|
Keyfactor DCOM and REST CA Gateways to Cloud CAs |
Cloud providers (for example, Entrust, Symantec) |
HTTP/HTTPS: TCP 80/443, or configured ports |
| Keyfactor Cloud Gateway | Microsoft Active Directory for group membership enumeration | Active Directory Web Services: TCP 9389 |
Was this page helpful? Provide Feedback