<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Multi-tier Environemnt Firewall Port Exceptions in Administration and Deployment</title>
    <link>https://communities.sas.com/t5/Administration-and-Deployment/Multi-tier-Environemnt-Firewall-Port-Exceptions/m-p/535395#M15636</link>
    <description>&lt;P&gt;I have searched and had various helpful posts and instruction manuals, but nothing concrete, so I just thought I would ask the community.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have been running our multi-tier environment for a few years now, wide open (no firewall). We now must implement a firewall, per company security. Our sas installer has been hesitant to assist in this endeavor. We are running Oracle 6.8, if that helps or matters. Our environment structure will be listed below in the outline and our proposed method.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Tools that people are using: VA, SMC, EG, Text Miner, SAS DI Studio, SAS Studio, Environment Manager, Document Conversion Server.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Global rules:&lt;/STRONG&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;All outbound will be open.&lt;/LI&gt;&lt;LI&gt;Between the 7 sas servers, all ports and protocols will be open.&lt;/LI&gt;&lt;LI&gt;Ping is open to a specific server (network monitoring server)&lt;/LI&gt;&lt;LI&gt;Loopback is enabled&lt;/LI&gt;&lt;LI&gt;Port 22 is open for SSH&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;U&gt;&lt;STRONG&gt;SAS client tools port rules:&lt;/STRONG&gt;&lt;/U&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Web:&lt;/STRONG&gt;&lt;BR /&gt;7980 # SAS Web Server HTTP Port&lt;BR /&gt;8343 # SAS Web Server HTTPS Port&lt;BR /&gt;7080 # Environment Manager HTTP&lt;BR /&gt;7443 # Environment Manager HTTPS&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Meta:&lt;/STRONG&gt;&lt;BR /&gt;8561 # Management Console&lt;BR /&gt;8591 # Enterprise Guide&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Compute:&lt;/STRONG&gt;&lt;BR /&gt;8701 # pooled workspace server port&lt;BR /&gt;8591 # Enterprise Guide&lt;BR /&gt;8601, 8611, 8621, 8631 # stored process server port&lt;BR /&gt;5308 # idk what this one is used for, but installer did mention it&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;VA:&lt;/STRONG&gt;&lt;BR /&gt;8701 # pooled workspace server port&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;VA worker 1-3:&lt;/STRONG&gt;&lt;BR /&gt;Nothing SAS specific has been opened&lt;/P&gt;&lt;P&gt;At first I was concerned about ldap and odbc database connections, but then realized they would be covered under outgoing. So is there anything else that I may have missed or need to open. Or does this path forward appear to be good?&lt;/P&gt;</description>
    <pubDate>Wed, 13 Feb 2019 20:27:10 GMT</pubDate>
    <dc:creator>five</dc:creator>
    <dc:date>2019-02-13T20:27:10Z</dc:date>
    <item>
      <title>Multi-tier Environemnt Firewall Port Exceptions</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/Multi-tier-Environemnt-Firewall-Port-Exceptions/m-p/535395#M15636</link>
      <description>&lt;P&gt;I have searched and had various helpful posts and instruction manuals, but nothing concrete, so I just thought I would ask the community.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have been running our multi-tier environment for a few years now, wide open (no firewall). We now must implement a firewall, per company security. Our sas installer has been hesitant to assist in this endeavor. We are running Oracle 6.8, if that helps or matters. Our environment structure will be listed below in the outline and our proposed method.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Tools that people are using: VA, SMC, EG, Text Miner, SAS DI Studio, SAS Studio, Environment Manager, Document Conversion Server.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Global rules:&lt;/STRONG&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;All outbound will be open.&lt;/LI&gt;&lt;LI&gt;Between the 7 sas servers, all ports and protocols will be open.&lt;/LI&gt;&lt;LI&gt;Ping is open to a specific server (network monitoring server)&lt;/LI&gt;&lt;LI&gt;Loopback is enabled&lt;/LI&gt;&lt;LI&gt;Port 22 is open for SSH&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;U&gt;&lt;STRONG&gt;SAS client tools port rules:&lt;/STRONG&gt;&lt;/U&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Web:&lt;/STRONG&gt;&lt;BR /&gt;7980 # SAS Web Server HTTP Port&lt;BR /&gt;8343 # SAS Web Server HTTPS Port&lt;BR /&gt;7080 # Environment Manager HTTP&lt;BR /&gt;7443 # Environment Manager HTTPS&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Meta:&lt;/STRONG&gt;&lt;BR /&gt;8561 # Management Console&lt;BR /&gt;8591 # Enterprise Guide&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Compute:&lt;/STRONG&gt;&lt;BR /&gt;8701 # pooled workspace server port&lt;BR /&gt;8591 # Enterprise Guide&lt;BR /&gt;8601, 8611, 8621, 8631 # stored process server port&lt;BR /&gt;5308 # idk what this one is used for, but installer did mention it&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;VA:&lt;/STRONG&gt;&lt;BR /&gt;8701 # pooled workspace server port&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;VA worker 1-3:&lt;/STRONG&gt;&lt;BR /&gt;Nothing SAS specific has been opened&lt;/P&gt;&lt;P&gt;At first I was concerned about ldap and odbc database connections, but then realized they would be covered under outgoing. So is there anything else that I may have missed or need to open. Or does this path forward appear to be good?&lt;/P&gt;</description>
      <pubDate>Wed, 13 Feb 2019 20:27:10 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/Multi-tier-Environemnt-Firewall-Port-Exceptions/m-p/535395#M15636</guid>
      <dc:creator>five</dc:creator>
      <dc:date>2019-02-13T20:27:10Z</dc:date>
    </item>
    <item>
      <title>Re: Multi-tier Environemnt Firewall Port Exceptions</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/Multi-tier-Environemnt-Firewall-Port-Exceptions/m-p/535436#M15638</link>
      <description>&lt;P&gt;ODBC connections are two-way. If by outbound you mean the server which initiates the connection then you should be OK. Where I work all ports need an explicit exception, both inbound and outbound, and in-flight traffic needs to be encrypted as well.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Enterprise Guide requires an 8561 metadata connection just like Management Console.&lt;/P&gt;</description>
      <pubDate>Wed, 13 Feb 2019 22:11:53 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/Multi-tier-Environemnt-Firewall-Port-Exceptions/m-p/535436#M15638</guid>
      <dc:creator>SASKiwi</dc:creator>
      <dc:date>2019-02-13T22:11:53Z</dc:date>
    </item>
  </channel>
</rss>

