BookmarkSubscribeRSS Feed
pbad
Obsidian | Level 7

Dear all,

 

 We have a requirement where we have to transfer our SAS servers to Enclave Network model. At the moment our servers are on Legacy system.

 

I understand that SAS has got predefined ports for SAS components. However following link says that for 'TCP port for middle-tier cache communications', the default port varies from 0 to 65535 and for the 'Cache Locator membership port range' needs 1024–65535 ports. 

 

So I was wondering whether Network team needs to open such a huge number of ports for the new system ? or it is ok if only few ports are defined. Should I understand that Network team has to open so many firewall rules ?

 

http://support.sas.com/documentation/cdl/en/biig/62611/HTML/default/viewer.htm#n02027intelplatform00...

 

This is for sure that different client are going to connect to SAS servers. Does it make a difference if Servers are on Legacy or Enclave system ?

 

I will appreciate to discuss on this topic.

 

Thanks

Pratik

4 REPLIES 4
Kurt_Bremser
Super User

Do you have a multi-tiered server setup, or is everything SAS on one server? This will strongly influence the ports open to the outside.

Ports that need to be open for client access in any case are

  • Metadata Server
  • Object Spawner
  • Workspace Server(s)
  • Pooled Workspace Servers
  • OLAP Servers
  • Stored Process Servers
  • HTTP/HTTPS (7980/8343, if defaults are used)
pbad
Obsidian | Level 7

Dear Kurt,

 

Thank you for your reply. It is not the multi-tiered server setup. Everything is lying on single SAS server.

 

Pratik

JuanS_OCS
Amethyst | Level 16

Hello @pbad,

 

for the Cache Locator, I would like to recommend you to read "Administering Cache Locator - Modifying the Configuration to Accommodate a Firewall" https://documentation.sas.com/?docsetId=bimtag&docsetTarget=n1dvn134xe84k0n1j14o0k534kv5.htm&docsetV...

 

For the rest of the services, most of the services mention a range from 0 to 9, which is for accomodating up to 10 SAS levels. But if you are deploying just 1 level, you can restrict the number quite a lot. Pay attention to the list, and the list provided by your SAS installer consultat (checklist.pdf) and you should be able to accomodate firewall to specific port numbers.

 

Hope it helps,


Kind regards,

Juan

suga badge.PNGThe SAS Users Group for Administrators (SUGA) is open to all SAS administrators and architects who install, update, manage or maintain a SAS deployment. 

Join SUGA 

Get Started with SAS Information Catalog in SAS Viya

SAS technical trainer Erin Winters shows you how to explore assets, create new data discovery agents, schedule data discovery agents, and much more.

Find more tutorials on the SAS Users YouTube channel.

Discussion stats
  • 4 replies
  • 942 views
  • 1 like
  • 3 in conversation