All SAS server tiers (Metadata, Compute, Middle Tier) will be on one box, with no separate nodes. SAS provided pre-install checklist has nearly 100 port exceptions "required". However, Network Security Team does not see justification for client access to all ports. They are questioning since everything will be on one box, all ports would be internally available to SAS Server. Therefore, only a handful of ports need client initiated access. I tend to agree, but I've never deployed an all-on-one box. In my experience, whenever you deviate it gets tricky. Especially if SAS expects certain ports open to work. Based on this, I'm thinking the only ports that require client access would be: 7980 SAS Web Server HTTP Port 8343 SAS Web Server HTTPS Port 8561 SAS Metadata Server 7080 SAS Environment Manager Dashboard Port (HTTP) 7443 SAS Environment Manager Dashboard Secure Port (HTTPS) The rest are only needed internal to SAS Server and would be available to SAS since a single box. Therefore no need for firewall exceptions for clients. I want to make sure I'm not missing anything or anyone with scenario could shed light? Thanks!
... View more