Black Box EncrypTight Enforcement Point (ETEP) Firewall Ports, Installation Instructions ET0010A

Models: ET10000A ET0100A ET0010A ET1000A

1 88
Download 88 pages 24.35 Kb
Page 29
Image 29
Grounding

Grounding

Maintain reliable grounding of a rack-mounted ETEP. Pay particular attention to supply connections other than direct connections to the branch circuit, such as the use of power strips.

Maintenance

Allow at least 19 inches (48.3 cm) of clearance at the front of the rack for maintenance. Use a cable- management system to help keep cables organized, out of the way, and free from kinks or bends that degrade cable performance.

Firewall Ports

Table 13 lists the protocols that are used by the ETEPs and the EncrypTight Manager system. Make sure that any firewalls in your system are configured to allow for the protocols that are required for your deployment: standalone ETEPs used for point-to-point encryption or ETEPs used in the EncrypTight Manager system.

Table 13 Firewall ports

Protocol

Port

Description

Standalone

EncrypTigh

ETEPs

t Manager

FTP

TCP 20,

Used for upgrading the software on the

Yes

Yes

 

21

ETEP and retrieving appliance log files.

 

 

ICMP/Ping

 

Used to check connectivity with a device.

Yes

Yes

IKE /

UDP 500

Used to establish security associations in

Yes

 

ISAKMP

 

IKE policies.

 

 

IPSec ESP

IP

Used in encryption policies.

Yes

Yes

 

protocol

 

 

 

 

50

 

 

 

SFTP

TCP 22

Used for secure FTP operations.

Yes

Yes

SNMP

UDP

Used to send SNMP traps from the ETEPs

 

Yes

 

161, 162

to a management workstation.

 

 

SNTP

UDP 123

Used for time synchronization among

 

Yes

 

 

EncrypTight Manager components.

 

 

SSH

TCP 22

Used to securely access the CLI on ETEPs.

Yes

Yes

Syslog

UDP 514

Used to send syslog messages from the

 

Yes

 

 

ETEPs to a syslog server.

 

 

TLS

TCP 443

A secure method of communicating

 

Yes

(HTTPS)

 

management information between

 

 

 

 

EncrypTight Manager and the ETEPs.

 

 

XML-RPC

TCP 443

Used for communications between

 

Yes

 

 

EncrypTight Manager components.

 

 

 

 

 

 

 

Installation Instructions: ET0010A

The ET0010A can be mounted in a standard 19-inch rack using the mounting kit, or simply placed on a rack shelf or solid surface. Before installing the ETEP in a 19-inch rack, review the mounting guidelines listed in “ETEP Site Preparation” on page 28.

ETEP Installation Guide

29

Page 29
Image 29
Black Box EncrypTight Enforcement Point (ETEP) Firewall Ports, Installation Instructions ET0010A, Grounding, Maintenance