186 IBM Tivoli Remote C ontrol Across Firewalls
TFST components and operations
In this section, we discuss the port requirements for the operations of Tivoli
Firewall Security Toolbox components in general and Endpoint Proxy and
Gateway Proxy in particular.
Each component of TFST (Endpoint Proxy, Gateway Proxy and Relay) will use
source and destination ports. TFST gives you the policies t o control this port
allocation. Note that TFST components can act as both client and server
depending on the direction the connection is initiating from. Connections are
established when the TMF components such as Gat eway or Endpoint initiates
the connection. Connection behavior is also governed by the TFST connection
policy. Both bidirectional and unidirectional modes are supported:
1. Source port: The source port is allocated on the client side of TCP/IP
connection by the operating system that is hosting the TFST component.
However, TFST does give a way to control the selection of this port range, so
that its possible to control which ports are used to connect from. The
port-range variable is the policy to control this.
2. Destination port: The destination port is the one the server listens on for
connections. This port number impacts firewall configuration because TFST
components must connect to the server through the firewall to talk to each
other. The destination port is controlled by allocating a single listening port
per Proxy component.

Port range configurations

This section describes the various parameters and configuration that govern the
port range usage of an Endpoint Proxy and Gateway Proxy:
򐂰The port-range parameter is the range of ports used by the application
(Gateway Proxy or Endpoint Proxy) to connect to their Tivoli counterparts i.e
Endpoint Proxy to Gateway and Gateway Proxy to Endpoint.
򐂰The local-port-range parameter is the range used by the application to
connect to their peers (Endpoint Proxy, Relay and Gateway Proxy)
򐂰The children-local-port parameter is the port on which Endpoint Proxy listens
for connections from Relay or Gateway Proxy (Relay uses this port parameter
to listen to its children Relay or Gateway Proxy).
򐂰The parent-local-port parameter is the port on which the Gateway Proxy
listens for connections from Endpoint Proxy or Relay. (Relay uses this port
parameter to listen from its parent Relay or Endpoint Proxy).