メインコンテンツまでスキップ

Which ports are needed to run vscan though a firewall?

Views:
9
Visibility:
Public
Votes:
0
Category:
ontap-9
Specialty:
nas
Last Updated:

Applies to

  • ONTAP 9
  • Clustered data ONTAP 8
  • vscan

Answer

Clustered data ONTAP uses two separate protocols for the purpose of antivirus scanning, in both cases connections will be initiated by the external antivirus server.

  • HTTPS (TCP port 443) towards the management lifs configured in the antivirus connector
  • SMB2 (TCP ports 139 and 445) towards the data lifs discovered by the connector

Additional Information

  • The source IP address used by the antivirus to contact any data lif should be one of those defined in the related scanner-pool
  • If a special network has been configured to separate vscan traffic from user data traffic then is better to configure the firewall to allow the antivirus server to only reach the data lifs designated for vscan traffic