ProLiant Servers (ML,DL,SL)
1753905 Members
10460 Online
108810 Solutions
New Discussion юеВ

Re: Smart Update Manager (HP SUM) ports over firewall

 
SOLVED
Go to solution
David Liverpool
Occasional Advisor

Smart Update Manager (HP SUM) ports over firewall

I'd like to use SUM over a firewall. Which ports will I need to open? Are the ports SUM uses configurable? Thanks!
7 REPLIES 7
James ~ Happy Dude
Honored Contributor

Re: Smart Update Manager (HP SUM) ports over firewall

Hello David,

I don't think there is any special settings needed to use HP SUM;

Your Firewall should Allow port 80 in order to receive updates;

There is no Automated way to HP SUM; Once you log in using ur credentials, you need to Click on "Download updates" & then Select the "FILTER updates" (as per your choice); Once the updates are displayed, select the Appropriate updates !!

I am not aware if ports used by SUM can be configured/changed; Its the basic/default one;

Regards,
James.
KarloChacon
Honored Contributor

Re: Smart Update Manager (HP SUM) ports over firewall

hi

well yes according with Sujith James and with the HP SUM help - attached (maybe lack of information) there is nothing configurable (firewall - ports) to have HP SUM working like want

regards
Didn't your momma teach you to say thanks!
Michael Garner_1
Honored Contributor
Solution

Re: Smart Update Manager (HP SUM) ports over firewall

David,
When HPSUM initiates communications to remote targets, it uses several well-known ports depending on the OS. For Windows, it uses ports 138 and 445 to connect to remote targets (equivalent to net use functionality). For Linux, HPSUM uses port 22 (ssh) to start the communications with the remote target.

In addition, HPSUM uses random ports above 49152 to communicate between the remote target and the workstation where HPSUM is executing. When you run HPSUM, HPSUM uses the adminstrator/root privileges to dynamically register the port with the default Windows/Linux firewalls for the length of the application execution, then closes and deregisters the port. All communications are over a SOAP server using SSL with additional functionality to prevent man-in-the-middle, packet spoofing, packet replay and several other attack profiles. The randomness of the port is one of the methods we use to prevent port scanning software from denying service to our application. The SOAP server is landed on the remote target using the initial ports described above (ports 138, 445, and 22) and then allocates another independent port above 49152 for its communications back to the workstation where HPSUM is running. During shutdown of HPSUM, the SOAP server is shutdown and removed from the target server, leaving no trace it was there other than the log files in the %WINDOWS%\temp directory.

The firewall software integration is in all versions of HPSUM starting with v3.0.2 that shipped with the Firmware Maintenance CD v7.90. The HPSUM version shipped with the Windows PSPs 7.90 (version 3.0.1) will not work if a firewall is installed. The next version of the Windows PSPs will have this functionality.

We do not currently allow the port that HPSUM uses to be configured. If there are enough customers who want the ability to configure a defined port number, we could look into adding it in a future release.

Regards,
Michael Garner
HPSUM Architect
James ~ Happy Dude
Honored Contributor

Re: Smart Update Manager (HP SUM) ports over firewall

Koool Michael,

Where can a user get these informations ? Its obviously not mentioned in the user guides.

Thanks for the information.

Regards,
James.
Michael Garner_1
Honored Contributor

Re: Smart Update Manager (HP SUM) ports over firewall

Sujith,
I'll see if we can add this information to the user's guide the next time it gets updated.

We're moving so quickly to enhance the product that sometimes we overlook the obvious.

Regards,
Michael
David Liverpool
Occasional Advisor

Re: Smart Update Manager (HP SUM) ports over firewall

See Michael Garner's reply in this thread. He gives a verbose sequence of the ports used by HP SUM in Windows during its execution.
bconstant
Advisor

Re: Smart Update Manager (HP SUM) ports over firewall

For Linux, please also note that update workstation won't be able to connect to the remote host if passphrase authentication is active.