Overview
This article describes outbound firewall ports and public NAT mappings required by x360Recover.
Note: Best practice calls for a hardware firewall between the internet and any device that requires inbound connections. Axcient vaults and portals should always be behind a hardware firewall, with inbound connections limited to the necessary ports listed below.
- We recommend enabling lockdown mode from x360Recover Manager for all devices to improve security and enable multi-factor authentication
- No inbound ports from the internet need to be opened at a customer location for appliances.
- Appliances connect to the cloud and establish secure tunnel services for remote access via Management Portal (Legacy) or x360Recover Manager.
For details on securing inbound communications, refer to this article.
[Full list: All supported hardware configurations and solutions for x360Recover]
Requirements for firewall ports (outbound): |
Direct-to-Cloud (D2C) agent requirements
The x360Recover Direct-to-Cloud (D2C) agent requires the following firewall ports to be open for outbound communications on the internet:
TCP 80 (http) |
TCP 443 (https) |
TCP 9079 (Endpoint Manager) |
TCP 9082 (Cloudserver) |
TCP 9083 (Disaster Recovery Access Layer - DRAL ) |
TCP 9090 (Backup Manager) |
TCP 9084 (Rsync) |
TCP/UDP 10000 - 11024 (FTPS PASV - for FTP recovery from vault) |
Note: the list of IP addresses within our datacenter to which the agent must communicate is dynamic and subject to change
Recovery Center requirements
x360Recover Recovery Center requires the following ports to be open:
- TCP/443 (https) to the vault (or appliance) holding the data to be recovered
- TCP/443 (https) to api.axcient.net
- TCP/443 (https) to api.axcient.com
- TCP/9083 (Disaster Recovery Access Layer [DRAL]) to the Axcient Scale-Out Cloud storage node
- Please refer to Axcient Cloud IP addresses and application port ranges
Common requirements for appliances and vaults
All x360Recover devices must be able to communicate with the following destinations and ports:
Distributed Tunnel Service
|
|
Cloud Key Management Services
|
|
Telemetry Services The x360Recover telemetry service utilizes a highly-dispersed cloud data provider with a large list of volatile IP addresses. A list of the current IP addresses in use can be found here |
|
Update Manager
|
|
Update Repository
|
|
Ubuntu Package Mirror
|
Appliance requirements
The x360Recover appliance is typically deployed on the same LAN as the protected systems it is servicing. This means NO inbound firewall rules are generally required. (The appliance has its own internal firewall restricting inbound traffic at the device level.)
For details on in-bound ports, please refer to Firewall ports (inbound)
However, if you have deployed a firewall between your protected systems and your appliance, the following ports need to be accessible:
Outbound traffic In addition to the common requirements for appliances and vaults detailed at the top of this article , the x360Recover appliance requires the following ports and destinations to be accessible: Management Portal Appliances must be able to communicate with the management portal on the following ports:
Vault Appliances must be able to communicate with all Vaults configured for Replication
Scale-Out Cloud Appliances must be able to communicate with all available Scale-Out Cloud storage nodes within the configured data center. The URLs and IP addresses of the Scale-Out Cloud are dynamic and subject to change as nodes are added over time. IP addresses will always be within the range described at Axcient Cloud IP addresses and application port ranges
|
Vault requirements
Most partners use Axcient-hosted cloud vaults, in which case all network security is fully managed by the Axcient cloud engineering team.
However, if you are self-hosting some or all of your vaults, refer to the following when configuring your firewall rules:
Outbound traffic In addition to the common requirements list at the top of this article, the vault requires the following ports and destinations to be accessible: Management Portal Vaults must be able to communicate with the Management Portal on the following ports:
For details on in-bound ports, please refer to Firewall ports (inbound) |
Additional requirements
Management Portal requirements
Most partners use an Axcient-hosted management portal, in which case all network security is fully managed by the Axcient cloud engineering team.
If you are self-hosting your management portal, please refer to the following when configuring your firewall rules:
Outbound traffic The Management Portal makes no unique outbound connections. (Please take note of the common requirements of all devices described at the beginning of this article.) For details on in-bound ports, please refer to Firewall ports (inbound) |
SUPPORT | 720-204-4500 | 800-352-0248
- To learn more about any of our Axcient products, sign up for free one-on-one training.
- Please contact your Partner Success Manager or Support if you have specific technical questions.
- Subscribe to the Axcient Status page for a list of status updates and scheduled maintenance.
750 | 1237 | 1295