Architecting a vRealize Log Insight Solution : vRealize Log Insight Security Design : 6.3 Port Map
   
6.3 Port Map
As part of a vRealize Log Insight design, include the specification of communications ports to be opened and the specific components of the architecture that will use them. Careful use of ports allows functioning across firewall boundaries, while also protecting the sensitive information gathered in the log messages from unsecure networks or unauthorized personnel. The best practice is to place the vRealize Log Insight appliances on a separated out-of-band management network segment protected by a firewall from the rest of the internal network. See Section 7, vRealize Log Insight Management Environment for more information on how to do that.
The following tables in this section list recommended communication port assignments. The exact port assignments might vary according to a specific service provider’s vRealize Log Insight system design.
The first table lists ports that need to be open to vRealize Log Insight from sources that send syslog message data to vRealize Log Insight.
Table 10. vRealize Log Insight Ports – Source Message Data
Source
Destination
Port
Protocol
Service Description
System sending logs
Log Insight appliance
514/UDP,
514/TCP
Syslog
Syslog data
System sending logs
Log Insight appliance
1514/TCP, 6514/TCP
Syslog-TLS (SSL)
Syslog data over SSL
System sending logs
Log Insight appliance
9000/TCP
vRealize Log Insight Ingestion API
vRealize Log Insight Ingestion API
System sending logs
Log Insight appliance
9543/TCP
vRealize Log Insight Ingestion API (SSL)
vRealize Log Insight Ingestion API - TLS (SSL)
 
 
The following ports need to be open to vRealize Log Insight to allow access to the user interface for administrators and operational teams.
Table 11. vRealize Log Insight Ports – User Access
Source
Destination
Port
Protocol
Service Description
User workstation
Log Insight appliance
80/TCP
HTTP
HTTP: Web interface
User workstation
Log Insight appliance
443/TCP
HTTPS
HTTPS: Web interface
Admin workstation
Log Insight appliance
22/TCP
SSH
SSH: Secure Shell connectivity
 
The following ports are only used for internal cluster communication between vRealize Log Insight master and worker nodes and they are only required to be open if a solution design does not allow for direct Layer 2 communication between the vRealize Log Insight cluster nodes. Normally a solution design would allow direct layer 2 communication between nodes, however this might not be the case, for example, if the vRealize Log Insight cluster nodes exist on separate network segments with a firewall restricting traffic between them. The restriction on Layer 2 communication might also exist if the design employs a distributed software-based firewall solution that restricts traffic between the cluster nodes.
Table 12. vRealize Log Insight Ports – Internal Communication
Source
Destination
Port
Protocol
Service Description
Worker Log Insight appliance
Master Log Insight appliance
16520-16580/TCP
Thrift RPC
Log Insight cluster services
Worker Log Insight appliance
Master Log Insight appliance
59778/TCP
log4j server
Log Insight cluster services
Worker Log Insight appliance
Master Log Insight appliance
12543/TCP
database server
Log Insight cluster services
 
 
Other vRealize Log Insight communication ports might be required, depending on other features employed in the infrastructure design.
Table 13. vRealize Log Insight Ports – Additional Communication Ports
Source
Destination
Port
Protocol
Service Description
User workstation
vRealize Log Insight appliance Tomcat service
9006-9007
TCP
Tomcat services
vAPI client applications
vRealize Log Insight appliance
9240
TCP
vRealize Log Insight vAPI service
vRealize Log Insight appliance
vRealize Log Insight appliance
111, 978
TCP, UDP
RPCbind service that converts RPC program numbers into universal addresses
vRealize Log Insight appliance
NTP server
123
UDP
NTPD: Provides NTP time synchronization
vRealize Log Insight appliance
Mail Server
25
TCP
SMTP mail service
vRealize Log Insight appliance
Mail Server
465
TCP
SMTPS: MTP mail service over SSL
vRealize Log Insight appliance
Mail Server
587
TCP
SMPT-MSA: mail submission agent
vRealize Log Insight appliance
DNS server
53
TCP, UDP
DNS
vRealize Log Insight appliance
AD server
389
TCP, UDP
Active Directory
vRealize Log Insight appliance
AD server
636
TCP
Active Directory over SSL
vRealize Log Insight appliance
AD server
3268
TCP
Active Directory global catalog
vRealize Log Insight appliance
AD server
3269
TCP
Active Directory global catalog SSL