Cisco NAC3350-PROF-K9 Hardware Installation Guide - Page 105

Device, Communicating, Ports to Open, Purpose

Page 105 highlights

Chapter 3 Installing the Clean Access Manager and Clean Access Server Cisco NAC Appliance Connectivity Across a Firewall Table 3-2 Port Usage Device Communicating Devices Firewall, if any CAM and CAS CAS and Agent Ports to Open Purpose TCP 8995, 8996 TCP 1099 Java Management Extensions (JMX) communication between the CAM and CAS, such as pre-connect and connect messages. TCP 443 HTTP over Secure Sockets Layer (SSL) communication between Agent/CAS/CAM, such as end user machine remediation via the Agent. TCP 80 (for version HTTP communication between Agent/CAS/CAM. Used to 3.6.x and earlier) download the Agent from the CAM to an end user machine. UDP 8905, 8906 SWISS, a proprietary CAS-Agent communication protocol used by the Agent for UDP discovery of the CAS. UDP 8905 is used for Layer 2 discovery; and 8906 is used for Layer 3 discovery. TCP 443 For more information, see the "Connecting to the CAS Using the SWISS Protocol" section in the Cisco NAC Appliance - Clean Access Server Configuration Guide, Release 4.8(3). HTTP over SSL communication between Agent/CAS/CAM, such as for user redirection to a web login page. TCP 80 (for version HTTP communication between Agent/CAS/CAM. Used to 3.6.x and earlier) download the Agent from the CAM to an end user machine. OL-20326-01 Cisco NAC Appliance Hardware Installation Guide 3-35

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176

3-35
Cisco NAC Appliance Hardware Installation Guide
OL-20326-01
Chapter 3
Installing the Clean Access Manager and Clean Access Server
Cisco NAC Appliance Connectivity Across a Firewall
Table 3-2
Port Usage
Device
Communicating
Devices
Ports to Open
Purpose
Firewall, if any
CAM and CAS
TCP 8995, 8996
TCP 1099
Java Management Extensions (JMX) communication between the
CAM and CAS, such as pre-connect and connect messages.
TCP 443
HTTP over Secure Sockets Layer (SSL) communication between
Agent/CAS/CAM, such as end user machine remediation via the
Agent.
TCP 80 (for version
3.6.x and earlier)
HTTP communication between Agent/CAS/CAM. Used to
download the Agent from the CAM to an end user machine.
CAS and Agent
UDP 8905, 8906
SWISS, a proprietary CAS-Agent communication protocol used
by the Agent for UDP discovery of the CAS. UDP 8905 is used for
Layer 2 discovery; and 8906 is used for Layer 3 discovery.
For more information, see the “Connecting to the CAS Using the
SWISS Protocol” section in the
Cisco NAC Appliance - Clean
Access Server Configuration Guide, Release 4.8(3)
.
TCP 443
HTTP over SSL communication between Agent/CAS/CAM, such
as for user redirection to a web login page.
TCP 80 (for version
3.6.x and earlier)
HTTP communication between Agent/CAS/CAM. Used to
download the Agent from the CAM to an end user machine.