The Entrust PKI Hub operation requires verifying the following ports are open for traffic.
You don't need to manually open these ports in the firewall of the host machines. The following commands will automatically open them.
- The clusterctl install command, executed when Starting up PKI Hub.
- The clusterctl backup restore and clusterctl node add commands, executed when Administrating.
Ensure no network restriction blocks access to these ports.
Required ports for incoming traffic
In all the installation nodes, check that the following ports are accessible for incoming traffic to Entrust PKI Hub.
Target Port | Protocol | Source | Target service |
---|---|---|---|
22 | TCP/SSH | The IP of the sysadmin Entrust PKI Hub administrator. | SSH |
443 | TCP/HTTPS | The IP of the Grafana and Management Console users. | Grafana and the Management Console. |
Required ports for outcoming traffic
Some start-up operations require opening ports for outgoing traffic – for example:
- Selecting the DNS server, as later explained in Configuring the connection of a PKI Hub ISO installation.
- Configuring the NTP client, as later explained in Configuring time synchronization.
Verify these ports are accessible for outgoing traffic in all the installation nodes.
Required ports for internode communication
In multi-node installations, check that the following ports are accessible for internal services – such as monitoring node status or synchronizing data between nodes.
Port | Protocol | Source | Destination |
---|---|---|---|
179 | TCP | All nodes | All nodes |
2379 | TCP | All nodes | All nodes |
2380 | TCP | All nodes | All nodes |
2381 | TCP | All nodes | All nodes |
4789 | UDP | All nodes | All nodes |
5473 | TCP | All nodes | All nodes |
6443 | TCP | All nodes | All nodes |
8000 | TCP | All nodes | All nodes |
9100 | TCP | All nodes | All nodes |
10250 | TCP | localhost | localhost |
15014 | TCP | All nodes | All nodes |
15021 | TCP | All nodes | All nodes |
30000 | TCP | localhost | localhost |
51820 | UDP | All nodes | All nodes |
Solution-specific port requirements
See the following table for the additional open ports each Entrust solution requires.
Solution | Section |
---|---|
Certificate Authorities | |
CA Gateway | |
Certificate Enrollment Gateway | |
Timestamping Authority | |
Entrust Validation Authority |