All Cryptographic Security Platform Vault IP addresses must use IPv4. Cryptographic Security Platform Vault does not support IPv6 addresses.

For Cryptographic Security Platform Vault to Cryptographic Security Platform Vault, Cryptographic Security Platform Vault to Cryptographic Security Platform Compliance Manager, and Policy Agent to Cryptographic Security Platform Vault, the following ports need to be open:

  • Internal protocol—The Cryptographic Security Platform Vault nodes must be able to communicate on TCP/443, TCP/8443, and TCP/5432. If you have a firewall between one or more nodes, make sure these ports are open.

  • Cryptographic Security Platform Compliance Manager—The Cryptographic Security Platform Vault nodes must be able to communicate  TCP/443 outbound to the Cryptographic Security Platform Compliance Manager.

  • Cryptographic Security Platform Vault webGUI—Inbound TCP/443 to administrator systems from any Cryptographic Security Platform Vault server in the cluster.
  • Cryptographic Security Platform Vault support-level access—Inbound TCP/22 from administrator systems to any Cryptographic Security Platform Vault server in the cluster.
  • Policy Agent to Cryptographic Security Platform Vault—Inbound TCP/443 from the Policy Agent to each of the Cryptographic Security Platform Vault nodes in the cluster.

For Cryptographic Security Platform Vault infrastructure services, the following ports need to be open:

  • DNS—Outbound UDP/53
  • SMTP—Outbound mail server, typically TCP/25. 

    If you disable SMTPS and the server supports StartTLS, it will use StartTLS when the connection is made. SMTPS is not compatible with StartTLS, and only one can be used.

  • SYSLOG—An outbound TCP/UDP port between 25 and 65535 if you want to use a remote syslog server. Cryptographic Security Platform Vault supports both TCP and UDP for syslog.

  • Backup and Restore via NFS—If you want to access the Cryptographic Security Platform Vault-generated backup files via NFS, you need to open the following ports: 2046 (lockd), 2047 (rpc statd), 2048 (rcp mountd), and 2049 (default NFS port).

    If you need to check the port status, you can run one of the following commands:  
    rcpinfo <KeyControl_Vault_IP_Address> or rcpinfo <KeyControl_Vault_Name>

  • NTP—Outbound NTP servers, typically UDP/123 or TCP/123 

    The network ports indicated for SMTP, syslog, and NTP are the typical ports for these services. If you need to change those ports, consult with the administrators of these services.

To configure Cryptographic Security Platform Vault as a KMIP server, open the port you plan to use. The default KMIP port is 5696.