Which ports are needed to run Vscan through a firewall?
Applies to
- ONTAP 9
- Vscan
Answer
- ONTAP 9 uses two separate protocols for the purpose of Vscan:
- HTTPS (TCP port 443) towards the management LIFs configured in the Antivirus Connector
- SMB2 (TCP ports 139 and 445) towards the data LIFs discovered by the Antivirus Connector
- In both cases, connections will be initiated by the external Vscan server
Additional Information
- The source IP address used by the Vscan server to contact any data LIF should be one defined in the related scanner-pool
- If a special network has been configured to separate Vscan traffic from user data traffic then is better to configure the firewall to allow the Vscan server to only reach the data LIFs designated for Vscan traffic
- The ONTAP firewall must allow access to HTTPS in order for the Antivirus Connector service to connect