This section explains how the Applications Manager can be accessed behind a firewall. Firewalls act as barriers that prevent unauthorized access to a network while allowing authorized users to access permitted resources. You need to configure the firewall so that the host on which Applications Manager runs can access the monitor at the relevant port.
Note: Ensure that all required ports are open to enable bi-directional communication.
| Monitors | Port Details |
|---|---|
| APPLICATION SERVERS | |
| Glassfish | Glassfish JMX port (Default port: 8686) |
| JBoss | Two-way communication between JBoss web server port (Default port: 8080) and Applications Manager web server port (Default port: 9090). Applications Manager hostname must be reachable from JBoss server. JBoss RMI object port (Default port: 4444). |
| Jetty | Enable JMX for monitoring. The JMX Port for default installations of Jetty is 9999. |
| Microsoft .NET | Windows Management Instrumentation (WMI) -- Port: 445 Remote Procedure Call (RPC) (Default port: 135) Learn more about the ports required for WMI Mode of monitoring. |
| Oracle Application Server | Oracle Application Server port (Default port: 7200) |
| Tomcat | Tomcat web server port (Default port: 8080) |
| VMware vFabric tc Server | JMX port for VMware vFabric tc Server (Default port: 6969) |
| WebLogic | Two-way communication between WebLogic listening port (Default port: 7001) and Applications Manager web server port (Default port: 9090) |
| WebSphere | WebSphere application port (Default port: 9080) |
| CLOUD APPS | |
| Microsoft Azure |
|
| Amazon | REST API via SDK HTTPS port (Default port: 443) |
| Microsoft 365 | REST API HTTPS port (Default port: 443) |
| Openstack | REST API HTTPS port (Default port: 443) |
| Google Cloud Platform | REST API HTTPS port (Default port: 443) |
| Oracle Cloud |
|
| CUSTOM MONITORS | |
| Database Query monitor | The corresponding database server port |
| File/Directory, Script (Telnet/SSH mode) | Telnet port: 23 (if the mode of monitoring is Telnet) SSH port: 22 (if the mode of monitoring is SSH) |
| File/Directory, WMI Performance counter (WMI mode) | Remote Procedure Call (RPC) (Default port: TCP 135) Windows Management Instrumentation (WMI) (Default port: TCP 445) Learn more about the ports required for WMI Mode of monitoring. |
| DATABASE SERVERS | |
| DB2 | The port on which DB2 is running (Default port: 50000) |
| Memcached | The port on which the Memcached server is running (Default port: 11211) |
| MySQL | The port on which MySQL is running (Default port: 3306) |
| Oracle | The port on which Oracle is running (Default port: 1521) |
| PostgreSQL | The port on which PostgreSQL is running (Default port: 5432) |
| Microsoft SQL Server | The port on which SQL Server is running (Default port: 1433). UDP port 1434 might be required for the SQL Server Browser Service when you are using named instances. |
| Sybase | The port on which Sybase is running (Default port: 5000) |
| SAP HANA | SAP HANA's IndexServer port (Default port: 30015) |
| Apache HBase | The port on which HBase is running. For default installations of HBase, the JMX port number is 10101 for Master and 10102 for RegionServer. |
| NoSQL | |
| Cassandra | Enable JMX for monitoring. The JMX Port for default installations of Cassandra is 7199. |
| ERP | |
| Oracle EBS | Oracle EBS web server port (Default port: 7200) |
| Microsoft Dynamics CRM/365 (On-Premise) | To monitor a Microsoft Dynamics CRM/365 application, use an Administrator user account that has permission to execute WMI queries on the 'root\CIMV2' namespace of the Dynamics CRM/365 Server. Firewall access for monitoring: Ports required for monitoring via WMI.
PowerShell access for monitoring: Click here to see powerShell prerequisites. |
| Microsoft Dynamics AX | Windows Management Instrumentation (WMI) -- Port: 445 Remote Procedure Call (RPC) -- Port: 135 Refer to the ports required for WMI Mode of monitoring under Servers |
| MAIL SERVERS | |
| Exchange Server | Windows Management Instrumentation (WMI) (Default port: 445) Remote Procedure Call (RPC) (Default port: 135) PowerShell remoting - TCP 5985 and 5986 Exchange PowerShell session - TCP 80 and 443 Learn more about the ports required for WMI Mode of monitoring |
| Mail Server | SMTP server port (Default port:25) to send mails from Applications Manager. POP port (Default port: 10 ) to fetch mails using the POP server. |
| MIDDLEWARE/PORTAL | |
| IBM WebSphere MQ | The MQ Listener Port (Default port:1414) |
| Microsoft MSMQ/SharePoint Server/Biztalk Server | Windows Management Instrumentation (WMI) -- Port: 445 Remote Procedure Call (RPC) -- Port: 135 PowerShell remoting - TCP 5985 and 5986 Learn more about the ports required for WMI Mode of monitoring. |
| VMware vFabric RabbitMQ Server | The port on which the management plugin is configured (Default port: 55672) |
| WebLogic Integration Server | WebLogic Integration port (Default port: 7001) |
| Oracle Tuxedo | The SNMP port number on which the Tuxedo SNMP agent is running. The Default port number is 161. |
| Apache ActiveMQ | Remote JMX should be enabled. The Default JMX port is 1099. |
| Apache Kafka | The Default JMX port is 9999. To enable JMX, you can set the JMX_PORT environment variable in the kafka-run-class.sh/kafka-run-class.bat file or use standard Java system properties. Alternatively, you can set the KAFKA_JMX_OPTS environment variable in the kafka-run-class.sh/kafka-run-class.bat file to enable JMX for monitoring in Applications Manager. For more information on configuring JMX, refer to this link. |
| Skype for Business Server | Windows Management Instrumentation (WMI) -- Port: 445 Remote Procedure Call (RPC) -- Port: 135 Refer to the ports required for WMI Mode of monitoring under Servers |
| SERVERS | |
| AS400/iSeries | To connect to an AS400/iSeries server from Applications Manager, it uses the JTOpen package. The JTOpen package uses the following Non-SSL ports: 449, 446, 8470, 8471, 8472, 8473, 8474, 8475, 8476. Ensure that the ports mentioned under the "Port Non-SSL" column in the link are not blocked in the firewall. |
| Linux / Solaris / AIX / HPUnix /Tru64 Unix | Telnet Port (Default port: 23), if the mode of monitoring is Telnet. SSH Port (Default port: 22), if the mode of monitoring is SSH SNMP Agent Port (Default port: 161), if the mode of monitoring is SNMP |
| Windows Cluster | Windows Management Instrumentation (WMI) -- Port: 445 Remote Procedure Call (RPC) -- Port: 135 Refer to the ports required for WMI Mode of monitoring under Servers |
| Windows | Applications Manager supports users with both administrator and non-administrator roles for monitoring Windows servers through WMI mode. However, it is recommended to use administrator privileges for Windows server monitoring. Ports required - Remote Procedure Call (RPC) (Default port: 135) WMI uses DCOM for remote communication. The server to be monitored by Applications Manager uses a random port number above 1024 by Default to respond. You have to connect to this target server and configure it to use a port within a specified range of ports. Check out this link to learn more about restricting the ports in the target server: https://support.microsoft.com/en-us/help/154596/how-to-configure-rpc-dynamic-port-allocation-to-work-with-firewalls. Note that you must specify at least 5 ports in this range for target server ( you are normally recommended to open at least a 100 ports). This same range of ports must also be opened in the firewall.
Ports required for SNMP Mode of monitoring - SNMP Agent (Default port: 161) |
| SERVICES | |
| Active Directory | Windows Management Instrumentation (WMI) -- Port: 445 Remote Procedure Call (RPC) -- Port: 135 PowerShell remoting -- TCP 5985 and 5986 Refer to the ports required for WMI Mode of monitoring under Servers |
| FTP/SFTP | Port on which FTP or SFTP is running (Default port:21 for FTP, 22 for SFTP) |
| JMX [ MX4J / JDK 1.5] | Port of JMX agent (Default port:1099) To monitor JMX behind a firewall, the following changes have to be made.
|
| LDAP | LDAP server port |
| Network Policy Server (NPS) | Windows Management Instrumentation (WMI) -- Port: 445 Remote Procedure Call (RPC) -- Port: 135 Refer to the ports required for WMI Mode of monitoring under Servers |
| Service Monitoring | The service port that you need to monitor |
| SNMP | SNMP Agent port (Default port:161) |
| Telnet | Port that you need to Telnet |
| Apache ZooKeeper | The Default port of the JMX agent is 1099 To enable Remote JMX for ZooKeeper in Linux Environments, open the zkServer.sh file under the bin folder and check the following:
In Windows Environments, do the following changes in zkServer.bat file under bin folder:
Replace < PORT NO> with JMXPORT and < IP address> with the IP address of the machine. |
| Oracle Coherence | Enable JMX for monitoring. The JMX Port for Default installations of Coherence is 1099. |
| Hadoop | Enable JMX for monitoring. The JMX port for the NameNode. |
| APPLICATION PERFORMANCE MANAGEMENT | |
| APM Insight | One-way communication from the Agent installed application server to the Applications Manager port (Default port: 9090/8443). |
| VIRTUALIZATION | |
| Hyper-V | Windows Management Instrumentation (WMI) -- Port: 445 Remote Procedure Call (RPC) -- Port: 135 Refer to the ports required for WMI Mode of monitoring under Servers |
| VMWare ESX/ESXi | VMWare Web Service port (Default port:443) |
| Citrix Xenserver | The https Port where the XenServer web service runs. The Default port is 443. |
| Docker | The Docker socket port. (Default port: 4243). |
| Kubernetes | SSH Port (Default port: 22). |
| OpenShift | SSH Port (Default port: 22) REST API Port (Default port: 8443) |
| WEB SERVER/SERVICES | |
| SSL Certificate Monitor | SSL port on which the web server is running (Default port: 443). |
| Web Server | HTTP Port of Web Server. (Default port is 80. For SSL, it is 443) |
| Elasticsearch | The port on which Elasticsearch is running (Default port: 9200). |
| Apache Solr | The port on which Apache Solr is running (Default port: 8983) |
| IIS Server | Port on which the IIS Server is running. (Default port is 80. For SSL, it is 443.) |
| Miscellaneous | |
| Trap Listeners | Trap Listener port (Default port:1620) in the Applications Manager server must be reachable from the server where you want to send traps. More on receiving SNMP Traps. |
| RUM Agent |
Note:
|
| EUM Agent |
|
Applications Manager makes sure that data is secure. The internal PostgreSQL database allows only localhost to access the database through authenticated users. User Names and Passwords are stored in the PostgreSQL database that is bundled along with the product. The passwords are encrypted to maintain security.
| Monitors | Privileges |
|---|---|
| Active Directory | Administrator username/password [WMI mode] |
| Amazon |
|
| Apache Server | Credentials for accessing the server status URL for Apache |
| AS400/iSeries |
|
| Database Query Monitor | User with privileges for accessing a particular database and executing the query |
| DB2 | User with at least SYSMON instance-level authority |
| Exchange Server | Administrator username/password [WMI mode] |
| File/Directory | User with privileges for accessing the File or Directory to monitor |
| FTP/SFTP | If Authentication is enabled, enter the Username and Password for connecting to the FTP/SFTP server & move to the required directory |
| Glassfish | Username and password for connecting to Glassfish Admin console |
| HP-UX | Guest user privilege |
| HTTP URL | If basic authentication is required, enter the same in Monitor. |
| Hyper-V | Administrator privileges to the root OS (Windows 2008 R2 and other supported Hyper-V versions) |
| IBM AIX | Guest user privileges are sufficient, but "root" privileges are required for collecting memory-related details. Hence, it is preferable to use a "root" account to view all the details |
| IBM WebSphere MQ | A Channel name with the type of "Server Connection Channel" |
| JBoss | Use the JBoss username/password (if JBoss is authenticated). User should be able to access the JBoss JMX console. If not, no username/password is required |
| JMX/Java Runtime | If Authentication is enabled, enter the Username and password for connecting to the JMX agent. To monitor a JMX application, the following Java runtime options are to be added to your application
Replace < PORT NO> with the JMX Port for the machine. |
| LDAP | If Authentication is enabled, enter the Username and Password. If no username and password are provided, then it will connect to the LDAP server as an anonymous login. |
| Linux | Guest user privilege |
| Mail Server | If Authentication is enabled, enter the Username and password for connecting to the SMTP and POP |
| Microsoft .Net | Administrator username/password [WMI mode] |
| Microsoft Office SharePoint Server | Administrator username/password [WMI mode] |
| MS SQL | System Administrator/Owner for the "master" database |
| MSMQ | Administrator username/password [WMI mode] |
| MySQL | The username specified should have access to the databases to be monitored. MySQL should also be configured. This allows the host on which App Manager is running to access the MySQL database. |
| Oracle EBS | Users with CONNECT, SELECT_CATALOG_ROLE, and SELECT ANY TABLE roles. |
| RabbitMQ | The User must have an administrator tag (that has privileges to list all the objects under every Virtual host) to monitor a RabbitMQ server. |
| SAP/SAP CCMS | You need an SAP user profile with the following authorization objects: S_RFC, S_XMI_LOG and S_XMI_PROD, which are the minimum prerequisites for adding an SAP monitor. We use the SAP Java Connector to connect to the SAP ABAP server. The SAP JCo will communicate from APM to SAP using the SAP Dispatcher. The SAP Dispatcher port to be used is 3200 with the SAP System number. |
| Script monitor | User with privileges for executing the script and accessing the output file. |
| Server with SNMP mode | SNMP Community string with read privileges. |
| SNMP/Network device | For SNMP Version V1/V2c:
For SNMP Version V3: Select one of the three Security Levels in the drop-down list:
|
| Solaris | Guest user privilege. |
| Sybase | The user should have admin privileges or be the DB owner for the master database. |
| Tomcat |
|
| VMWare ESX/ESXi | When adding VMware ESX/ESXi servers for monitoring, we recommend using the root account. However, if you are unable to use the root account, you can use a 'view-only' profile to add the servers. This profile has all the privileges required for monitoring. The user you create must be:
|
| VMware vFabric RabbitMQ Server | User Name and Password of RabbitMQ server. |
| WebLogic | Use the WebLogic username/password if WebLogic is authenticated. The user should be an administrator. Otherwise, no username/password is required. |
| WebLogic Integration Server | Use the WebLogic username/password if WebLogic is authenticated. User should be an administrator. Otherwise, no username/password is required. |
| Webservices | Provide the User Name and Password if required to invoke the web service operation. |
| WebSphere | If Global Security is enabled, use the same username/password. If not, no username/password is required. |
| Windows | Administrator username/password [WMI mode]. |
| Windows Cluster | Administrator username/password [WMI mode]. |
| Path | Ports |
|---|---|
| Central Server to Probe Server | SSL Port (Default port: 8443) for data syncing. Web server (Default port: 9090). |
| Probe Server to Central Server | SSL Port (Default port: 8443) for data syncing. |
Note: Production Environment gives you the configuration details that you need to take care of when moving Applications Manager into Production.
It allows us to track crucial metrics such as response times, resource utilization, error rates, and transaction performance. The real-time monitoring alerts promptly notify us of any issues or anomalies, enabling us to take immediate action.
Reviewer Role: Research and Development