Schedule demo

Security/Firewall Requirements


This section explains how the Applications Manager can be accessed behind a firewall. Firewalls act as barriers that prevent unauthorized access to a network while allowing authorized users to access permitted resources. You need to configure the firewall so that the host on which Applications Manager runs can access the monitor at the relevant port.

Note: Ensure that all required ports are open to enable bi-directional communication.

Ports to be opened when Monitors are behind the firewall:

MonitorsPort Details
APPLICATION SERVERS
GlassfishGlassfish JMX port (Default port: 8686)
JBossTwo-way communication between JBoss web server port (Default port: 8080) and Applications Manager web server port (Default port: 9090).
Applications Manager hostname must be reachable from JBoss server.
JBoss RMI object port (Default port: 4444).
JettyEnable JMX for monitoring. The JMX Port  for default installations of Jetty is 9999.
Microsoft .NET

Windows Management Instrumentation (WMI) -- Port: 445

Remote Procedure Call (RPC) (Default port: 135)

Learn more about the  ports required for WMI Mode of monitoring.

Oracle Application ServerOracle Application Server port (Default port: 7200)
TomcatTomcat web server port (Default port: 8080)
VMware vFabric tc ServerJMX port for VMware vFabric tc Server (Default port: 6969)
WebLogicTwo-way communication between WebLogic listening port (Default port: 7001) and Applications Manager web server port (Default port: 9090)
WebSphereWebSphere application port (Default port: 9080)
CLOUD APPS
Microsoft Azure
  • REST API HTTPS port (Default port: 443)
  • For Azure VM: PowerShell port (Default port: 5985,5986)
  • For Azure SQL: DB connection via JDBC port (Default port: 1433)
AmazonREST API via SDK HTTPS port (Default port: 443)
Microsoft 365REST API HTTPS port (Default port: 443)
OpenstackREST API HTTPS port (Default port: 443)
Google Cloud PlatformREST API HTTPS port (Default port: 443)
Oracle Cloud
  • REST API HTTPS port (Default port: 443)
  • For Autonomous Database: DB connection via JDBC port (Default port: 1433)
CUSTOM MONITORS
Database Query monitorThe corresponding database server port
File/Directory, Script (Telnet/SSH mode)

Telnet port: 23 (if the mode of monitoring is Telnet)

SSH port: 22 (if the mode of monitoring is SSH)

File/Directory, WMI Performance counter (WMI mode)

Remote Procedure Call (RPC) (Default port: TCP 135)

Windows Management Instrumentation (WMI) (Default port: TCP 445)

Learn more about the  ports required for WMI Mode of monitoring.

DATABASE SERVERS
DB2The port on which DB2 is running (Default port: 50000)
MemcachedThe port on which the Memcached server is running (Default port: 11211)
MySQLThe port on which MySQL is running (Default port: 3306)
OracleThe port on which Oracle is running (Default port: 1521)
PostgreSQLThe port on which PostgreSQL is running (Default port: 5432)
Microsoft SQL ServerThe port on which SQL Server is running (Default port: 1433). UDP port 1434 might be required for the SQL Server Browser Service when you are using named instances.
SybaseThe port on which Sybase is running (Default port: 5000)
SAP HANASAP HANA's IndexServer port (Default port: 30015)
Apache HBaseThe port on which HBase is running. 
For default installations of HBase, the JMX port number is 10101 for Master and 10102 for RegionServer.
NoSQL
CassandraEnable JMX for monitoring. The JMX Port for default installations of Cassandra is 7199.
ERP
Oracle EBSOracle EBS web server port (Default port: 7200)
Microsoft Dynamics CRM/365 (On-Premise)

To monitor a Microsoft Dynamics CRM/365 application, use an Administrator user account that has permission to execute WMI queries on the 'root\CIMV2' namespace of the Dynamics CRM/365 Server.

Firewall access for monitoring:

Ports required for monitoring via WMI.

  • Windows Management Instrumentation (WMI) (Default port: TCP 445)
  • Remote Procedure Call (RPC) (Default port: TCP 135)
  • Refer to the ports required for WMI Mode of monitoring under Servers

PowerShell access for monitoring:

Click here to see powerShell prerequisites.

Microsoft Dynamics AX

Windows Management Instrumentation (WMI) -- Port: 445

Remote Procedure Call (RPC) -- Port: 135

Refer to the ports required for WMI Mode of monitoring under Servers

MAIL SERVERS
Exchange Server

Windows Management Instrumentation (WMI) (Default port: 445)

Remote Procedure Call (RPC) (Default port: 135)

PowerShell remoting - TCP 5985 and 5986

Exchange PowerShell session - TCP 80 and 443

Learn more about the ports required for WMI Mode of monitoring

Mail ServerSMTP server port (Default port:25) to send mails from Applications Manager.
POP port (Default port: 10 ) to fetch mails using the POP server.
MIDDLEWARE/PORTAL
IBM WebSphere MQThe MQ Listener Port (Default port:1414)
Microsoft MSMQ/SharePoint Server/Biztalk Server

Windows Management Instrumentation (WMI) -- Port: 445

Remote Procedure Call (RPC) -- Port: 135

PowerShell remoting - TCP 5985 and 5986

Learn more about the ports required for WMI Mode of monitoring.

VMware vFabric RabbitMQ ServerThe port on which the management plugin is configured (Default port: 55672)
WebLogic Integration ServerWebLogic Integration port (Default port: 7001)
Oracle TuxedoThe SNMP port number on which the Tuxedo SNMP agent is running. The Default port number is 161.
Apache ActiveMQ

Remote JMX should be enabled. The Default JMX port is 1099.

Learn how to enable JMX for ActiveMQ

Apache Kafka

The Default JMX port is 9999.

To enable JMX, you can set the JMX_PORT environment variable in the kafka-run-class.sh/kafka-run-class.bat file or use standard Java system properties. Alternatively, you can set the KAFKA_JMX_OPTS environment variable in the kafka-run-class.sh/kafka-run-class.bat file to enable JMX for monitoring in Applications Manager. For more information on configuring JMX, refer to this link.
Skype for Business Server

Windows Management Instrumentation (WMI) -- Port: 445

Remote Procedure Call (RPC) -- Port: 135

Refer to the ports required for WMI Mode of monitoring under Servers

SERVERS
AS400/iSeries

To connect to an AS400/iSeries server from Applications Manager, it uses the JTOpen package. The JTOpen package uses the following Non-SSL ports: 449, 446, 8470, 8471, 8472, 8473, 8474, 8475, 8476. Ensure that the ports mentioned under the "Port Non-SSL" column in the link are not blocked in the firewall.

https://www-01.ibm.com/support/docview.wss?uid=nas8N1019667

Linux / Solaris / AIX / HPUnix /Tru64 Unix

Telnet Port (Default port: 23), if the mode of monitoring is Telnet.

SSH Port (Default port: 22), if the mode of monitoring is SSH

SNMP Agent Port (Default port: 161), if the mode of monitoring is SNMP

Windows Cluster

Windows Management Instrumentation (WMI) -- Port: 445

Remote Procedure Call (RPC) -- Port: 135

Refer to the ports required for WMI Mode of monitoring under Servers

Windows

For WMI Mode of Monitoring:

Applications Manager supports users with both administrator and non-administrator roles for monitoring Windows servers through WMI mode. However, it is recommended to use administrator privileges for Windows server monitoring.

Ports required -

Remote Procedure Call (RPC) (Default port: 135)

WMI uses DCOM for remote communication. The server to be monitored by Applications Manager uses a random port number above 1024 by Default to respond. You have to connect to this target server and configure it to use a port within a specified range of ports. Check out this link to learn more about restricting the ports in the target server:  https://support.microsoft.com/en-us/help/154596/how-to-configure-rpc-dynamic-port-allocation-to-work-with-firewalls. Note that you must specify at least 5 ports in this range for target server ( you are normally recommended to open at least a 100 ports). This same range of ports must also be opened in the firewall.

  • For Windows Server 2008 and later versions (Windows Server 2019, Windows Server 2016, Windows Server 2012, Windows Server 2008 R2, Windows Server 2008), and in Windows Vista and later versions (Windows 10, Windows 8, Windows 7, Windows Vista), use the following dynamic port range:

    Start port: 49152

    End port: 65535

  • For versions of Windows Server below 2008 (Windows 2000, Windows XP, and Windows Server 2003, and in Windows below Vista (Windows XP), use the following dynamic port range:

    Start port: 1025

    End port: 5000

  • If your computer network environment uses Windows Server 2019, Windows Server 2016, Windows Server 2012, Windows Server 2008 R2, Windows Server 2008, Windows 8, Windows 7, Windows Vista together with versions of Windows below Windows Server 2008 and Windows Vista, you must enable connectivity over both the following port ranges:

    High port range: 49152 through 65535

    Low port range: 1025 through 5000

  • For more information about the Default dynamic port range, click here.

Ports required for SNMP Mode of monitoring -

SNMP Agent (Default port: 161)

SERVICES
Active Directory

Windows Management Instrumentation (WMI) -- Port: 445

Remote Procedure Call (RPC) -- Port: 135

PowerShell remoting -- TCP 5985 and 5986

Refer to the ports required for WMI Mode of monitoring under Servers

FTP/SFTPPort on which FTP or SFTP is running (Default port:21 for FTP, 22 for SFTP)
JMX [ MX4J / JDK 1.5]

Port of JMX agent (Default port:1099)
 

To monitor JMX behind a firewall, the following changes have to be made.

  • Edit startApplicationsManager.bat/sh file. Add
    -Dmonitor.jmx.rmi.port=<port number for RMI socket communication> to the Java runtime options.
  • Restart Applications Manager server
  • Ensure that you have the RMI Socket port (step1) and JNDI Port (step4) opened up in the firewall
  • Add the JMX Applications monitor after providing the relevant details.
  • The monitor should be added successfully
LDAPLDAP server port
Network Policy Server (NPS)

Windows Management Instrumentation (WMI) -- Port: 445

Remote Procedure Call (RPC) -- Port: 135

Refer to the ports required for WMI Mode of monitoring under Servers

Service MonitoringThe service port that you need to monitor
SNMPSNMP Agent port (Default port:161)
TelnetPort that you need to Telnet
Apache ZooKeeper

The Default port of the JMX agent is 1099

To enable Remote JMX for ZooKeeper in Linux Environments, open the zkServer.sh file under the bin folder and check the following:
  • JMXPORT=<PORT NO>
  • ZOOMAIN="-Djava.rmi.server.hostname=<IP address> -Dcom.sun.management.jmxremote -Dcom.sun.management.jmxremote.port=$JMXPORT -Dcom.sun.management.jmxremote.authenticate=$JMXAUTH -Dcom.sun.management.jmxremote.ssl=$JMXSSL -Dzookeeper.jmx.log4j.disable=$JMXLOG4J org.apache.zookeeper.server.quorum.QuorumPeerMain"
In Windows Environments, do the following changes in zkServer.bat file under bin folder:
  • set JMXPORT=<PORT NO>
  • set ZOOMAIN="-Dcom.sun.management.jmxremote""-Dcom.sun.management.jmxremote.port=%JMXPORT%""-Dcom.sun.management.jmxremote.ssl=false""-Dcom.sun.management.jmxremote.authenticate=false"" org.apache.zookeeper.server.quorum.QuorumPeerMain"
Replace < PORT NO> with JMXPORT and < IP address> with the IP address of the machine.
Oracle CoherenceEnable JMX for monitoring. The JMX Port for Default installations of Coherence is 1099.
HadoopEnable JMX for monitoring. The JMX port for the NameNode.
APPLICATION PERFORMANCE MANAGEMENT
APM InsightOne-way communication from the Agent installed application server to the Applications Manager port (Default port: 9090/8443).
VIRTUALIZATION
Hyper-V

Windows Management Instrumentation (WMI) -- Port: 445

Remote Procedure Call (RPC) -- Port: 135

Refer to the ports required for WMI Mode of monitoring under Servers

VMWare ESX/ESXiVMWare Web Service port (Default port:443)
Citrix XenserverThe https Port where the XenServer web service runs. The Default port is 443.
DockerThe Docker socket port. (Default port: 4243).
KubernetesSSH Port (Default port: 22).
OpenShiftSSH Port (Default port: 22)
REST API Port (Default port: 8443)
WEB SERVER/SERVICES
SSL Certificate MonitorSSL port on which the web server is running (Default port: 443).
Web ServerHTTP Port of Web Server. (Default port is 80. For SSL, it is 443)
ElasticsearchThe port on which Elasticsearch is running (Default port: 9200).
Apache SolrThe port on which Apache Solr is running (Default port: 8983)
IIS ServerPort on which the IIS Server is running. (Default port is 80. For SSL, it is 443.)
Miscellaneous
Trap ListenersTrap Listener port (Default port:1620) in the Applications Manager server must be reachable from the server where you want to send traps. More on receiving SNMP Traps.
RUM Agent
  • Default RUM agent port 7070 (HTTP) and 7443 (HTTPS).
  • Above RUM Agent ports should be opened in the firewall for all the end users accessing the application, which is monitored in Real User Monitor in Applications Manager.
  • RUM Agent should be able to communicate with the Applications Manager server. i.e., one-way communication from the RUM Agent to the Applications Manager HTTPS port (Default HTTPS port: 8443).

Note:

  • End users accessing the website monitored in Applications Manager should have access to RUM Agent.
  • RUM Agent should be available on the internet and should be able to communicate with Applications Manager.
EUM Agent
  • Default EUM agent port 9999 (HTTP) and 9443 (HTTPS).
  • EUM Agent should be able to communicate with the Applications Manager server. i.e., one-way communication from the EUM Agent to the Applications Manager HTTPS port (Default port: 8443).
  • Firewall requirements for the following EUM-based monitor types should be the same as those of the non-EUM-based monitors supported in Applications Manager:
    • DNS
    • LDAP
    • Telnet
    • Mail
    • Ping
    • RBM (Default port 9595)

Applications Manager makes sure that data is secure. The internal PostgreSQL database allows only localhost to access the database through authenticated users. User Names and Passwords are stored in the PostgreSQL database that is bundled along with the product. The passwords are encrypted to maintain security.

Privileges required for different monitor types:

MonitorsPrivileges
Active DirectoryAdministrator username/password [WMI mode]
Amazon
  • The AWS Access Key ID for accessing AWS through the API. The access key has 20 alpha-numeric characters.
  • The Secret Access Key of the AWS. The secret key should be 40 alpha-numeric characters long.
Apache ServerCredentials for accessing the server status URL for Apache
AS400/iSeries
  • To retrieve data for all modules in AS400/iSeries monitor except 'Disk', a user with *USER user profile is required.
  • To retrieve data for 'Disk' and to perform Admin actions from Applications Manager, a user with the *SECOFR user profile is required.
  • If using the *SECOFR user profile is not possible, then for retrieving disk data and performing admin actions such as viewing spooled files, job logs, and performing actions in JOBS, SPOOL, SUBSYSTEM, a user profile with special authorities such as *ALLOBJ, *SAVSYS, *JOBCTL, *SPLCTL is required.
  • The user should have permission to access the QMPGDATA/QPFRDATA library because Applications Manager uses the performance collection service for retrieving disk details from the AS400/iSeries server. Note: If the performance data collection is not enabled in AS400/iSeries, you need to start it by using the command STRPFRCOL or GO PERFORM--> COLLECT PERFORMANCE DATA--> START PERFORMANCE COLLECTION. You will also be able to execute the STRPFRCOL command from the AS400/iSeries server monitor page in Admin--> Non-Interactive command option.
Database Query MonitorUser with privileges for accessing a particular database and executing the query
DB2User with at least SYSMON instance-level authority
Exchange ServerAdministrator username/password [WMI mode]
File/DirectoryUser with privileges for accessing the File or Directory to monitor
FTP/SFTPIf Authentication is enabled, enter the Username and Password for connecting to the FTP/SFTP server & move to the required directory
GlassfishUsername and password for connecting to Glassfish Admin console
HP-UXGuest user privilege
HTTP URLIf basic authentication is required, enter the same in Monitor.
Hyper-VAdministrator privileges to the root OS (Windows 2008 R2 and other supported Hyper-V versions)
IBM AIXGuest user privileges are sufficient, but "root" privileges are required for collecting memory-related details. Hence, it is preferable to use a "root" account to view all the details
IBM WebSphere MQA Channel name with the type of "Server Connection Channel"
JBossUse the JBoss username/password (if JBoss is authenticated). User should be able to access the JBoss JMX console. If not, no username/password is required
JMX/Java Runtime

If Authentication is enabled, enter the Username and password for connecting to the JMX agent.

To monitor a JMX application, the following Java runtime options are to be added to your application
  • -Dcom.sun.management.jmxremote -Dcom.sun.management.jmxremote.port=<PORT NO>
  • -Dcom.sun.management.jmxremote.ssl=false -Dcom.sun.management.jmxremote.local.only=false -Dcom.sun.management.jmxremote.authenticate=false
Replace < PORT NO> with the JMX Port for the machine.
LDAPIf Authentication is enabled, enter the Username and Password. If no username and password are provided, then it will connect to the LDAP server as an anonymous login.
LinuxGuest user privilege
Mail ServerIf Authentication is enabled, enter the Username and password for connecting to the SMTP and POP
Microsoft .NetAdministrator username/password [WMI mode]
Microsoft Office SharePoint ServerAdministrator username/password [WMI mode]
MS SQLSystem Administrator/Owner for the "master" database
MSMQAdministrator username/password [WMI mode]
MySQLThe username specified should have access to the databases to be monitored. MySQL should also be configured. This allows the host on which App Manager is running to access the MySQL database.
Oracle EBSUsers with CONNECT, SELECT_CATALOG_ROLE, and SELECT ANY TABLE roles.
RabbitMQThe User must have an administrator tag (that has privileges to list all the objects under every Virtual host) to monitor a RabbitMQ server.
SAP/SAP CCMS

You need an SAP user profile with the following authorization objects: S_RFC, S_XMI_LOG and S_XMI_PROD, which are the minimum prerequisites for adding an SAP monitor.

We use the SAP Java Connector to connect to the SAP ABAP server. The SAP JCo will communicate from APM to SAP using the SAP Dispatcher. The SAP Dispatcher port to be used is 3200 with the SAP System number.

Script monitorUser with privileges for executing the script and accessing the output file.
Server with SNMP modeSNMP Community string with read privileges.
SNMP/Network device

For SNMP Version V1/V2c:

  • SNMP Community string with read-only privileges.

For SNMP Version V3:

Select one of the three Security Levels in the drop-down list:

  • NoAuthNoPriv - Messages can be sent unauthenticated and unencrypted. Enter a UserName and Context Name.
  • AuthNoPriv - Messages can be sent authenticated but unencrypted. Enter a UserName, Context Name, and an Authentication Password. You can select an Authentication Protocol like MD5 or SHA from the drop-down list.
  • AuthPriv - Messages can be sent authenticated and encrypted. Enter a UserName, Context Name, an Authentication Password, and a Privacy Password. You can select an Authentication Protocol like MD5 or SHA from the drop-down list. By Default, the 'DES' encryption technique will be used.
SolarisGuest user privilege.
SybaseThe user should have admin privileges or be the DB owner for the master database.
Tomcat
  • For 5.x and above, a username and password are required to connect to the Tomcat Manager Application. If not, no username/password is required.
  • For 5.x, the user specified should have a 'manager' role.
  • For 6.x and above, the user specified should have "manager-gui", "manager-script", "manager-jmx" and "manager-status" roles.
VMWare ESX/ESXi

When adding VMware ESX/ESXi servers for monitoring, we recommend using the root account. However, if you are unable to use the root account, you can use a 'view-only' profile to add the servers. This profile has all the privileges required for monitoring. The user you create must be:

  • A member of the group user.
  • Based on the profile 'read only'.
VMware vFabric RabbitMQ ServerUser Name and Password of RabbitMQ server.
WebLogicUse the WebLogic username/password if WebLogic is authenticated. The user should be an administrator. Otherwise, no username/password is required.
WebLogic Integration ServerUse the WebLogic username/password if WebLogic is authenticated. User should be an administrator. Otherwise, no username/password is required.
WebservicesProvide the User Name and Password if required to invoke the web service operation.
WebSphereIf Global Security is enabled, use the same username/password. If not, no username/password is required.
WindowsAdministrator username/password [WMI mode].
Windows ClusterAdministrator username/password [WMI mode].

Enterprise Edition

PathPorts
Central Server to Probe ServerSSL Port (Default port: 8443) for data syncing.
Web server (Default port: 9090).
Probe Server to Central ServerSSL Port (Default port: 8443) for data syncing.

Note: Production Environment gives you the configuration details that you need to take care of when moving Applications Manager into Production.

Loved by customers all over the world

"Standout Tool With Extensive Monitoring Capabilities"

It allows us to track crucial metrics such as response times, resource utilization, error rates, and transaction performance. The real-time monitoring alerts promptly notify us of any issues or anomalies, enabling us to take immediate action.

Reviewer Role: Research and Development

carlos-rivero
"I like Applications Manager because it helps us to detect issues present in our servers and SQL databases."
Carlos Rivero

Tech Support Manager, Lexmark

Trusted by thousands of leading businesses globally