This discussion has been locked. The information referenced herein may be inaccurate due to age, software updates, or external references.
You can no longer post new replies to this discussion. If you have a similar question you can start a new discussion in this forum.

HA TCP Port 5671

Hello All,

I am working on a large scale design with multiple APE's all with HA, and the following description has got me slightly confused.

5671TCP

SolarWinds High Availability

bidirectionalPort 5671 must be open into the HA pool with the main Orion server from all Orion servers. Traffic is encrypted using TLS 1.2.

I am building Firewall rules for the environment and this description doesn't clarify which devices use this port. Does this mean that each of the Pool Members in an HA Pair needs to communicate with each other on this port? Does it mean that the Primary Server needs to communicate with each of the pool members of any HA APE Pool, can anyone add any context?

Thanks

David

Parents Reply
  • Thanks, we do want to include the VIP as a source as it has been given an IP appropriate to ensure polling from the VIP but I wasn’t sure if this port was needed between the two pool members of a HA pair or just from the each pool member to the VIP of other pool members?

Children
  • It is not required between individual APEs in a pool, but it is required from each APE pool member to both main Orion servers if they're participating in an HA pool.

    If it's easier to understand excluding HA from the equation, all APE's must have this port open the main Orion server. if they're in an HA pool, then that means both members of the HA pool must have this port open to the main Orion server. If he main Orion server is in an HA pool, then both members of that main HA pool must have this port open also, in addition to any APEs.

  • Excellent, thank you for the clarification.

    Sorry but are you able to confirm, if that’s the same for the new Cortex Service on port 17799 ?

  • TCP Port 17799 communicates exclusively through localhost. It does not need to be opened externally to any network hosts.