Configure Firewall and Proxy Rules for eyeInspect

 

Before you can install or configure your eyeInspect Command Center or Sensors, you must set your firewall and proxy rules.

eyeInspect Firewall Rules

Source Destination Port Description of Connection
Command Center Active Sensor 22 (ssh)

System Management

Command Center Passive Sensor 22 (ssh) System Management
Enterprise Command Center Command Center 443 Sends eyeInspect data
Active Sensor Command Center 9092 Sends Active Sensor data
Active Sensor Target Hosts Service-specific Performs Active Sensor scans (WMI, SEL, etc.)
Passive Sensor Command Center 29999*

9092

Sends Passive Sensor data
eyeInspect Operators Command Center/ Enterprise Command Center 22 (ssh)

443 (https)

Command Center and Enterprise Command center GUI system management
(Optional) Primary Command Center Secondary Command Center 5432

22 (ssh)

Bi-directional, Command Center High Availability (not enabled by default)
* Port can be customized for your system.

Firewalls and Proxies for Active Sensors

Active Sensors need to be connected to the network of their target assets. Having routers, firewalls, or proxies between the Active Sensor and their target asset diminishes the sensor's ability to retrieve data.

Firewalls and Proxies for Passive Sensors

The default port via which the Command Center and the Passive Sensor communicate is 29999. To change the port to something other than 29999, refer to Passive Sensor Startup Options in the eyeInspect Configuration Guide v5.9.

The following traffic must be allowed to reach the Command Center and the Passive Sensor:

  • DNS access for Sensor and Command Center

  • LDAP access for Command Center and Enterprise Command Center

  • NTP access for the Sensor, Command Center and Enterprise Command Center (not required for demo deployments)

  • SMTP access for Command Center alert forwarding

  • Syslog access for Command Center alert forwarding

Note: The open port 29999 for communication between the Command Center and Passive Sensor is not needed for bundled configurations where the Command Center and Passive Sensor are on one server.
Remember: Internal services bind to localhost/loopback interfaces for inter-component communications and are not accessible from external networks. Security audits may observe internal eyeInspect Command Center services bound to localhost or loopback addresses (127.0.0.1) in listening state. These services handle inter-component communications for processing, aggregating, and storing real-time traffic information collected from eyeInspect Sensors. Services bound to loopback interfaces are not accessible from external networks due to the iptables configuration.