cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
314
Views
0
Helpful
1
Replies

TCP Port use when adding sensors to VMS

melangnghe
Level 1
Level 1

What TCP port does VMS use when adding a sensor to VMS Security Monitor, Device Manager etc?

Is RDEF listener using a port?

Is UDP port 45000 still needed in IDS4.x or is it only required in IDS 3x?

Thanks.

1 Accepted Solution

Accepted Solutions

a.arndt
Level 3
Level 3

An RDEP listener, if I understand the context of your question, is the process on the IDS appliance that is connected to by the RDEP clients (IEV, CTR, VMS / IDSMC). Since it is a server-like process, it listens on TCP 443. It can be configured to listen on TCP 80, but this is not a default setting.

The only other default port used by Cisco IDS 4.x is TCP 22 (SSH) for CLI access and certain file copy operations (scp, for example). Again, you can configure the use of TCP 23 (TELNET) for CLI access, but it is not a default setting.

In summary, an appliance (IDS-42XX, IDSM-2, NM-CIDS) will only have two ports open by default; TCP 22 and 443. TCP 22 is used by SSH for CLI access and TCP 443 is used for both RDEP and IDM access.

Finally, UDP 45000 is not used by Cisco IDS 4.x; this was only used by 3.x and older for the old communications protocol.

I hope this helps,

Alex Arndt

View solution in original post

1 Reply 1

a.arndt
Level 3
Level 3

An RDEP listener, if I understand the context of your question, is the process on the IDS appliance that is connected to by the RDEP clients (IEV, CTR, VMS / IDSMC). Since it is a server-like process, it listens on TCP 443. It can be configured to listen on TCP 80, but this is not a default setting.

The only other default port used by Cisco IDS 4.x is TCP 22 (SSH) for CLI access and certain file copy operations (scp, for example). Again, you can configure the use of TCP 23 (TELNET) for CLI access, but it is not a default setting.

In summary, an appliance (IDS-42XX, IDSM-2, NM-CIDS) will only have two ports open by default; TCP 22 and 443. TCP 22 is used by SSH for CLI access and TCP 443 is used for both RDEP and IDM access.

Finally, UDP 45000 is not used by Cisco IDS 4.x; this was only used by 3.x and older for the old communications protocol.

I hope this helps,

Alex Arndt