<docbook><section><title>MTFirewallConfiguration</title><para> </para><title> Firewall Considerations for Multi-Tier &quot;Enterprise&quot; Edition Data Access Drivers </title> Firewall Considerations for Multi-Tier &quot;Enterprise&quot; Edition Data Access Drivers 
<itemizedlist mark="bullet" spacing="compact"><listitem> The Request Broker host must accept (and all intervening firewalls must permit) inbound connections from all client hosts (and from the Request Broker host itself) to (and responses from) -- <itemizedlist mark="bullet" spacing="compact"><listitem> TCP port <emphasis><computeroutput>60001</computeroutput></emphasis>, in all Releases; </listitem>
<listitem> UDP port <emphasis><computeroutput>60001</computeroutput></emphasis>, in all Releases; </listitem>
<listitem> TCP port <emphasis><computeroutput>5000</computeroutput></emphasis>, in Release 3.x and earlier; </listitem>
<listitem> TCP port specified by Rulebook setting <emphasis><computeroutput>[Protocol TCP]:Listen</computeroutput></emphasis> in Release 4.x and later; default is <emphasis><computeroutput>5000</computeroutput></emphasis>; and </listitem>
<listitem> TCP ports between Rulebook settings <emphasis><computeroutput>[Protocol TCP]:PortLow</computeroutput></emphasis> (default <emphasis><computeroutput>5000</computeroutput></emphasis>) and <emphasis><computeroutput>[Protocol TCP]:PortHigh</computeroutput></emphasis> (default <emphasis><computeroutput>60000</computeroutput></emphasis>) (including the port numbers specified for these settings).</listitem>
</itemizedlist></listitem>
</itemizedlist><itemizedlist mark="bullet" spacing="compact"><listitem> The Generic Client hosts (and all intervening firewalls) must permit outbound connections to (and responses from) the Broker host on -- <itemizedlist mark="bullet" spacing="compact"><listitem> TCP port <emphasis><computeroutput>5000</computeroutput></emphasis>, in Release 3.x and earlier; </listitem>
<listitem> TCP port specified by Rulebook setting <emphasis><computeroutput>[Protocol TCP]:Listen</computeroutput></emphasis> in Release 4.x and later; default is <emphasis><computeroutput>5000</computeroutput></emphasis>; and </listitem>
<listitem> TCP ports between Rulebook settings <emphasis><computeroutput>[Protocol TCP]:PortLow</computeroutput></emphasis> (default <emphasis><computeroutput>5000</computeroutput></emphasis>) and <emphasis><computeroutput>[Protocol TCP]:PortHigh</computeroutput></emphasis> (default <emphasis><computeroutput>60000</computeroutput></emphasis>) (including the port numbers specified for these settings).</listitem>
</itemizedlist></listitem>
</itemizedlist><itemizedlist mark="bullet" spacing="compact"><listitem> If the Database Agent makes a network connection to the target DBMS (in a &quot;three-tier&quot; or &quot;gateway&quot; deployment), the database server host must accept (and all intervening firewalls must permit) inbound connections on the DBMS listen port(s) (e.g., <emphasis><computeroutput>5432/tcp</computeroutput></emphasis> for PostgreSQL; <emphasis><computeroutput>1433/tcp</computeroutput></emphasis>, <emphasis><computeroutput>1433/udp</computeroutput></emphasis>, <emphasis><computeroutput>1434/tcp</computeroutput></emphasis>, and <emphasis><computeroutput>1434/udp</computeroutput></emphasis> for SQL Server, etc.).</listitem>
</itemizedlist><itemizedlist mark="bullet" spacing="compact"><listitem> If you have a stateful firewall, return packets from the Request Broker and Database Agents to the clients should be taken care of automatically.
 If not, you will also have to address the ephemeral client-side ports.</listitem>
</itemizedlist><itemizedlist mark="bullet" spacing="compact"><listitem> The Multi-Tier Admin Assistant listens at TCP port <emphasis><computeroutput>8000</computeroutput></emphasis> by default.
 This is configurable, via the <computeroutput>HttpPort</computeroutput> setting in the <computeroutput>[Startup]</computeroutput> stanza of the <computeroutput>www_sv.ini</computeroutput> file, typically found in the <computeroutput>w3config</computeroutput> subdirectory of the <computeroutput>bin</computeroutput> directory containing the Broker executable, <computeroutput>oplrqb</computeroutput>.</listitem>
</itemizedlist><bridgehead class="http://www.w3.org/1999/xhtml:h2"> Related Documentation </bridgehead>
<itemizedlist mark="bullet" spacing="compact"><listitem> <ulink url="ConfigureServer-sideFirewallsForMulti-TierConnectivity">Configuring Server-side Firewalls for Multi-Tier Connectivity</ulink> </listitem>
<listitem> <ulink url="UnableContactLicenseManager">Error Message: Unable to contact the OpenLink License Manager</ulink> </listitem>
<listitem> <ulink url="OplmgrNetworking">OpenLink License Manager Networking Considerations</ulink> </listitem>
<listitem> <ulink url="ConfigureMulti-TierRequestBrokerForUseOnMachinesWithMultipleNetworkCards">Configure Multi-Tier Request Broker for Use on Machines with Multiple Network Cards</ulink></listitem>
</itemizedlist></section></docbook>