Ad Widget

Collapse

Zabbix ports, auto deployment and remote control

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • Tharbad
    Junior Member
    • Apr 2014
    • 5

    #1

    Zabbix ports, auto deployment and remote control

    Hi all,

    I have 3 questions:
    1) What ports do I need to open in my firewall? I need to know protocol, direction and port numbers.
    2) Is it possible to auto deploy agents?
    3) Is it possible to tunnel ssh or RDP over zabbix agent<=>server communication? Is it possible to create such connection at all through zabbix?

    Details:
    I'm using the latest appliance.

    Thanks
  • steveboyson
    Senior Member
    • Jul 2013
    • 582

    #2
    1) 10050/tcp/incoming to your agents, 10051/tcp/incoming to your servers or proxies. Is pretty well covered in the docs.
    2) no
    3) no

    Comment

    • Tharbad
      Junior Member
      • Apr 2014
      • 5

      #3
      What about outbound traffic?

      I've opened those ports but I get the following error:

      Code:
      Get value from agent failed: cannot connect to [[<IP>]:10050]: [4] Interrupted system call

      Comment

      • steveboyson
        Senior Member
        • Jul 2013
        • 582

        #4
        Of course you need a way back from your agent. This is usually a high port (> 1024) and works as usual TCP connects via firewalls work.

        Comment

        • Tharbad
          Junior Member
          • Apr 2014
          • 5

          #5
          This port has a number? Or it's random?

          Thanks

          Comment

          • steveboyson
            Senior Member
            • Jul 2013
            • 582

            #6
            It's as random as other outgoing tcp connections use random source ports.

            Comment

            • Tharbad
              Junior Member
              • Apr 2014
              • 5

              #7
              Great...
              Is there a way to make it static?

              Comment

              • steveboyson
                Senior Member
                • Jul 2013
                • 582

                #8
                Originally posted by Tharbad
                Great...
                Is there a way to make it static?
                Not that I know of. May I ask why is that causing troubles for you? It is just the way TCP works ...

                Comment

                • Tharbad
                  Junior Member
                  • Apr 2014
                  • 5

                  #9
                  I like my security tight. Most of the monitoring system allow static ongoing ports. It's one of those "nice to have" features with all the security buzz in the recent years.

                  Comment

                  • steveboyson
                    Senior Member
                    • Jul 2013
                    • 582

                    #10
                    I personally see no problem at all in this. SMTP, ssh, http, ... - they are all working that way using dynamic outgoing ports.

                    The rules on the firewalls almost always work with "SYN" and "TCP_ESTABLISHED" flags so that poses no probs in my opinion.

                    Comment

                    Working...