Firewalls

Ports used by SEP Sesam

When using the standard configuration for SEP Sesam the following TCP ports must be open:

Server:

  • stpd 11001
  • remote-gui 11401

Client:

  • ctrl 11301
  • data 1024-65535 (can be limited with the custom ports option below)

Standard Connection Process:

  1. The Sesam server opens a connection to port 11301 on client
  2. The Sesam client opens a connection to port 11001 on Sesam server (or remote device server).
  3. The Sesam server opens a connection to a random port above 1024 on the client.

Custom Ports for firewalled/nat/wan/vpn clients:

  1. Edit the properties of the client (Components > Topology)
  2. Switch to the "Options" tab
  3. Add 11003-11010 to specify a port range, 2 ports are required for each stream, these reduce your "data" ports above
  4. Enable access to these ports from the sesam server to the client in the client and/or edge firewall(s)
SSH Alternative:

  1. Use ssh-genkey (as root on the backup server) to create a key pair, don't use a password. They will be saved by default as /root/.ssh/id.[dr]sa.[prv|pub]
  2. To "allow" this key to access the server you will have to transfer it to /root/.ssh/authorized_keys on the server.
  3. Transfer the file with the following command, twice
  4. The server ssh client (/etc/ssh/ssh_config) should consider Compression=Yes and CompressionLevel=6 for optimal VPN/CPU performance

root@SEP_SERVER# scp -v /root/.ssh/id.rsa.pub root@SEP_CLIENT:/root/.ssh/authorized_keys.

You can use multiple keys in the authorized_keys file, one on each line.

After this setup you should be able to login to the sep server as root and ssh to the client as root without using a password, set the client properties connection method to ssh and the access option "-s".

"If you are asked for the password on the second attempt there is a problem which may be located in /etc/ssh/sshd_config as AuthorizedKeysFile=[/dev/null|/any/empty/file]"

Request Call

Our sales team would be happy to assist you!

Download

SEP 30-day Trial

You must login or use current login to download the FREE trial.

Media Library

Browse and discover videos by SEP.