Skip to main content

Network requirements

This section provides the network requirements, including the port, firewall, and proxy requirements.

Port availability

Several ports must be available, depending on how the firewalls are implemented in environment. If the required ports are blocked or used by another process, some Lenovo XClarity Integrator functions might not work.

To determine which ports must be opened based in environment, review the following sections. The tables in these sections include information about how each port is used in XClarity Integrator, the vCenter, the managed device that is affected, the protocol (TCP or UDP), and the direction of traffic flow.

Inbound traffic identifies flows from the managed device or external systems to XClarity Integrator, so ports need to open on the XClarity Integrator appliance. Outbound traffic flows from XClarity Integrator to the managed device or external systems.

Access to the XClarity Integrator servers

If the XClarity Integrator server and all managed devices are behind a firewall, and users are intended to access those devices from a browser that is outside of the firewall, users should ensure that the XClarity Integrator ports are open.

The XClarity Integrator server listens on and responds through the ports that are listed in the following table.

Note
XClarity Integrator is a RESTful application that communicates securely over TCP on port 443.
Table 1. Internet connection requirements
CommunicationXClarity Integrator appliancevCenterXClarity Administrator 1Lenovo services 2
Outbound (ports open on external systems)DNS – TCP/UDP on port 53HTTPS – TCP on port 443HTTPS – TCP on port 443HTTPS – TCP on port 443
Inbound (ports open on XClarity Integrator appliance)HTTPS – TCP on port 443HTTPS – TCP on port 443N/AN/A
  1. To register XClarity Administrator to XClarity Integrator, refer to https://sysmgt.lenovofiles.com/help/topic/com.lenovo.lxca.doc/plan_openports.html.

  2. To access to the specific Lenovo service web sites, refer to Firewall.

Access between XClarity Integrator and managed devices

If managed devices (such as compute nodes or rack servers) are behind a firewall and if users are intended to manage those devices from a XClarity Integrator server that is outside of that firewall, users should ensure that all ports involved with communications between XClarity Integrator and the baseboard management controller in each managed device are open.

Note
ICMP protocol also should be permitted between XClarity Integrator and server BMC. Lenovo XClarity Integrator uses ICMP (ping) to check BMC connectivity during firmware updates.
Table 2. Servers and compute nodes
CommunicationThinkSystem and ThinkAgileSystem x
Outbound (ports open on external systems)
  • SLP – UDP on port 427

  • HTTPS – TCP on port 443

  • CIM HTTPS – TCP on port 5989 2

  • Firmware updates - TCP on port 69904

  • SLP – UDP on port 427

  • HTTPS – TCP on port 443

  • IPMI – TCP on port 623 1

  • CIM HTTP – TCP on port 59883

  • CIM HTTPS – TCP on port 5989 3

  • Firmware updates - TCP on port 6990 4

Inbound (ports open on XClarity Integrator appliance)
  • HTTPS – TCP on port 443

  • Firmware updates - TCP on port 6990 4

  • HTTPS – TCP on port 443

  • Firmware updates - TCP on port 6990 4

  1. XClarity Integrator uses this port for server configuration and firmware update.

  2. By default, this port is disabled on some new servers. In this case, it is not required to open this port and XClarity Integrator uses REST Over HTTPS for management. It is only required to open this port for the servers managed by XClarity Integrator using CIM.

  3. By default, management is performed over secure ports. The non-secure ports are optional.

  4. This port is used for connecting to the BMU OS to transfer files and run the update commands.

Firewall

Downloading management server updates and firmware updates requires Internet access. Configure the firewall (if any) in network to enable LXCI management server to perform these operations. If the management server fails to access to the Internet, configure LXCI to use a proxy server.

Ensure that the following FQDN and ports are available on the firewall and allowed in the proxy.

Table 3. Internet connection requirements
DNS namePortsProtocols
datacentersupport.lenovo.com443https
download.lenovo.com443https
filedownload.lenovo.com443https
support.lenovo.com443https
supportapi.lenovo.com443https

Proxy

To set the proxy in vCenter and to use vLCM function to update the firmware, users should allow the connection from vCenter to Lenovo XClarity Integrator (protocol HTTPS, port 443) in the proxy configuration of users’ company.

The proxy server should meet the following requirements:

  • The proxy server is set up to use basic authentication.

  • The proxy server is set up as a non-terminating proxy.

  • The proxy server is set up as a forwarding proxy.

  • The load balancers are configured to keep sessions with only one proxy server.