On-premises network infrastructure | PRA On-prem
The following questions should be considered when implementing your B Series Appliance in the network.
How are connections established to the B Series Appliance?
The connection from each of the various clients is an outbound connection from the computer to the B Series Appliance, and the only required ports are 80 and 443. Therefore, the allowed ports would typically be 80 and 443 from the internet to the DMZ, and 80 and 443 from the internal network to the DMZ.
Is port 443 the only port that needs to stay open inbound to the B Series Appliance?
The connection from each of the various clients is an outbound connection from the computer to the B Series Appliance, and the only required ports are 80 and 443. Therefore, the allowed ports would typically be 80 and 443 from the internet to the DMZ, and 80 and 443 from the internal network to the DMZ. Port 22 is an outbound port from the B Series Appliance to BeyondTrust. More ports may be available depending on your build.
Optionally, the B Series Appliance can be configured to automatically check for updates from btupdate.com. This requires an outbound connection on port 443 from the B Series Appliance and the ability to connect to a DNS server to resolve this name. If the DNS server is within the DMZ, no additional ports would be required, but if the DNS server is in a different zone, the necessary ports for this would need to be allowed as described in the Firewall Rules table in the previous section. This can be avoided by downloading updates for the B Series Appliance and applying them manually. Lastly, the server is configured with an NTP server to sync the time on the B Series Appliance. This can be supported by connecting to clock.bomgar.com, or it can be supported pointing to an internal NTP server using Port 123.
What other outbound connectivity does the B Series Appliance need?
The B Series Appliance can be configured with an NTP server to sync the time on the B Series Appliance. This can be supported by connecting to clock.bomgar.com, or it can be supported pointing to an internal NTP server using Port 123.
Is the LDAP server on the same LAN as your B Series Appliance?
If not, you must install a BeyondTrust Connection Agent on the LDAP server to support communications between the B Series Appliance and the LDAP Server.
Will there be two B Series Appliances configured, one as a backup B Series Appliance to support automatic failover?
If so, the B Series Appliances need to be on the same subnet, and they each need a DNS A Record for their individual IP Addresses.
Will you be utilizing a RADIUS server with BeyondTrust?
If so, this is typically port 1812.
Will you be utilizing a Kerberos Key Distribution Center (KDC) with BeyondTrust?
If so, the users typically communicate with their KDC over port 88 UDP.
Is your client base completely internal or accessible through a VPN?
If so, deploying the B Series Appliance on an internal network segment is ideal, and no firewall changes are required, because both the B Series Appliance and all of the supported clients are internal to the firewall.
Are you accessing endpoints outside of your company's internal network?
If so, best practices in network design discourage opening external access directly to your internal network. If you are using BeyondTrust to access endpoints external to your network, it is highly recommended that the B Series Appliance reside in a DMZ that segments the internal network from the internet.
How are updates to the B Series Appliance done?
The B Series Appliance can be configured to automatically check for updates from btupdate.com. This requires an outbound connection on port 443 from the B Series Appliance and the ability to connect to a DNS server to resolve this name. If the DNS Server is within the DMZ, no additional ports would be required, but if the DNS server is in a different zone, the necessary ports for this would need to be allowed. This can be avoided by downloading updates for the B Series Appliance and applying them manually.
Updated 2 months ago
