Skip navigation
McAfee Secure sites help keep you safe from identity theft, credit card fraud, spyware, spam, viruses and online scams
856 Views 10 Replies Latest reply: Oct 30, 2013 9:23 PM by brentdw RSS 1 2 Previous Next
brentdw Newcomer 11 posts since
Oct 23, 2013
Currently Being Moderated

Oct 30, 2013 10:11 AM

Agent Handler in DMZ

I've deployed an Agent Handler in our DMZ. The following ports are open on the firewall between the AH and ePO Server:

 

TCP 80

TCP 389

TCP 443

TCP 636

TCP 1433

UDP 1434

TCP 8081

UDP 8082

TCP 8443

TCP 8444

 

The Agent Handler is able to communicate with the ePO Server without any issue. The problem is that other servers in the DMZ cannot communicate with the Agent Handler. I have two priority rules: the first one defines our internal subnets and restricts them to the internal ePO Server, and the second rule defines the DMZ subnet and restricts it to the Agent Handler.

 

The message I'm receiving in the Agent Monitor on all DMZ servers (except the AH itself) is "Agent failed to communicate with ePO Server." When I go to the "About..." menu, it is correctly pointed to the Agent Handler in the DMZ. Any thoughts?

  • JoeBidgood McAfee SME 2,868 posts since
    Sep 11, 2009
    Currently Being Moderated
    1. Oct 30, 2013 10:44 AM (in response to brentdw)
    Re: Agent Handler in DMZ

    Possibly a silly question, but is there any kind of firewall or port blocking that is preventing inbound connections to the AH machines? Specifically on the agent-to-server ports, which are 80 and 443 by default?

     

    HTH -

     

    Joe




    (Please post questions to the forum, as I am unable to respond to private messages. Thanks!)



  • Laszlo G Veteran 1,213 posts since
    May 23, 2007
    Currently Being Moderated
    3. Oct 30, 2013 11:03 AM (in response to brentdw)
    Re: Agent Handler in DMZ

    Could it be that servers on DMZ are trying to connect to Agent Handler to its public IP address?

  • Laszlo G Veteran 1,213 posts since
    May 23, 2007
    Currently Being Moderated
    5. Oct 30, 2013 11:19 AM (in response to brentdw)
    Re: Agent Handler in DMZ

    Can you telnet from a server on the DMZ to the Agent-Handler through agent-to-server communication port?

  • JoeBidgood McAfee SME 2,868 posts since
    Sep 11, 2009
    Currently Being Moderated
    7. Oct 30, 2013 2:42 PM (in response to brentdw)
    Re: Agent Handler in DMZ

    Is there anything recorded in the server.log on the AH that would indicate a problem?

     

    HTH -

     

    Joe




    (Please post questions to the forum, as I am unable to respond to private messages. Thanks!)



1 2 Previous Next

More Like This

  • Retrieving data ...

Bookmarked By (0)

Legend

  • Correct Answers - 5 points
  • Helpful Answers - 3 points