3.3.2 Activating ports

The following ports are required for operating the AGW:

PortSourceDestinationDescription
Basic functionalities
TCP 443 (https)HIN Access Gateway(s)gateway.hin.ch / app.hin.ch / auth.hin.ch / agw-manager.hin.chConnection to the HIN datacentre for application access.
TCP 443 (https)Clients (end users)HIN Access Gateway(s)Access to the access gateway for authentication
TCP 389 (ldap)HIN Access Gateway(s)Active DirectoryVerification of the AD login
TCP 636 (ldaps)HIN Access Gateway(s)Active DirectoryVerification of the AD login
TCP 88HIN Access Gateway(s)Active DirectoryVerification of the Kerberos token
UDP/TCP 464HIN Access Gateway(s)Active DirectoryKerberos for AGW AD Join
TCP 2222 (ssh)HIN Access Gateway(s)update2.agw.hin.chConnection to the HIN datacentre for the support connection
TCP 80 (http)HIN Access Gateway(s)update2.agw.hin.chObtaining system updates
TCP 4433Admin clientsHIN Access Gateway(s)HIN AGW Admin port
Cluster (Required if the AGW is being run in a cluster)
TCP 22 (ssh)Between all cluster nodesRequired for synchronising the cluster settings
UDP 5404-5406Between all cluster nodesRequired for switching virtual IP address