OS Service Configuration
  • 18 Mar 2024
  • Dark
    Light
  • PDF

OS Service Configuration

  • Dark
    Light
  • PDF

Article summary

Use the information below to configure OS Services for IAP.

  1. Configure the following services to start on boot.

    • NTPD - Provides synchronization of time across all the systems. This is important to keep consistency in audit trails and logging.
    • NSCD - This service is a name server caching daemon. Best practice dictates that frequently accessed hosts should be configured in the /etc/hosts file (example: MongoDB server). The name server caching daemon helps improve operational performance of the platform by caching DNS lookups for a configurable period, as opposed to performing a separate DNS lookup request for each transaction the system needs to perform. This should be used in environments where hosts file configuration is not feasible or allowed.
  2. Configure host firewall protection services, e.g. IP Tables, to protect incoming traffic wherever feasible.

  3. The following list of open ports may be different for your environment. These ports are required. Please see your system administrator or network security officer.

    • Allow established connections.
    • Allow all packets on the loopback interfaceAllow SSH, TCP port 22, from the management network.
    • Allow DNS, UDP port 53, from configured DNS servers.
    • Allow NTP, UDP port 123, from configured NTP servers.
    • Allow MongoDB, TCP port 27017, from IAP servers.
    • Allow IAP HTTPS, default is TCP port 3443, from the northbound network.

Was this article helpful?

Changing your password will log you out immediately. Use the new password to log back in.
First name must have atleast 2 characters. Numbers and special characters are not allowed.
Last name must have atleast 1 characters. Numbers and special characters are not allowed.
Enter a valid email
Enter a valid password
Your profile has been successfully updated.