-
- Influencer
- Posts: 14
- Liked: 2 times
- Joined: Mar 27, 2018 3:19 pm
- Full Name: Dustin Dasal
- Contact:
ThreatHunter Service
After upgrading to 12.3, our scan indicate the new ThreatHunter service is using tcp port 6175. There is no reflection of this in the documentation for ports required. I have a case open (07580196) where the engineer has informed us that this port will be used between various components for this new feature. If there is documentation on these new port(s), can someone point me to it, otherwise, when do we expect this to be added? Like all the other ports and port ranges used between infrastructure components, we need this change to also be reflected so we can make the proper changes and have justification for it.
Thanks!
Thanks!
-
- Product Manager
- Posts: 10324
- Liked: 2756 times
- Joined: May 13, 2017 4:51 pm
- Full Name: Fabian K.
- Location: Switzerland
- Contact:
Re: ThreatHunter Service
Hello Dustin
I'm checking with our RnD team the purpose of port 6175.
And we will update the port list in our help center when I got the answer.
Best,
Fabian
I'm checking with our RnD team the purpose of port 6175.
And we will update the port list in our help center when I got the answer.
Best,
Fabian
Product Management Analyst @ Veeam Software
-
- Influencer
- Posts: 14
- Liked: 2 times
- Joined: Mar 27, 2018 3:19 pm
- Full Name: Dustin Dasal
- Contact:
Re: ThreatHunter Service
Thank you!
-
- Product Manager
- Posts: 10324
- Liked: 2756 times
- Joined: May 13, 2017 4:51 pm
- Full Name: Fabian K.
- Location: Switzerland
- Contact:
Re: ThreatHunter Service
Hello Dustin,
We have added port 6175 to our help center documentation. This port is used locally by the Veeam Threat Hunter Service.
When you initiate a antivirus scan with Veeam Thread Hunter (Scan Backup, Secure Restore), we start a small executable that runs the scan of your backup content.
This executable will communicate with the Veeam Threat Hunter Service through port 6175.
Please note that this connection is entirely local on the mount server machine, and no remote machine will need to connect to port 6175.
Best regards,
Fabian
We have added port 6175 to our help center documentation. This port is used locally by the Veeam Threat Hunter Service.
When you initiate a antivirus scan with Veeam Thread Hunter (Scan Backup, Secure Restore), we start a small executable that runs the scan of your backup content.
This executable will communicate with the Veeam Threat Hunter Service through port 6175.
Please note that this connection is entirely local on the mount server machine, and no remote machine will need to connect to port 6175.
Best regards,
Fabian
Product Management Analyst @ Veeam Software
-
- Influencer
- Posts: 11
- Liked: 6 times
- Joined: Jul 13, 2023 2:43 pm
- Full Name: Jeremy Rogers
- Contact:
Re: ThreatHunter Service
Thanks for the clarification. So if the mount server "trusts" the veeam components on a local scope (from a FW persective) there's no additional port rule requirement?
-
- Influencer
- Posts: 14
- Liked: 2 times
- Joined: Mar 27, 2018 3:19 pm
- Full Name: Dustin Dasal
- Contact:
Re: ThreatHunter Service
I appreciate the update and documentation!
-
- Product Manager
- Posts: 10324
- Liked: 2756 times
- Joined: May 13, 2017 4:51 pm
- Full Name: Fabian K.
- Location: Switzerland
- Contact:
Re: ThreatHunter Service
Correct. No external firewall ports to open. Traffic stays local on the mount server between two Veeam components.there's no additional port rule requirement?
Best,
Fabian
Product Management Analyst @ Veeam Software
-
- Chief Product Officer
- Posts: 32237
- Liked: 7598 times
- Joined: Jan 01, 2006 1:01 am
- Location: Baar, Switzerland
- Contact:
Re: ThreatHunter Service
@Mildur in this case let's remove it from the documentation ASAP, as it is meant to document external ports that need to be open in firewalls. Otherwise customers will just open it along with all other ports, and every open port increases attack surface.
-
- Product Manager
- Posts: 10324
- Liked: 2756 times
- Joined: May 13, 2017 4:51 pm
- Full Name: Fabian K.
- Location: Switzerland
- Contact:
Re: ThreatHunter Service
Hi Anton
As discussed yesterday, we will review all "local-only ports" and remove them from the documentation.
Best,
Fabian
As discussed yesterday, we will review all "local-only ports" and remove them from the documentation.
Best,
Fabian
Product Management Analyst @ Veeam Software
Who is online
Users browsing this forum: Bing [Bot], madbana and 99 guests