Previous Topic: Configure the System for FirewallsNext Topic: Configure the Hosts File for Firewalls that use Network Address Translation


Specify the Firewall Rules

You must configure the firewall to allow the necessary traffic between Business Objects components. See your firewall documentation for details of how to specify these rules.

Specify one inbound access rule for each communication path that crosses the firewall. You might not need to specify an access rule for every Business Objects server behind the firewall.

Use the port number you specify in the server Port text box. Remember that each server on a computer must use a unique port number. Some Business Objects servers use more than one port.

Note: If BusinessObjects Enterprise is deployed across firewalls that use NAT, every BusinessObjects Enterprise server on all computers needs a unique Request Port number. That is, no two servers in the entire deployment can share the same Request Port.

Note: You do not need to specify any outbound access rules. BusinessObjects Enterprise servers do not initiate communication to the web application server, or to any client applications.

Example:

This example shows the inbound access rules for a firewall between the web application server and the BusinessObjects Enterprise servers. In this case you open two ports for the CMS, one port for the Input File Repository Server (FRS), and one port for the Output FRS. The Request Port numbers are the port numbers you specify in the Port text box in the CMC configuration page for a server.

Source Computer

Port

Destination Computer

Port

Action

Web Application Server

Any

CMS

6400

Allow

Web Application Server

Any

CMS

<Request Port Number>

Allow

Web Application Server

Any

Input FRS

<Request Port Number>

Allow

Web Application Server

Any

Output FRS

<Request Port Number>

Allow

Any

Any

CMS

Any

Reject

Any

Any

Other BusinessObjects Enterprise servers

Any

Reject