Installing the Agent Handler server hardware and software, and configuring the firewall ports are the first steps before using ePO - On-prem to manage systems behind a DMZ.
Make sure that your Agent Handler server meets all hardware and software requirements.
Build the Agent Handler server hardware with the Microsoft Windows Server operating system.
Install the server in the DMZ behind the firewall in the protected network.
Configure your Domain Name System (DNS) server to add the Agent Handler server behind the firewall in the protected network.
Configure these ports on the internal-facing firewall to communicate between the ePO - On-prem server and the Agent Handler in DMZ:
Port 80 — Bidirectional
Port 8443 — Agent Handler to the ePO - On-prem server
Port 8444 — Agent Handler to the ePO - On-prem server
Port 443 — Bidirectional
If your SQL database is installed on a different server than your ePO - On-prem server, configure these two ports on the internal-facing firewall for that connection to the Agent Handler:
Port 1433 TCP — Agent Handler to SQL database server
Port 1434 UDP — Agent Handler to SQL database server
Configure these ports on the public-facing firewall to communicate between the ePO - On-prem server and the Agent Handler in the DMZ:
Port 80 TCP — Inbound
Port 443 TCP — Inbound
Port 8081 TCP — Bidirectional
Port 8082 UDP — Bidirectional