Segmenting network architecture and ports

Prev Next

Isolate deployment components to maintain data confidentiality, integrity, and availability during network events.

Dedicated management zone

Place the ePO Server, Agent Handlers, and the SQL Server database inside a restricted Management Security Zone (Isolated VLAN). Block inbound traffic from general user workstations and standard server segments except through designated product ports.

For requirements and traffic details, see Ports required for communicating through a firewall.

Distributed repositories and SuperAgents

Deploy Distributed Repositories or SuperAgents to localize content and definition updates across your architecture. For details, see Best practice: SuperAgent repositories.

  • Mitigates single points of network failure.

  • Preserves network bandwidth across WAN links.

  • Enforces HTTPS across all communication channels between Distributed Repositories, Agent Handlers, and Source Sites.

Host-based firewall hardening

Use a host-based firewall on the operating system to restrict incoming connections to the ePO server, allowing traffic only from validated Agent Handlers and managed subnets.