By default, Network Security appliances use a single-port address type for the following types of communication with the Central Management System appliance:
Remote management—Initiates the connection and configures the appliance.
DTI network service—Requests software updates (such as system images, guest images, and security content) from the DTI network.
The single-port configuration uses only SSH port 22 by default. This reduces the complexity of firewall rules, and it provides an additional layer of security and privacy between the Central Management System appliance and the appliances it manages.
You can configure the managed appliance to use the dual-port address type instead. With the dual-port address type, the management traffic uses the SSH port (port 22) and the DTI network service traffic uses the HTTPS port (port 443).
In environments in which the Central Management System appliance is behind a Network Address Translation (NAT) gateway, using a single port also eliminates the need to open an additional HTTPS port (443) for the managed appliance to request software updates from the Central Management System appliance. (For details about NAT deployment, see Configuring Network Address Translation (NAT) and Switching to single-port or dual-port Communication in a NAT deployment .)
Note
If you change the address type on an appliance that was already added to the Central Management System appliance using a client-initiated connection, that appliance will be briefly disconnected and then reconnected using the new configuration.
Admin access to the managed appliance