Skip to main content
Question

Discovery Scan Port Communication Direction

  • January 24, 2025
  • 5 replies
  • 414 views

Forum|alt.badge.img+3

Hi All, 

 

For running detailed discovery scan, we need to open multiple ports between Password Safe Appliances/Resource Brokers and Target Systems. I wanted to understand whether those ports communication would be unidirectional or bi-directional? 

 

Regards

Mahendra

5 replies

  • BeyondTrust Employee
  • January 27, 2025

Hey ​@mj15! As I understand it, for Detailed Discovery scans this requires TCP/445 or TCP/139 to be open on the scan target, and once connected to the target host the agent will communicate with the BTExecService over this port. All sessions originate from the BT Discovery Agent (BDA) so there aren’t any inbound port requirements on the BDA host machine. KB0017022 has all of the requirements for staging a Windows system for discovery scans (KB linked below).

 

Here are a couple of helpful KB articles on the topic:


Forum|alt.badge.img
  • BeyondTrust Employee
  • January 27, 2025

Hi the below article list the ports and protocols 

https://beyondtrustcorp.service-now.com/csm?id=kb_article_view&sysparm_article=KB0019381

-Communication and port list for Password Safe Cloud Resource Brokers and tenant (instance)


Forum|alt.badge.img+3
  • Author
  • Rising Star
  • January 28, 2025

Thanks Nik and Glenn for the response. 

The articles does not mention anything about directions for these ports, whether it will be unidirectional or bi-directional. Can you please throw some light on it or if I have missed out to locate it in the articles? 

Thanks in advance.  

 

Regards,

Mahendra


cpontau
BeyondTrust Employee
Forum|alt.badge.img+4
  • BeyondTrust Employee
  • January 30, 2025

Hi ​@mj15,

let me give you some examples. Always one direction. You can find them in the KB article Glenn posted:

General communication

Resource Broker(s) → PScloud (your tenant) Port 443

 

Discovery

Resource Broker(s) → Windows device Port 445

Resource Broker(s) → SSH Device Port 22

 

Session

Resource Broker(s) → Windows device Port 3389 (RDP)

Resource Broker(s) → SSH device Port 22

 

Ports for Password Safe Users

User Client → PS Cloud interface Port 443

User Client → Resource Broker(s) Port 4489, 4422 (to start RDP and SSH sessions)


GloriaB
BeyondTrust Employee
  • BeyondTrust Employee
  • February 4, 2025

I have updated the article so the port direction is more clear:  Communication and port list for Password Safe Cloud Resource Brokers and tenant (instance)