Firewall Rule for TCP_IP Port AJP_8009

If you are using network security products to scan your local intranet hosts for vulnerabilities, be aware that these products have a specific scan used against a JBoss server at TCP/IP port AJP/8009. Scanning the LIQUENT InSight server with a network security product will cause an outage, requiring a restart.

To avoid issues caused by network security scanning products:
  1. Create a firewall rule on the InSightManager application server to block external hosts from sending inbound traffic to TCP/IP port 8009.
  2. Ensure that the firewall rule does not block localhost traffic to that same TCP/IP port 8009.

Please consult with your internal network security department to be sure that these security requirements can be met by the Windows configuration in your environment.