Page tree

This topic only applies to Armor Anywhere users.


Operating system compatibility

Operating systemSupported version for 64-bit environments only
CentOS6.X, 7.X

Red Hat Enterprise Linux (RHEL)

6.X, 7.X

Ubuntu14.04 LTS, 16.04, 18.04
Amazon Linux

2015.03, 2015.09, 2016.03, 2016.09, 2017.03, 2017.09, 2018.03

Oracle Linux6.X, 7.X
Windows

2008, 2008 R2, 2012, 2012 R2, 2016 Standard, 2016 Datacenter, 2016 Essentials

For Windows users, PowerShell 3 and the latest version of .NET 4.X must be installed.

For Windows 2012 users, when you install the Armor Agent, the corresponding Trend Micro agent may cause your system to reboot. Trend Micro is currently researching this issue.


Browser support

The Armor Management Portal (AMP) supports the current version of the following browsers:

  • Chrome
  • Firefox
  • Internet Explorer
  • Safari
     

Armor cannot guarantee that previous versions will be supported.


Resource requirements

RequirementWindows InstanceLinux Instance
CPU2 Cores1 Core
RAM2GB1GB
Disk Space3GB3GB
BandwidthEstimated 50-100Kb per minute, based on the logs generated in your system.


Firewall rules

This topic only applies to Armor Anywhere users.

The following ports will need to be opened for each server registered with Armor Anywhere.

Inbound / OutboundService / PurposePortDestination
OutboundArmor Agent443/tcp
  • 146.88.106.210  
    • (api.armor.com)
OutboundMalware Protection, FIM, IDS

4119/tcp

  • 146.88.106.197  
    • (1a.epsec.armor.com)
  • 146.88.114.197  
    • (2a.epsec.armor.com)
  • 35.163.135.130
  • 34.214.246.111
  • 52.13.172.208
    • (3a.epsec.armor.com)
OutboundDSM4120/tcp
  • 146.88.106.197
    • (1b.epsec.armor.com)
  • 146.88.114.197
    • (2b.epsec.armor.com)
  • 35.163.135.130
  • 34.214.246.111
  • 52.13.172.208
    • (3a.epsec.armor.com)
OutboundRelay4122/tcp
  • 146.88.106.197
    • (1c.epsec.armor.com)
  • 146.88.114.197
    • (2c.epsec.armor.com)
  • 35.163.135.130
  • 34.214.246.111
  • 52.13.172.208
    • (3a.epsec.armor.com)
OutboundLog Management (Filebeat / Winlogbeat)515/tcp
  • 146.88.106.196  
    • (1a.log.armor.com)
  • 146.88.144.196  
    • (2a.log.armor.com)
OutboundMonitoring8443/tcp
  • 146.88.106.200  
    • (1a.mon.armor.com)
  • 146.88.114.200  
    • (2a.mon.armor.com)
OutboundRemote Access443/tcp
  • 146.88.106.216 
    • (1a.rs.armor.com)
  • 146.88.114.216
    • (alternate)
Outbound

Vulnerability Scanning

*443/tcp
  • endpoint.ingress.rapid7.com
    • (United States)
  • ca.endpoint.ingress.rapid7.com
    • (Canada)
  • eu.endpoint.ingress.rapid7.com
    • (Europe)
  • ap.endpoint.ingress.rapid7.com
    • (Japan)
  • au.endpoint.ingress.rapid7.com
    • (Australia)
Outbound

Vulnerability Scanning

*443/tcp
  • s3.amazonaws.com
    • (United States)
  • s3.ca-central-1.amazonaws.com
    • (Canada)
  • s3.eu-central-1.amazonaws.com
    • (Europe)
  • s3.ap-northeast-1.amazonaws.com
    • (Japan)
  • s3-ap-southeast-2.amazonaws.com
    • (Australia)

* The agent will perform a lookup to the applicable DNS entry, which may resolve to one of multiple Amazon Web Services based subnets. As a result, if your firewall does not support outbound filtering by domain name, then you may need to open all outbound traffic to 443/tcp to accommodate this service.


Pre-installation scripts

Before you install the Anywhere agent, you can run the following scrips to verify that your environment is compatible. 

Operating system

Script

  • Linux

    • CentOS

    • Red Hat Enterprise Linux

    • Ubuntu

    • Amazon Linux

    • Oracle

sudo curl -sSL https://get.core.armor.com/latest/armor_agent.sh | bash /dev/stdin
  • Windows 2012

  • Windows 2016

[Net.ServicePointManager]::SecurityProtocol = [Net.SecurityProtocolType]::Tls12; Invoke-WebRequest https://get.core.armor.com/latest/armor_agent.ps1 -outfile armor_agent.ps1 ; .\armor_agent.ps1
  • Windows 2008
[Net.ServicePointManager]::SecurityProtocol = [Net.SecurityProtocolType]::Tls12; Import-Module bitstransfer; start-bitstransfer -source https://get.core.armor.com/latest/armor_agent.ps1 -destination . ; .\armor_agent.ps1

Related documentation

At a high-level, to install Armor Anywhere, including the agent, you must:  

  1. Review requirements, especially the firewall rules

  2. Complete your account signup

  3. Download and install the agent

  4. Test and verify the agent's connection

  5. Configure your AMP notification preferences

To learn how to install Armor Anywhere, see Install Armor Anywhere






In this topic



Have a suggestion for the Armor Knowledge Base? Send a message to kb@armor.com.