
AndreLocker (Customer) asked a question.
After installing the RSA MFA Agent on a windows servers, we ran a port scan and found TCP-400 open, the process name is work-sol.
Has anyone seen this before ? is that normal expected behaivour after the installation is completed ?
Has anyone seen this before ? is that normal expected behaivour after the installation is completed ?
We've been running MFA Agent since the start & most of the deployments are v2.5 in which I'm not finding any scenarios of what you're stating.
Only thing that gives a hint of Workstation Solutions port 400 is in some Western Michigan University doc.
@johnneset (Customer) , thanks for the research!
@AndreLocker (Customer), per IANA, port 400 is assigned to Oracle Secure Backup. Do you use this in your environment?
Port 400 is not used by Authentication Manager nor by ID Plus.
Sorry misspoke, i'm actually seeing the port open on the RSA Virtual appliance, not the windows servers.
Can confirm that scenario that AM servers are listening on port 400.
Expecting Erica/staff will tell you what I'm thinking which is to submit this scenario as a support ticket with your findings & possible timeline vs community.
@AndreLocker (Customer) ,
Exactly what @johnneset (Customer) said (thanks John!).
Please open a support case with results of running sudo ss -tulnp and sudo netstat -tunlp along with an explanation of what is happening on your servers.