Join Server Ports to Get Targeted Information
Some servers dynamically assign individual server port numbers to their clients. Because PerformanceGuard stores information about IP traffic by server IP address, server port number and protocol, individually assigned server port numbers introduce large amounts of data that’s of no interest.
Solve this by joining ports. The benefits can be great:
How joined server ports work
Section titled “How joined server ports work”A joined server port entry consists of a server IP address, a protocol (TCP or UDP), a list of port ranges (the Port-Mapping) and a Virtual Port.
The frontend servers read the list of joined server ports when they start, and then again every minute. Every time a PerformanceGuard agent delivers an IP traffic report about a server, the frontend server checks if the server IP address and protocol match an entry in the list. If they match, and the reported server port number lies in one of the port ranges in the Port-Mapping, the frontend server changes the port number to the Virtual Port before it stores the data in the database.
This way hundreds, or even thousands, of dynamically allocated port numbers may be collapsed into just one static port number, and database disk usage is reduced by the same factor.
Example
Section titled “Example”An Oracle database server 10.0.1.3 installed on Windows by default allocates ports to clients dynamically. All of the clients first connect to port 1521, and then get individual port numbers (typically above 2000) to connect to and use for the rest of their sessions.
To join all TCP ports above 2000 on server 10.0.1.3 into TCP port number 1234, create a joined server port entry with these values:
| IP address | Virtual Port | Protocol | Port-Mapping |
|---|---|---|---|
| 10.0.1.3 | 1234 | TCP | 2000-65535 |
Manage joined server ports
Section titled “Manage joined server ports”To manage joined server ports, select ADMINISTRATION > Server / Port > Joined Server Ports.
The Existing tab lists already defined joined server ports in two tables, one for manually joined server ports and one for automatically joined server ports. Each table shows the Hostname, IP address, Virtual Port, Protocol and Port-Mapping of each entry. Use the edit and delete icons next to an entry to change or remove it.
Manually joined server ports
Section titled “Manually joined server ports”These are the entries that you have created yourself on the New tab (see the following).
Automatically joined server ports
Section titled “Automatically joined server ports”Every 15 minutes, PerformanceGuard automatically joins ports from servers that use many different ports. If there’s IP data in the database about a server (IP address) on at least as many ports above port 1024 as the configured threshold (see the following), using the same protocol (UDP or TCP), all ports from 1025 through 65535 on that server and protocol are automatically joined to the virtual port 0. PerformanceGuard only does this for servers and protocols that aren’t already in the list of joined server ports.
The job that does this is called Identify Servers with Dynamic Port Numbers. You can view its status on the Scheduled Jobs tab of ADMINISTRATION > Status > System Status.
There is no difference between the automatically joined server ports and the manually joined server ports other than the way they were created.
If you edit an automatically joined server port entry, and save the change, the entry will be moved to the manually joined server ports list.
Define new joined server ports
Section titled “Define new joined server ports”-
Select ADMINISTRATION > Server / Port > Joined Server Ports and then select the New tab.
-
Specify the IP address of the server, for example 10.10.110.218.
-
Specify the Virtual Port, that is the single port that you want the other ports to join into. Must be a number between 0 and 65535.
-
Select the required Protocol: TCP or UDP.
-
Specify the required Port-Mapping, that is the list of ports that you want to join into the virtual port. Specify the ports as a comma-separated list in which you can also include port ranges. Allowed characters: 0-9, commas, semicolons and dashes. Spaces aren’t allowed.
-
Click Create.
Configure number of ports required for auto-joining
Section titled “Configure number of ports required for auto-joining”The number of ports, from the same server (IP address) and the same protocol, required for PerformanceGuard to join the ports automatically, is configurable. To change the number of ports required, select ADMINISTRATION > Setup > Parameters and then select the Frontend tab.
The field Port spammer threshold defines the number of ports required for auto-joining. When you edit the field and click Save, the new value is written to the database at once, so the next time PerformanceGuard auto-joins server ports, this new number will be used to detect servers that use many ports. The default number is 20.
View status of automatically joined server ports
Section titled “View status of automatically joined server ports”You can use the System Status page (ADMINISTRATION > Status > System Status) to check whether automatically joined server ports have been detected. Look for Auto joined port spammers found.