PowerStore Planning Guide
PowerStore Planning Guide
Planning Guide
Version 4.x
July 2024
Rev. A11
Notes, cautions, and warnings
NOTE: A NOTE indicates important information that helps you make better use of your product.
CAUTION: A CAUTION indicates either potential damage to hardware or loss of data and tells you how to avoid
the problem.
WARNING: A WARNING indicates a potential for property damage, personal injury, or death.
© 2020 - 2024 Dell Inc. or its subsidiaries. All rights reserved. Dell Technologies, Dell, and other trademarks are trademarks of Dell Inc. or its
subsidiaries. Other trademarks may be trademarks of their respective owners.
Contents
Additional Resources.....................................................................................................................5
Chapter 1: Introduction................................................................................................................. 6
Introduction to PowerStore .............................................................................................................................................6
Appliances........................................................................................................................................................................6
PowerStore Clusters..................................................................................................................................................... 7
Planning and installation overview...................................................................................................................................7
Contents 3
Appendix A: Port usage............................................................................................................... 27
Appliance network ports.................................................................................................................................................. 27
Appliance network ports related to file........................................................................................................................30
4 Contents
Preface
As part of an improvement effort, revisions of the software and hardware are periodically released. Some functions that are
described in this document are not supported by all versions of the software or hardware currently in use. The product release
notes provide the most up-to-date information about product features. Contact your service provider if a product does not
function properly or does not function as described in this document.
NOTE: PowerStore X model customers: For the latest how-to technical manuals and guides for your model, download the
PowerStore 3.2.x Documentation Set from the PowerStore Documentation page at dell.com/powerstoredocs.
Additional Resources 5
1
Introduction
Use this document to better understand the installation process and prepare your site and workstation for a successful
PowerStore implementation. This chapter includes the following topics:
Topics:
• Introduction to PowerStore
• Planning and installation overview
Introduction to PowerStore
PowerStore achieves new levels of operational simplicity and agility. It uses a container-based microservices architecture,
advanced storage technologies, and integrated machine learning to unlock the power of your data. A versatile platform
with a performance-centric design, PowerStore delivers multidimensional scale, always on data reduction, and support for
next-generation media.
PowerStore brings the simplicity of public cloud to on-premises infrastructure, streamlining operations with an integrated
machine learning engine and seamless automation, while offering predictive analytics to monitor, analyze, and troubleshoot the
environment. PowerStore is highly adaptable, providing the flexibility to host specialized workloads directly on the appliance
and modernize infrastructure without disruption. It also offers investment protection through flexible payment solutions and
data-in-place upgrades.
PowerStore T model appliances (500, 1000, 1200, 3000, 3200, 5000, 5200, 7000, 9000, and 9200) and PowerStore Q model
appliances (3200) are storage-centric, and enable you to manage and provision block and file storage to external hosts. During
initial configuration, you can choose to configure an appliance for unified (block and file) or block optimized (block-only)
storage.
PowerStore 3200Q model appliances are populated with a minimum of 11 large capacity quad-level cell (QLC) SSDs. The
supported QLC SSDs are 15 TB in size and have a lower cost per Gigabyte than the triple-level cell (TLC) SSDs used in
PowerStore T model appliances.
Appliances
A PowerStore appliance is a preconfigured infrastructure component that has both storage and compute resources. An
appliance consists of:
● Base enclosure – Holds up to 25 drives (minimum of six drives) and includes two nodes for high availability with data
protection that is implemented across the nodes.
● Expansion enclosures – Enable you to add more drives and increase the storage capacity for the appliance. You can add up
to three expansion enclosures.
○ The PowerStore 500T supports the NVMe expansion enclosure.
○ All other PowerStore models support the NVMe expansion enclosure or the SAS expansion enclosure.
NOTE: Mixing NVMe expansion enclosures and SAS expansion enclosures in the same appliance is not supported.
Go to Hardware > Appliances to review the overall health of the appliances in the cluster and collect support materials for the
appliances for troubleshooting issues.
Click the appliance name to launch the Appliance details page where you can review the metrics, alerts, and health information
of the appliance and its components. Use the More Actions options on the details page to collect support materials for the
appliance for resolving minor issues.
6 Introduction
PowerStore Clusters
A PowerStore cluster is a group of one to four appliances acting as a single component for resource management, efficiency,
and availability purposes. A cluster can contain up to four appliances. In this release, you can only have appliances of the same
configuration in one cluster.
The following diagram shows the components of a cluster:
Introduction 7
Once the appliance arrives:
See the PowerStore Quick Start Guide to:
1. Unbox and install your appliance (base enclosure and expansion enclosures).
2. Connect the enclosures to the network, and power on.
3. Start the initial configuration process. For more information, see the PowerStore Networking Guide for Initial Deployment .
The PowerStore Installation and Service Guide also includes installation instructions for later reference.
NOTE: Either during the initial configuration process or once you log in to PowerStore Manager, it is recommended that
you enable the Support Connectivity feature to accelerate problem diagnosis, perform troubleshooting, and help speed time
to resolution. For more information, see Support Connectivity.
8 Introduction
2
Site Planning
This chapter contains the following topics:
Topics:
• Rack space guidelines
• Technical specifications
Technical specifications
Review the technical specifications to plan and prepare the site where you are installing the PowerStore cluster.
Site Planning 9
Table 2. Base enclosure dimensions and weight (continued)
Dimension Value
Depth 79.5 cm (31.3 in)
NOTE: The weight does not include mounting rails. Allow 3.6 kg (8 lbs) for a rail set.
10 Site Planning
Power requirements for the base enclosure
Power requirements vary depending on system configuration, loading, and environmental conditions. The table below describes
the maximum expected power draw. To estimate power consumption values for your specific environment, use the Dell Power
Calculator.
Site Planning 11
Table 6. Power requirements for x200 models (continued)
Requirement 1200T 3200T 3200Q 5200T 9200T
AC Inlet type IEC320-C14 or IEC320-C20 appliance coupler per power zone IEC320-C20
appliance coupler
per power zone
Normal input 47 Hz–63 Hz
frequency
Maximum inrush 45 Apk "cold" per line cord at any line voltage
current
AC protection 20 A fuse on each power supply, single line
Ride-through 10 ms min
time
Current sharing ± 5 percent of full load between power supplies
Startup Surge 120 Apk "hot" per line cord, at any line voltage
Current
12 Site Planning
Power requirements for PowerStore 500T
Power requirements vary depending on system configuration, loading, and environmental conditions. The table below provides
worst case data. To estimate power consumption values for your specific environment, use the Dell Power Calculator.
Site Planning 13
Table 10. High ambient temperature shutdown (continued)
Ambient temperature Hardware fault Consequence
returns to less than 45° C (113° F) , the system
powers on.
Any The three hottest drives have an The system shuts down after five minute timer
average temperature of 50° C (122° expires.
F)
Any Two fans fault The system shuts down after five minute timer
expires.
14 Site Planning
Table 12. Power requirements (continued)
Requirement Description
Power factor 0.92 minimum at full load 100V/200V
Heat dissipation (operating maximum at 200 2.27 x 10 6 J/hr (2,150 Btu/hr)
VAC)
In-rush current 82A max for 1/2 Line cycle per line cord at 200 VAC
Startup surge current 100A Max for up to 125uSec
AC protection 15 A fuse on each power supply, both Line and Neutral
AC inlet type IEC320-C14 appliance coupler, per power zone
Ride-through time 10-millisecond minimum
Current sharing +/- 5% of full load between power supplies
Site Planning 15
Table 15. Base enclosure airflow
Max Airflow CFM Min Airflow CFM Max Power Usage (Watts)
165 CFM 50 CFM 850 W
Environmental recovery
If the system exceeds the maximum ambient temperature by approximately 10°C (18°F), the nodes in the system begin an
orderly shutdown that saves cached data, and then shut themselves down. Link control cards (LCCs) in each expansion
enclosure in the system power down drives but remain powered on.
If the system detects that the temperature has dropped to an acceptable level, it restores power to the base enclosures and the
LCCs restore power to their drives.
16 Site Planning
Shock and vibration
Products have been tested to withstand the shock and random vibration levels.
The levels apply to all three axes and should be measured with an accelerometer on the equipment enclosures within the cabinet
and shall not exceed any of the values in this table.
Systems that are mounted on an approved package have completed transportation testing to withstand shock and vibrations in
the vertical direction only. The levels shall not exceed the values in this table.
Site Planning 17
3
Licensing and Workstation Requirements
This chapter includes the following topics:
Topics:
• PowerStore licensing
• Workstation requirements
PowerStore licensing
PowerStore license is automatically obtained and installed on all the appliances in your cluster during initial configuration. It
includes access to all features available with PowerStore.
To obtain licenses automatically during and after initial configuration, ensure that the port 443 is open. The cluster
communicates with the Dell Electronic Licensing Management System (ELMS) using port 443 to obtain the license file. If
there is an issue obtaining the license file, your cluster will operate in a 30-day trial period. The system attempts to obtain a
license automatically every 24 hours. To review the status of your license, in PowerStore Manager, go to Settings > Licensing.
An Active status indicates that all the appliances in the cluster have a valid license.
If you do not have an active license yet, you can click Refresh on the PowerStore Licensing page to try obtaining the license
automatically. Or, click Install License to manually install the license.
NOTE: You do not need a separate PowerStore license when installing PowerStore operating environment software and
firmware upgrades.
Workstation requirements
Once you complete the physical installation process, use a Windows-based workstation or virtual machine to discover the
appliances and begin the initial configuration. For workstation and virtual machine requirements, see the PowerStore Simple
Support Matrix, which can be downloaded from the PowerStore Info Hub.
NOTE: Secure Remote Services and SupportAssist Enterprise capabilities are now part of secure connect gateway.
Support Connectivity 19
Connectivity from PowerStore Manager from the Settings page or through the Initial Configuration Wizard (ICW), the System
Checks tab on the Monitoring page shows the results of the system check. The profile reflects Support Connectivity.
When Run System Check is selected, the values for Profile and Last Run change and reflect that a system check is running.
Once the results are available, both values are updated to reflect the Service Engagement profile, and the last run value. The
Job Details for PowerStore Manager reflect the output of the invoked system check. If there were failures during the check,
they are shown in the output of the Job Details.
NOTE: The precheck can also be invoked from the svc_health_check service script. Also, the remote_support
REST API includes a precheck_override option that allows users to skip the Support Connectivity precheck.
The connection status of Support Connectivity indicates both the state of the connection between PowerStore and your
service provider's backend Support services and the quality of service of the connection. The connection state is determined
over five minute periods and the quality of service of the connection is determined over 24 hour periods. The connection status
can appear as one of the following based on any of the appliances in the cluster:
● Unavailable – Connectivity data is unavailable. You may have lost contact with an appliance or Support Connectivity has
just been enabled and there is insufficient data to determine the state.
● Disabled – Support Connectivity has not been enabled.
● Not connected – Connectivity has been lost. Five consecutive keepalive failures have been detected.
● Reconnecting – PowerStore is attempting to reconnect after loss of connectivity. Five consecutive successful keepalive
requests are needed to transition back to a connected status.
The connection status can appear as one of the following based on the average of all the appliances in the cluster when
PowerStore is connected to your service provider backend Support services:
● Evaluating – The quality of service for the connection will be undetermined for the first 10 minutes after Support
Connectivity is first initialized.
● Good – 80% or more of the consecutive keepalive requests were successful.
● Fair – Between 50% and 80% of the consecutive keepalive requests were successful.
● Poor – Less than 50% of the consecutive keepalive requests were successful.
20 Support Connectivity
Support Connectivity remote support
Support Connectivity and its remote support feature are disabled by default. As part of enabling Support Connectivity and to
use its remote support services, you must accept the End User License Agreement (EULA). Otherwise, Support Connectivity
cannot be enabled and its remote support feature cannot be used. Once the Support Connectivity EULA is accepted, Support
Connectivity and its remote support feature can be configured.
Enabling the remote support feature allows support engineers who are authorized by your service provider to securely access
and troubleshoot your system. This feature allows your service provider's support personnel to remotely log in to the system
to address issues that may occur. Support personnel can remotely log in to your system through SSH or PowerStore Manager.
Your support contract determines what and when support personnel are allowed to do. By enabling this feature, you grant
access to your system so that troubleshooting and fixing issues can happen as they occur. For example, if a call home, data
unavailable or loss, or any otherwise abnormal event occurs, this feature allows your service provider's support personnel to
respond faster to correct issues.
Support Connectivity 21
● Network traffic (HTTPS) must be permitted on port 9443 between the appliance and the secure connect gateway server.
Allow access to ports 22, 443, and 8443 between PowerStore and the secure connect gateway server for PowerStore
Manager and SSH accessing. Also, set a reject rule between the appliance and outbound access for ports 443 and 8443 to
ensure that the PowerStore appliance directs traffic to the secure connect gateway server.
● The secure connect gateway server must be version 5.00.06.xy or later.
● Ensure that the PowerStore cluster is running PowerStore operating system version 3.0 or later.
NOTE: Never manually add or remove an appliance from the gateway server. Only add or remove an appliance from the
PowerStore Manager.
22 Support Connectivity
Configure the initial setup of Support Connectivity
Prerequisites
To enable Support Connectivity for either the Connect Directly or Connect via Secure Connect Gateway option,
unrestricted access to Dell Support (esrs3-core.emc.com and esrs3-coredr.emc.com) over the Internet using HTTPS (for
nonproxy environments) is required.
When configuring Support Connectivity, if your firewall is configured to inspect TLS certificates for verification, the associated
Certificate Authority certificate files must be added to the list of trusted authorities included in your firewall. The following
required certificate files can be downloaded from their respective link:
● Download the DellSecureRemoteServicesRootCA.crt certificate file from Dell.
● Download the ESRS2CA.cer certificate file from Dell.
Steps
1. Click Settings and under Support select Support Connectivity.
The Support Connectivity page appears with Support Contacts selected.
2. Type in the required information.
NOTE: The First Name and Last Name of the Primary Contact are mandatory, and the Email or Phone (at least
one is required) of the Primary Contact. Providing information for the Secondary Contact is optional. Your Support
Connectivity contact information is critical for a quick response to support issues and must be accurate and current.
Also, you can view the Privacy Policy and the Telemetry Notice by selecting the related link in the Support Contacts
introductory text.
Support Connectivity 23
7. Select the Type of Support Connectivity option that you intend to use from the list.
8. Depending on which type of Support Connectivity option you select, do one of the following:
● For the Connect via Secure Connect Gateway option:
○ Specify the IP address of each gateway server, the primary server and, if available, the backup server.
NOTE: Each gateway server must be up and running before you configure your appliance to use it.
○ Port 9443 is the default port and cannot be changed.
● For the Connect Directly option:
○ If your network connection uses a proxy server, specify the IP address of the proxy server.
NOTE: The proxy server must be up and running before you configure your appliance to use it.
○ Use the controls to select the number of the port that will be used to connect to the proxy server in your network.
NOTE: Port 3128 is the default that is used when the port is not specified and Support Connectivity is enabled
with Connect Directly and a firewall is employed between the appliance and a Proxy server. If the default or
user-specified port is closed, communication with the appliance through the port is not available.
9. Depending on which type of Support Connectivity option you select, do one of the following:
● For the Connect Directly option, go to the next step.
● For the Connect via Secure Connect Gateway option, select Test Connection for each configured gateway server to
check the status of the connection to the gateway server.
NOTE: If the connectivity status appears to remain as Transitioning and does not change after several minutes
(the time it should take to test connectivity), contact your service provider.
10. The Connect to CloudIQ checkbox is selected by default; if you do not want to send files to CloudIQ and be able to use the
Cybersecurity application, clear the checkbox; otherwise, leave the checkbox selected.
11. The Remote Support checkbox is selected by default; if you do not want to allow support engineers who are authorized by
your service provider to securely troubleshoot your system, clear the checkbox; otherwise, leave the checkbox selected.
12. Select Send Test Alert to send a test alert to your service provider to ensure end-to-end connectivity.
13. Select Apply to retain the Support Connectivity configuration information.
Steps
1. In PowerStore Manager, select Settings and, under Support, select Support Connectivity.
The Support Connectivity page appears.
2. To modify the configuration settings of Support Connectivity, do one or more of the following actions as needed:
NOTE: You must click Apply before you can navigate from either Support Contacts or Connection Type after
changes have been made under either tab; otherwise, a prompt appears asking whether to cancel the navigation move
or to discard the information that you typed in.
● Change or delete the information for the Primary Contact or Secondary Contact, or both.
NOTE: With PowerStore operating system 2.1. and later releases, this feature cannot be enabled unless the Primary
Contact information with the required values is provided. Also, the Primary Contact information can only be
deleted when the feature is disabled. The First Name and Last Name of the Primary Contact are mandatory,
as well as the Email or Phone (at least one is required) of the Primary Contact. Providing information for the
Secondary Contact is optional. Your Support Connectivity contact information is critical for quick response to
support issues and must be accurate and current. Also, you can view the Privacy Policy and the Telemetry Notice by
selecting the related link in the Support Contacts introductory text.
● Click the Enabled/Disabled control to enable or disable Support Connectivity.
24 Support Connectivity
NOTE: The connection status will not change until after you click Apply.
NOTE: With PowerStore operating system version 4.0 or later versions, Support Connectivity runs a precheck as
part of its enablement process to proactively confirm that it is ready to be enabled. If the precheck determines that
enabling Support Connectivity will fail, it remains disabled. Also, notifications are provided along with actionable steps
to take to remedy issues that are discovered during the precheck. See Support Connectivity enablement precheck
for more information about the Support Connectivity precheck.
● Change the Connection Type option you intend to use and provide any related information that is required.
○ For the Connect via Secure Connect Gateway option:
■ Specify the IP address of each gateway server, the primary server and, if available, the backup server.
NOTE: Each gateway server must be up and running before you configure your appliance to use it.
■ Port 9443 is the default port and cannot be changed.
○ For the Connect Directly option:
■ If your network connection uses a proxy server, specify the IP address of the proxy server.
NOTE: The proxy server must be up and running before you configure your appliance to use it.
■ Use the controls to select the number of the port that will be used to connect to the proxy server in your
network.
NOTE: Port 3128 is the default used when the port is not specified and Support Connectivity is enabled with
Connect Directly and a firewall is employed between the storage system and a Proxy server. If the default or
user-specified port is closed, communication with the storage system through the port will be unavailable.
● For the Connect via Secure Connect Gateway option, select Test Connection for the configured gateway servers to
check the status of the connection to the gateway servers.
NOTE: If the connectivity status appears to remain as Transitioning and does not change after several minutes
(the time it should take to test connectivity), contact your service provider.
● Send a test alert to your service provider to ensure end-to-end connectivity.
● Change the Connect to CloudIQ setting.
NOTE: To send files to CloudIQ and be able to use the Cybersecurity application, select the checkbox; otherwise,
clear the checkbox.
● Change the setting for Remote Support.
NOTE: If you want to allow support engineers authorized by your service provider to securely troubleshoot your
system, select the checkbox; otherwise, clear the checkbox.
3. Select Apply to retain the Support Connectivity configuration information.
CloudIQ
CloudIQ is a cloud-based application that allows users to monitor system performance in near real-time across multiple
PowerStore clusters and perform basic service actions. CloudIQ uses logs, system configuration, alerts, performance metrics,
capacity metrics, and capacity forecast data that Support Connectivity collects from PowerStore clusters. CloudIQ provides
dashboard views of all connected clusters, showing key information such as performance, capacity trending, and capacity
predictions. CloudIQ also provides proactive serviceability that informs the user about issues before they occur and provides the
user with simple, guided remediation.
NOTE: Support Connectivity must be enabled on the cluster to send data to CloudIQ.
Users can enable CloudIQ during the configuration of Support Connectivity on a PowerStore cluster. CloudIQ support is enabled
by default when any Support Connectivity option is enabled. When Support Connectivity and CloudIQ are enabled, CloudIQ
can be launched directly from PowerStore Manager. Users can also log in to the Dell site for CloudIQ with their valid service
credentials to view their PowerStore clusters in CloudIQ.
NOTE: Once CloudIQ is enabled, it is possible to disable Support Connectivity without changing the CloudIQ setting.
Without Support Connectivity, data is not collected and sent to CloudIQ, but if Support Connectivity is re-enabled, the
system remembers the CloudIQ setting and immediately resumes sending data to CloudIQ. Disabling CloudIQ support does
not disable the transfer of service-related telemetry data and data proactive collections that are provided through Support
Connectivity.
Support Connectivity 25
System Health
NOTE: This feature is only applicable when Support Connectivity is enabled on the cluster and a bi-directional connection
exists between PowerStore and CloudIQ.
System Health is shown in the Overview tab of the Dashboard page in PowerStore Manager. The health score provides an
insight into how the system is performing. The health score is based on PowerStore alerts that are sent in the telemetry data.
System Health also includes five attributes that appear as icons for Components, Configuration, Capacity, Performance, and
Data Protection, respectively, along with issues and their associated remediation steps.
Cybersecurity
NOTE: Support Connectivity and CloudIQ must be enabled on the storage system to enable use of the Cybersecurity
application.
Cybersecurity is a software as a service cloud-based storage security analytics application. It provides security assessment
and measures the overall cybersecurity risk level of appliances using intelligent, comprehensive, and predictive analytics.
Cybersecurity uses Support Connectivity to collect system logs, system configurations, security configurations and settings,
alerts, and performance metrics from your PowerStore system.
26 Support Connectivity
A
Port usage
The following sections outline the collection of network ports and the corresponding services that may be found on the
appliance. The appliance functions as a network client in several circumstances, for example, in communicating with a vCenter
Server. In these instances, the appliance initiates communication and the network infrastructure will need to support these
connections.
NOTE: For additional information about ports, see KB article 000022861, PowerStore: User Network Firewall Rules Tool
- TCP/UDP Ports. The tool enables you to filter and review the list of firewall rules and ports that are relevant to your
PowerStore deployment.
Topics:
• Appliance network ports
• Appliance network ports related to file
Port usage 27
Table 18. Appliance network ports (continued)
Port Service Protocol Access Direction Description
communication with the appliance is not
available.
500 IPsec (IKEv2) UDP Bi-directional To make IPSec work through your
firewalls, open UDP port 500 and permit
IP protocol numbers 50 and 51 on both
inbound and outbound firewall filters.
UDP Port 500 should be opened to
allow Internet Security Association and
Key Management Protocol (ISAKMP)
traffic to be forwarded through your
firewalls. IP protocol ID 50 should be
set to allow IPSec Encapsulating Security
Protocol (ESP) traffic to be forwarded.
IP protocol ID 51 should be set to allow
Authentication Header (AH) traffic to be
forwarded. If closed, IPsec connection
between PowerStore appliances is not
available.
514 Remote Logging UDP Outbound Used by the appliance to send log
messages to remote syslog servers. If
closed, log messages cannot be sent to
remote syslog servers.
1468 Remote Logging TCP Outbound Used by the appliance to send log
messages to remote syslog servers. If
closed, log messages cannot be sent to
remote syslog servers.
2049 DDBoost/NFS TCP Bi-directional Main port used by NFS.
2051 DDBoost TCP Bi-directional Used only if replication is configured.
2052 DDBoost/NFS TCP Bi-directional Used by the DDboost protocol.
3033 Import TCP or UDP Outbound Required for storage import from legacy
EqualLogic Peer Storage and Dell
Compellent Storage Center systems.
3260 iSCSI TCP ● Inbound for Required to provide the following access
Host and ESXi to iSCSI services:
host access ● External host iSCSI access
● Bi-directional for ● External or PowerStore embedded
replication ESXi host iSCSI access
● Outbound ● Inter-cluster access for replication
storage for ● Storage import access from legacy
import EqualLogic Peer Storage, Dell
Compellent Storage Center, Unity, and
VNX2 systems
If closed, iSCSI services are not available.
Used by Data mobility to support
reasonable replication performance on
low-latency connection.
3261 Data mobility TCP Bi-directional Used by Data mobility to support
reasonable replication performance on
high latency connection.
4420 I/O Controller TCP ● Inbound for Required to provide the following access
Host and ESXi to NVMe/TCP I/O Controller services:
host access ● External host NVMe/TCP access
28 Port usage
Table 18. Appliance network ports (continued)
Port Service Protocol Access Direction Description
● Bi-directional for ● External or PowerStore embedded
replication ESXi host NVMe/TCP access
● Outbound for ● Inter-cluster access for replication
storage import ● Storage import access from legacy
EqualLogic Peer Storage, Dell
Compellent Storage Center, Unity, and
VNX2 systems
If closed, NVMe TCP I/O I/O Controller
services are not available.
5353 Multicast DNS UDP Bi-directional Multicast DNS query. If closed, mDNS
(mDNS) name resolution does not work.
5555 RSA SecurID TCP Outbound Used to communicate with an RSA
Authentication Authentication server when the RSA
SecurID Authentication feature is enabled.
If closed, authentication using the RSA
SecurID Authentication server does not
function. The default port set for RSA
SecurID Authentication is 5555.
8009 Discovery TCP Bi-directional Used by Data mobility to support
Controller reasonable replication performance on
high latency connection. If closed, NVMe
TCP Discovery services are unavailable.
8443 VASA Support TCP ● Inbound for ● Required for the VASA Vendor
Connectivity VASA Provider for VASA 3.0.
● Outbound for ● Required for the related Support
Support Connectivity Connect Home
Connectivity functions.
8443, 50443, Windows import TCP Outbound One of these ports must be open
55443, or 60443 host agent, Linux when importing data storage from legacy
import host agent, storage systems.
or VMware import
host agent
9443 Support TCP Outbound Required for Support Connectivity REST
Connectivity API related to Connect Home.
13333 Data mobility TCP Bi-directional Used by iBasic replication data traffic on
block replication network interfaces for
latency setting: Low
13334 Data mobility TCP Bi-directional Used by iBasic replication data traffic on
block replication network interfaces for
latency setting: Low_Medium
13335 Data mobility TCP Bi-directional Used by iBasic replication data traffic on
block replication network interfaces for
latency setting: Medium
13336 Data mobility TCP Bi-directional Used by iBasic replication data traffic on
block replication network interfaces for
latency setting: Medium_High
13337 Data mobility TCP Bi-directional Used by iBasic replication data traffic on
block replication network interfaces for
latency setting: High
Port usage 29
Appliance network ports related to file
The following table outlines the collection of network ports and the corresponding services that may be found on the appliance
that is related to file.
30 Port usage
Table 19. Appliance network ports related to file (continued)
Port Service Protocol Access Direction Description
162 or between SNMP UDP Outbound SNMP communications. If closed, storage
1024-49151 system alert mechanisms which rely on
SNMP are not sent. The default port set
for SNMP is 162.
389 LDAP TCP or UDP Outbound Unsecure LDAP queries. If closed,
Unsecure LDAP authentication queries are
not available. Secure LDAP is configurable
as an alternative.
445 Microsoft SMB TCP Inbound SMB (on domain controller) and SMB
connectivity port for Windows 2000
and later clients. Clients with legitimate
access to the appliance SMB services
must have network connectivity to the
port for continued operation. Disabling
this port disables all SMB-related
services. If port 139 is also disabled, SMB
file sharing is disabled.
464 Kerberos TCP or UDP Outbound Required for Kerberos authentication
services and SMB.
500 IPsec (IKEv2) UDP Bi-directional To make IPSec work through your
firewalls, open UDP port 500 and permit
IP protocol numbers 50 and 51 on both
inbound and outbound firewall filters.
UDP Port 500 should be opened to
allow Internet Security Association and
Key Management Protocol (ISAKMP)
traffic to be forwarded through your
firewalls. IP protocol ID 50 should be
set to allow IPSec Encapsulating Security
Protocol (ESP) traffic to be forwarded.
IP protocol ID 51 should be set to allow
Authentication Header (AH) traffic to be
forwarded. If closed, IPsec connection
between PowerStore appliances is not
available.
514 Remote Logging UDP Outbound Allows the appliance to send log
messages to remote syslog servers. If
closed, log messages cannot be sent to
remote syslog servers.
636 LDAPS TCP or UDP Outbound Secure LDAP queries. If closed, secure
LDAP authentication is not available.
1234 NFS mountd TCP or UDP Bi-directional Used for the mount service, which is
a core component of the NFS service
(versions 2, 3, and 4).
1468 Remote Logging TCP Outbound Allows the appliance to send log
messages to remote syslog servers. If
closed, log messages cannot be sent to
remote syslog servers.
2000 SSHD TCP Inbound SSHD for serviceability (optional)
2049 NFS I/O TCP or UDP Bi-directional Used to provide NFS services.
3268 LDAP UDP Outbound Unsecure LDAP queries. If closed,
Unsecure LDAP authentication queries are
not available.
Port usage 31
Table 19. Appliance network ports related to file (continued)
Port Service Protocol Access Direction Description
3269 LDAPS UDP Outbound Secure LDAP queries. If closed, Secure
LDAP authentication queries are not
available.
4000 STATD for NFSv3 TCP or UDP Bi-directional Used to provide NFS statd services. statd
is the NFS file-locking status monitor and
works with lockd to provide crash and
recovery functions for NFS. If closed,
NAS statd services are not available.
4001 NLMD for NFSv3 TCP or UDP Bi-directional Used to provide NFS lockd services.
lockd is the NFS file-locking daemon.
It processes lock requests from NFS
clients and works with the statd daemon.
If closed, NAS lockd services are not
available.
4002 RQUOTAD for TCP or UDP; Inbound; Outbound Used to provide NFS rquotad services.
NFSv3 UDP The rquotad daemon provides quota
information to NFS clients that have
mounted a file system. If closed, NAS
rquotad services are not available.
4003 XATTRPD TCP or UDP Inbound Required for managing file attributes in a
(extended file multi-protocol environment.
attribute)
4658 PAX (NAS server TCP Inbound PAX is an appliance archive protocol that
archive) works with standard UNIX tape formats.
5085, 5086 File replication TCP Bi-directional Used by management communication
(replication for file services file replication between
management clusters.
traffic)
8888 File replication TCP Bi-directional Used between replication network IP
(replication data addresses on the file services file
traffic) replication network interfaces.
10000 NDMP TCP Inbound ● Enables you to control the backup
and recovery of a Network Data
Management Protocol (NDMP) server
through a network backup application,
without installing third party software
on the server. In an appliance, the
NAS Server functions as the NDMP
server.
● If NDMP tape backup is not used, the
NDMP service can be disabled.
● The NDMP service is authenticated
with a username and password pair.
The username is configurable. The
NDMP documentation describes how
to configure the password for various
environments.
[10500,10531] NDMP reserved TCP Inbound For three-way backup/restore sessions,
range for NDMP NAS Servers use ports 10500–10531.
dynamic ports
12228 Antivirus checker TCP Outbound Required for the Antivirus checker
service service.
32 Port usage
B
Rack Space Planning Worksheets
This appendix includes the following worksheets:
Topics:
• Sample worksheet for rack space planning
• Blank worksheet for rack space planning
29 / 30
(2U)
27 / 28
(2U)
25 / 26
(2U)
23 / 24
(2U)
21 / 22 (2U)
19 / 20 (2U)
17 / 18 (2U)
15 / 16 (2U)
13 / 14 (2U)
11 / 12 (2U)
09 / 10
(2U)
07 / 08
(2U)
05 / 06
(2U)
03 / 04
(2U)
01 / 02 (2U) Reserved for Serviceability