Designating Ports and Multicast Addresses
About Ports and Multicast Addresses
While you are creating operating system user accounts and groups, you need to review
the ports that the SAS servers, third-party servers, and spawners in your system use
by default. If any of these ports is unavailable, select an alternate port, and record
the new port in a :
You need to plan for designating Internet Protocol (IP) multicast addresses for all
machines in your SAS deployment. Multicasting simplifies the ongoing management and
deployment of SAS web applications by providing the flexibility to customize the SAS
and to distribute SAS web components to implement .
Multicast Address Considerations
By default, multicasting
is not used in the typical SAS deployment and SAS Remote Services
is turned off. If you created a custom application that uses SAS Remote
Services, you can use multicasting and enable SAS Remote Services.
The prompts you to supply a multicast address for intermachine communication. The wizard
provides you with a default multicast address that it generates based on the machine's
IP address and the Admin-Local scope that is recommended in RFC 3171 (IPv4) or RFC
4291 ().
A multicast group communication protocol is used to communicate among middle-tier
SAS applications in a single SAS deployment (the SAS applications connected to the
same ). The combination of multicast IP address and multicast UDP port should be different
for each SAS deployment and different from combinations used by other multicast applications
at your site.
The IP multicast address must be valid for IP multicasting. It should be in the range
224.0.0.0 to 239.255.255.255 for IPv4 or have the prefix ff00::/8 for IPv6. Typically,
the chosen IP multicast address is in the Admin-Local scope block, which
corresponds to 239/8 for IPv4 and ff14::/8 for IPv6. The sample address provided by
the SAS Deployment Wizard during configuration conforms to these standards. The address
should be unique to
SAS applications for the subnet that they are installed on.
The IP multicast UDP port should be open and usable on any machine on which a middle-tier
application is to be installed. It should not conflict with any previous TCP port
definitions such as the SAS Metadata Server. The multicast group communication is
intended to be used only within your data center
environment. Many sites keep their data center network separated from users via a
firewall that automatically isolates the multicast protocol. Alternatively, the time
to live (TTL) parameter can be used to restrict the scope of multicast communication.
Your network administrator can suggest a TTL setting to limit the scope of multicast.
The TTL parameter and the token option both have security implications.
The multicast TTL parameter
(default = 1, range = 0–255) affects the number of network
hops a multicast packet can take before being dropped. The TTL value
must be greater than or equal to the highest number of hops between
any two servers containing SAS products. In addition, some network
router documentation recommends that multicast datagrams with initial
TTL=0 are restricted to the same host, multicast datagrams with initial
TTL=1 are restricted to the same subnet, and multicast datagrams with
initial TTL=32 are restricted to the same site. Consult your network
router documentation or your network administrator to determine the
correct values for your environment.
Note: Make sure that all of the
machines in your SAS 9.4 deployment are members of the same subnet
or be sure to set the default TTL value to a number higher than 1.
The SAS Deployment Wizard lets you set the TTL value during SAS 9.4
deployment. For information about how to change this parameter after
deployment, see Administer Custom Applications in SAS Intelligence Platform: Middle-Tier Administration Guide.
Because the multicast protocol conveys , it is protected via . By default, the multicast group communication is protected only with a fixed encryption
key that is built into the software. If your middle tier is running in an environment
that is not well-isolated from user access, then you
might want better protection against eavesdroppers and unauthorized group participants.
In this case, choose an authentication token known only to your SAS middle-tier administrative
users. The authentication
token is a password-like string needed to connect to the multicast group and create
a site-specific encryption key.
The SAS Deployment Wizard default simplifies configuration by using the authentication
token that is built into the software. This option is best used in development and
other low-security environments. It might be appropriate in higher-security environments
where the multicast group communication is isolated from the user community (either
via a firewall or the TTL parameter) and where all data center administrative users
and operational users have sufficient security approval.
If your multicast group communication is not within a well-isolated data center environment
or if the security procedures at your site require protection for administrative users
and operational users in various roles, you should specify an authentication token
that is known only to the administrators of the SAS environment. The same token
must be supplied on each tier in the configuration.
By default, there is a code-level authentication token shared between all SAS middle-tier
applications to prevent access to the multicast
group from unauthorized listeners. If you choose to use a customized authentication
token, use the SAS Deployment Wizard to enter an authentication token value that meets
your organization's security guidelines.
In a multi-tier configuration, a prompt appears on each tier that has an application
participating in the SAS multicast group. You must provide the same authentication
token to each tier in the same SAS deployment (that is, each tier associated with
the same SAS Metadata Server).
Pre-installation Checklist for Ports for SAS
The following checklist indicates what ports are used
for SAS by default. Record information about them in this checklist.
SAS servers and their clients dynamically allocate
ports in the ephemeral ports range. Ephemeral ports are temporary ports that are assigned
by a
machine's IP stack from a designated range of ports that are specifically for temporary
use.
Each operating system assigns ephemeral ports from
a specific port range. By default, the range is 32768 to 65535 on Linux and AIX. On
Windows and
HP-UX, it is 49152 to 65535. In SAS 9.x environments,
SAS attempts to bind to an ephemeral port number in the 49152-65535 range. However,
testing is
needed to determine how the firewall functions with these ports.
These ranges are generally tunable by a system
administrator. Consult your operating system administration documentation for details
about
tuning your system. An ephemeral port becomes available for reuse when the connection
terminates.
Note: The SAS Deployment Wizard
prompts you for this information. You cannot complete the installation
without it.
On z/OS, the SAS servers
are configured and initially started as TSO processes invoked from
the USS shell using
/bin/tso. When these servers are started under TSO, the name is the user ID that is starting the server with a character appended to the
end. If your site uses the reserved ports facility in TCP/IP, each port definition
should include the started task and the Installer ID job name as valid users of this
port. You can use an asterisk (such as, sas*) in this definition. You can use a TCP
name instead of a hardcoded port. For more information about how to reserve the TCP
port for a particular SAS server, refer to your operating system documentation.On all operating systems, for the SAS server tier, the last digit of the default port
number reflects the configuration level that you select in the SAS Deployment Wizard.
For example, when you select Lev1, the default port for the SAS Metadata Server is 8561. If you select another level,
such as Lev2, the wizard changes
the default port to 8562.
Note: Deployment plans contain
more complete and up-to-date checklists. If you are a SAS solutions
customer, consult the pre-installation checklist provided by your
SAS representative for a complete list of ports that you must designate.
|
Server or Spawner
|
Default Port
Lev0–Lev9
|
Data Direction
|
Actual Port
|
|---|---|---|---|
|
Email Server
|
25
|
Outbound
|
|
|
HTTP Server
|
80 (Windows)
7980 (UNIX)
|
Inbound and outbound
|
|
|
HTTP Server (Secure
Port)
|
443 (Windows)
8343 (UNIX)
|
Inbound and outbound
|
|
|
SAS Scheduling Port
|
1964–1989
|
Inbound and outbound
| |
|
SAS Environment Manager
Agent Listening Port
|
2143–2152
|
Inbound and outbound
| |
|
SAS Environment Manager
(UDP multicast)
|
3029–3038
|
Inbound and outbound
| |
|
SAS Remote Services
Application
|
5090–5099
|
Inbound
|
|
|
SAS Web Infrastructure
Platform Data Server
|
5431–5440
|
Inbound and outbound
| |
|
SAS OLAP Server
|
5450–5459
|
Inbound and outbound
|
|
|
SAS Deployment Agent
|
5660–5669
|
Inbound and outbound
| |
|
Event Broker administration
|
6050–6059
|
Inbound
|
|
|
Web Application Server:
JMX Port (Server 1)
.
.
.
Web Application Server:
JMX Port (Server 15)
|
6969 (Single)
6969–6973 (Vertical
Clustering)
.
.
8369 (Single)
8369-8373 (Vertical
Clustering)
|
Inbound
| |
|
SAS Environment Manager
HTTP Port
|
7079–7088
|
Inbound and outbound
| |
|
SAS Environment Manager
HTTPS Secure Port
|
7442–7450
|
Inbound and outbound
| |
|
IP Multicast UDP Scheduler
Main Channel
|
7450–7459
|
Inbound and outbound
| |
|
IP Multicast UDP Scheduler
Hash Channel
|
7460–7469
|
Inbound and outbound
| |
|
SAS/CONNECT Spawner
|
7540–7549
|
Inbound
| |
|
SAS/CONNECT Server
|
7550–7559
|
Inbound and outbound
|
|
|
SAS Web Report Studio:
In-Process Scheduling Ports 1–3
|
7570–7599
|
Inbound and outbound
|
|
|
Web Application Server:
HTTP Port (Server 1)
.
.
.
Web Application Server:
HTTP Port (Server 15)
|
8080 (Single)
8080–8084 (Vertical
Clustering)
.
.
9480 (Single)
9480–9484 (Vertical
Clustering)
|
Inbound and outbound
| |
|
SAS Environment Manager
(embedded Tomcat server BIO SSL port)
|
8442–8451
|
Inbound
| |
|
Web Application Server
HTTPS Port (Server 1)
.
.
.
Web Application Server
HTTPS Port (Server 15)
|
8443 (Single)
8443–8448 (Vertical
Clustering)
.
.
9843 (Single)
9843–9848 (Vertical
Clustering)
|
Inbound and outbound
| |
|
Event Broker HTTP
|
8110–8119
|
Inbound
|
|
|
Operating System Services
Scheduling Server
|
8450–8459
|
Inbound
|
|
|
SAS/SHARE Server
|
8550–8559
|
Inbound
|
|
|
IP Multicast UDP Port
|
8560–8569
|
Inbound and outbound
|
|
|
SAS Metadata Server
|
8560–8569
|
Inbound and outbound
|
|
|
SAS Object Spawner:
Operator Port
|
8580–8589
|
Inbound
|
|
|
SAS Workspace Server
|
8590–8599
|
Inbound
|
|
|
SAS Stored Process Server: Bridge Port
|
8600–8609
|
Inbound
|
|
|
Stored Process Server:
Multibridge Connections
|
8610–8619
|
Inbound
|
|
|
SAS Stored Process Server: load balancing connection 2 (MultiBridge)
|
8620–8629
|
Inbound
|
|
|
SAS Stored Process Server: load balancing connection 3 (MultiBridge)
|
8630–8639
|
Inbound
|
|
|
SAS Pooled Workspace Server
|
8700–8709
|
Inbound
|
|
|
SAS Object Spawner:
PortBank Port 1
|
8800–8809
|
Inbound
|
|
|
SAS Object Spawner:
PortBank Port 2
|
8810–8819
|
Inbound
|
|
|
SAS Object Spawner:
PortBank Port 3
|
8820–8829
|
Inbound
|
|
|
SAS Workload Orchestrator
|
8900–8909
|
Inbound and outbound
| |
|
SAS Environment Manager
(embedded Tomcat server JMX port)
|
9360–9369
|
Inbound
| |
|
SAS Environment Manager
(embedded Tomcat server Base JMX port)
|
9360–9369
|
Inbound
| |
|
SAS Web Infrastructure
Platform Database Server (default instance)
|
9431–9440
|
Inbound and outbound
| |
|
SAS Environment Manager
(database port)
|
9432
|
Inbound and outbound
| |
|
SAS Job Monitor Database
Server
|
9451–9460
|
Inbound and outbound
| |
|
Data Remediation Data
Server
|
9831–9840
|
Inbound and outbound
| |
|
SAS Deployment Tester
Server
|
10020–10029
|
Inbound
| |
|
Data Management Data
Server
|
10441–10450
|
Inbound and outbound
| |
|
JMS Broker4
|
1883 (MQTT)
5672 (AMQP)
11098–11107 (JMX)
61613 (STOMP)
61614 (WebSockets)
61616 (OpenWire)
|
Inbound
| |
|
SAS Cloud Analytic Services
(CAS)2
|
19990–19999
|
Inbound and outbound
| |
|
DataFlux Data Management
Server
|
21036
|
Inbound and outbound
| |
|
Data Management Server
(WLP DataFlux port)
|
21037
|
Inbound and outbound
| |
|
DataFlux Web Studio
Server
|
21038
|
Inbound and outbound
| |
|
Process Orchestration
Server (for design)
|
21040–21049
|
Inbound and outbound
| |
|
SAS Visual Process Orchestration
Runtime Server for execution)
|
21050–21059
|
Inbound and outbound
| |
|
DataFlux Web Studio
Client
|
21079
|
Inbound and outbound
| |
|
Authentication Server
|
24139
|
Inbound and outbound
| |
|
Cache Locator Port
|
41414–41423
|
Inbound and outbound
| |
|
JMS Server Port
|
61615–61624
|
Inbound and outbound
| |
|
Cache Locator membership
port range
(TCP/UDP port range)1
|
1024–65535
|
Inbound and outbound
| |
|
TCP port for middle-tier
cache communications3
|
0–65535
|
Inbound and outbound
| |
| 1The range of ephemeral ports available for unicast UDP messaging and for TCP failure detection is in the peer-to-peer distributed system. These ephemeral ports are created from available ports in a system. | |||
| 2SAS Cloud Analytic Services (CAS) is installed with SAS Viya. | |||
| 3If set to zero, the operating system selects an available port. Each process on a machine must have its own TCP port. Note that some operating systems restrict the range of ports usable by non-privileged users and that using restricted port numbers can cause run-time errors in GemFire start-up. | |||
| 4You can manually change a port. | |||
Changing Ports for the JMS Broker Server
To change ports on the JMS Broker Server in the
ActiveMQ broker configuration file (SAS configuration
directory/level/Web/activemq/conf/activemq.xml),
perform the following step:
OpenWire
<transportConnectors> <transportConnector name="openwire" uri="tcp://0.0.0.0:61616" enableStatusMonitor="true"/> </transportConnectors>
Reference:
AMQP
<transportConnectors> <transportConnector name="amqp" uri="amqp://0.0.0.0:5672"/ </transportConnectors>
Reference:
STOMP
<transportConnectors> <transportConnector name="stomp" uri="stomp://localhost:61613"/> </transportConnectors>
Reference:
MQTT
<transportConnectors> <transportConnector name="mqtt" uri="mqtt://localhost:1883"/> </transportConnectors>
Reference:
WebSockets
<transportConnectors> <transportConnector name="ws" uri="ws://0.0.0.0:61614"/> </transportConnectors>
Reference:
For more information
about ActiveMQ configuration and transport configuration, see https://activemq.apache.org/configuring-transports.html and https://activemq.apache.org/xml-configuration.
Last updated: July 7, 2026