<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: E-Series disable HTTP in EF &amp; E-Series, SANtricity, and Related Plug-ins</title>
    <link>https://community.netapp.com/t5/EF-E-Series-SANtricity-and-Related-Plug-ins/E-Series-disable-HTTP/m-p/154096#M821</link>
    <description>&lt;P&gt;So is the open http port 80 just forwarding requests to https port 443/8443 ?&lt;/P&gt;
&lt;P&gt;A quick nmap scan shows all three ports (80,443,8443) as open...&lt;/P&gt;</description>
    <pubDate>Wed, 05 Feb 2020 09:47:34 GMT</pubDate>
    <dc:creator>gfz-marco</dc:creator>
    <dc:date>2020-02-05T09:47:34Z</dc:date>
    <item>
      <title>E-Series disable HTTP</title>
      <link>https://community.netapp.com/t5/EF-E-Series-SANtricity-and-Related-Plug-ins/E-Series-disable-HTTP/m-p/154062#M819</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is it possible to disable HTTP on E-Series Systems?&lt;/P&gt;
&lt;P&gt;We have different models that we access through https, so an open http port may pose a security issue that we want to avoid.&lt;/P&gt;</description>
      <pubDate>Wed, 04 Jun 2025 11:20:11 GMT</pubDate>
      <guid>https://community.netapp.com/t5/EF-E-Series-SANtricity-and-Related-Plug-ins/E-Series-disable-HTTP/m-p/154062#M819</guid>
      <dc:creator>gfz-marco</dc:creator>
      <dc:date>2025-06-04T11:20:11Z</dc:date>
    </item>
    <item>
      <title>Re: E-Series disable HTTP</title>
      <link>https://community.netapp.com/t5/EF-E-Series-SANtricity-and-Related-Plug-ins/E-Series-disable-HTTP/m-p/154070#M820</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;By default, E-Series uses&lt;STRONG&gt; https&lt;/STRONG&gt; for internal web services so it is safe.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am not an E-Series person but in general we call http/https connections as 'Web services' atleast in ONTAP and I believe also in E-Series (Santricity). In general we use these for API purposes for monitoring and/or managing purposes.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;A&lt;U&gt;ccording to this PDF:4736&lt;/U&gt;&lt;BR /&gt;There are &lt;U&gt;two implementations of Web Services&lt;/U&gt;; one is embedded on the controller, and one is a separate proxy that can be installed on Linux or Windows.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;1) For the embedded Web Services implementation, the port on the controller cannot be changed; it defaults to port 8443 for secure connections.&lt;/P&gt;
&lt;P&gt;https://&amp;lt;controller&amp;gt;:&amp;lt;port&amp;gt;/devmgr/ (This is&lt;STRONG&gt; https and cannot be changed&lt;/STRONG&gt;, hence you need not worry)&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;2) For the Proxy Web services (Win/Linux), you can choose between http or https:&lt;/P&gt;
&lt;P&gt;http[s]://&amp;lt;server&amp;gt;:&amp;lt;port&amp;gt;/devmgr/&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The file that controls this 'proxy' port for proxy-server is this: &lt;U&gt;wsconfig.xml&lt;/U&gt; file&lt;BR /&gt;located at: C:\Program Files\NetApp\SANtricity Web Services Proxy&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For more info:&lt;BR /&gt;&lt;A href="https://www.netapp.com/us/media/tr-4736.pdf" target="_blank"&gt;https://www.netapp.com/us/media/tr-4736.pdf&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Tue, 04 Feb 2020 17:07:40 GMT</pubDate>
      <guid>https://community.netapp.com/t5/EF-E-Series-SANtricity-and-Related-Plug-ins/E-Series-disable-HTTP/m-p/154070#M820</guid>
      <dc:creator>Ontapforrum</dc:creator>
      <dc:date>2020-02-04T17:07:40Z</dc:date>
    </item>
    <item>
      <title>Re: E-Series disable HTTP</title>
      <link>https://community.netapp.com/t5/EF-E-Series-SANtricity-and-Related-Plug-ins/E-Series-disable-HTTP/m-p/154096#M821</link>
      <description>&lt;P&gt;So is the open http port 80 just forwarding requests to https port 443/8443 ?&lt;/P&gt;
&lt;P&gt;A quick nmap scan shows all three ports (80,443,8443) as open...&lt;/P&gt;</description>
      <pubDate>Wed, 05 Feb 2020 09:47:34 GMT</pubDate>
      <guid>https://community.netapp.com/t5/EF-E-Series-SANtricity-and-Related-Plug-ins/E-Series-disable-HTTP/m-p/154096#M821</guid>
      <dc:creator>gfz-marco</dc:creator>
      <dc:date>2020-02-05T09:47:34Z</dc:date>
    </item>
    <item>
      <title>Re: E-Series disable HTTP</title>
      <link>https://community.netapp.com/t5/EF-E-Series-SANtricity-and-Related-Plug-ins/E-Series-disable-HTTP/m-p/154123#M822</link>
      <description>&lt;P&gt;I think you are correct. It does say security is minimal for proxy implementations.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Take a look here, &lt;A href="https://www.netapp.com/us/media/tr-4736.pdf" target="_blank"&gt;https://www.netapp.com/us/media/tr-4736.pdf&lt;/A&gt;&lt;BR /&gt;Comparison of Embedded and Proxy Implementations : Page-7 | section 3.1&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;It says:&lt;/STRONG&gt;&lt;BR /&gt;1) Proxy = security is minimal&lt;BR /&gt;Reason: Developers can get started with the API quickly and easily. &lt;BR /&gt;Can you change ?: If desired, you can configure the proxy with the same security profile as the embedded version.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;2) Embedded = Security is High&lt;BR /&gt;Reason: Security settings are high because the API runs directly on the controllers.&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Interesting - I guess embedded is when you access the single E-SERIES storage system directly. With proxy I guess you can manage multiple E-SERIES systems.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Highlight for me is : Document says - If desired, you can configure the proxy with the same security profile as the embedded version. So it is indicating about hardening the proxy security, but it does not discusses it further.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;My suggestion will be:&lt;/P&gt;
&lt;P&gt;1) Give this a try:&lt;/P&gt;
&lt;P&gt;Open this file wsconfig.xml file:&lt;BR /&gt;I guess these are the default ports for https &amp;amp; http, comment out the http line there:&lt;/P&gt;
&lt;P&gt;&amp;lt;sslport clientauth=”request”&amp;gt;8443&amp;lt;/sslport&amp;gt;&lt;BR /&gt;## &amp;lt;port&amp;gt;8080&amp;lt;/port&amp;gt;&lt;/P&gt;
&lt;P&gt;save,close &amp;amp; restart service.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Try if you can access it via http, Run the nmap again to scan for ports.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;2) If you can still see http/8080 ports , open a ticket with NetApp and to find out 'how to make the proxy secure/https.'&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 05 Feb 2020 22:57:18 GMT</pubDate>
      <guid>https://community.netapp.com/t5/EF-E-Series-SANtricity-and-Related-Plug-ins/E-Series-disable-HTTP/m-p/154123#M822</guid>
      <dc:creator>Ontapforrum</dc:creator>
      <dc:date>2020-02-05T22:57:18Z</dc:date>
    </item>
  </channel>
</rss>

