14.3 Security Considerations

NetIQ recommends that you review the following considerations for deploying Identity Manager components on AWS cloud:

  • Identity Manager components are configured on a private network with no public access or attached to an Elastic IP address.

  • Web applications such as Identity Applications, Identity Reporting, or iManager are accessed through a load balancer.

  • Identity Manager components are configured to use a secured communication channel.

  • Data is configured on a separate encrypted EBS volume for each component.

  • The following ports are available on the Identity Manager servers to use within the subnet.

    Port

    Application

    636

    LDAP

    8543

    Identity Applications

    8643

    Identity Reporting

    5432

    PostgreSQL

    8443

    iManager