- Primeros pasos
- Requisitos
- Mejores prácticas
- Instalación
- Actualizando
- Servidor de identidad
- Solución de problemas de errores de inicio
Configuración del cortafuegos
Puertos de firewall necesarios y referencia de comunicación de red para implementaciones de Orchestrator
Para una implementación de Orchestrator que funcione correctamente, deberás comprobar que todos los puertos necesarios estén abiertos en tu cortafuegos para permitir la comunicación entre todos los componentes, como se indica en este este gráfico:
Figura 1. Diagrama de red de UiPath Orchestrator
A continuación se describe cada puerto y su respectivo uso:
443: comunicación entre usuarios y Orchestrator con los Robots conectados.Puedes seleccionar un puerto HTTPS diferente para Orchestrator, si así lo prefieres.Nota:Este puerto está abierto de forma predeterminada, a menos que su administrador de seguridad lo cierre.
1433: el puerto predeterminado para la comunicación entre Orchestrator y la máquina del servidor SQL. Puedes seleccionar un puerto diferente para que esté abierto en el cortafuegos.10000: comunicación entre Orchestrator y el HAA.9200: comunicación entre Orchestrator y el servidor de Elasticsearch.Nota:Este puerto solo puede abrirse para Orchestrator, ya que ninguna otra máquina puede acceder al servidor de Elasticsearch directamente.
9300: comunicación entre los nodos de Elasticsearch.5601: un puerto predeterminado utilizado por Kibana. Debe estar abierto en la máquina donde está instalado Kibana.
No aparece en la imagen anterior
3389: obligatorio para la automatización de RDP, necesario para HD Robots.80: obligatorio para el servicio web de Webhooks.
Conexiones salientes
A standalone Orchestrator installation serves the host Libraries feed from inside Orchestrator, using the activity packages that come with the installer, and needs no outbound internet access for it. If you point the Libraries feed at the official UiPath® feed instead, Orchestrator and the robot machines reach that feed over the internet. If your network restricts outbound traffic to an allowlist, the following hostnames must then be on it.
| NombreDelHost | Protocolo | Puerto | Aplicación | Utilizado para |
|---|---|---|---|---|
pkgs.uipath.com | TCP | 443 | Https | The official UiPath® package feed, at https://pkgs.uipath.com/official/index.json. This is the new address of the feed. |
pkgs.dev.azure.com | TCP | 443 | Https | The previous, Azure DevOps-hosted address of the official UiPath® package feed, at https://pkgs.dev.azure.com/uipath/Public.Feeds/_packaging/UiPath-Official/nuget/v3/index.json. The same feed also answers on uipath.pkgs.visualstudio.com, so allow the address your Libraries feed is configured with. It stays required until your deployment moves to the new address. |
These rules apply to the Orchestrator server nodes, which read the feed to list packages on the Libraries page, and to the robot machines, which download packages directly from the feed address that Orchestrator sends them.
You set the feed from the Deployment tab of the host or tenant settings. For the available feed types, see About Libraries and Settings - Tenant Level.
pkgs.uipath.com is the specific host that serves the official feed, and it is the entry used across the UiPath® documentation. A broader *.uipath.com rule also covers it, along with every other UiPath® endpoint, if your network policy favors domain-level rules.