| Server IP : 195.130.67.5 / Your IP : 216.73.217.127 Web Server : Microsoft-IIS/10.0 System : Windows NT WEBSERVER1 10.0 build 17763 (Windows Server 2016) i586 User : IUSR ( 0) PHP Version : 7.4.19 Disable Function : NONE MySQL : OFF | cURL : ON | WGET : OFF | Perl : OFF | Python : OFF | Sudo : OFF | Pkexec : OFF Directory : /Program Files/ArcGIS/LicenseManager/Documentation/lmrefguide/ |
Upload File : |
<!DOCTYPE html><html lang="en" xml:lang="en"><head> <META http-equiv="Content-Type" content="text/html"> <meta http-equiv="Content-Type" content="text/html; charset=utf-8"><meta name="content-language" content="en"><link href="rsrc/htmlhelp.css" rel="stylesheet" type="text/css"><link href="rsrc/htmlhelp_simpletoc.css" rel="stylesheet" type="text/css"><title> Configure ArcGIS License Manager to work through a firewall</title></head><!--Publication GUID: [GUID-BC990B43-3F11-4C46-9757-E4A61209745C]--><!--Topic GUID: [GUID-BA772F27-1840-4A68-BE47-A4C6927E9706]--><body><div id="wrapper"><div class="pageheader"></div><div class="toc"><ol> <li class='toc-title toc-level1'><h3>Introduction</h3></li> <li class='toc-level1'><i>•</i> <a href='007900000002000000.htm'>Welcome</a></li> <li class='toc-level1'><i>•</i> <a href='007900000003000000.htm'>License manager basics</a></li> <li class='toc-title toc-level1'><h3>Getting Started</h3></li> <li class='toc-level1'><i>•</i> <a href='00790000003p000000.htm'>ArcGIS License Manager system requirements</a></li> <li class='toc-level1'><i>•</i> <a href='007900000039000000.htm'>Supported software products</a></li> <li class='toc-level1'><i>•</i> <a href='007900000005000000.htm'>License manager installation and startup</a></li> <li class='toc-level1'><i>•</i> <a href='007900000006000000.htm'>Client machine setup using the ArcGIS Administrator</a></li> <li class='toc-level1'><i>•</i> <a href='00790000002q000000.htm'>Existing users</a></li> <li class='toc-title toc-level1'><h3>Administering the License Manager</h3></li> <li class='toc-level1'><i>•</i> <a href='007900000004000000.htm'>Using the ArcGIS License Server Administrator</a></li> <li class='toc-level1'><i>•</i> <a href='007900000007000000.htm'>Starting and stopping the License Manager</a></li> <li class='toc-level1'><i>•</i> <a href='007900000008000000.htm'>Checking the license server status</a></li> <li class='toc-level1'><i>•</i> <a href='007900000009000000.htm'>Configuring license borrowing</a></li> <li class='toc-level1'><i>•</i> <a href='00790000000m000000.htm'>Viewing the audit log</a></li> <li class='toc-level1'><i>•</i> <a href='00790000000n000000.htm'>Viewing license availability</a></li> <li class='toc-level1'><i>•</i> <a href='00790000000p000000.htm'>Authorizing additional features</a></li> <li class='toc-level1'><i>•</i> <a href='00790000000q000000.htm'>Diagnosing errors</a></li> <li class='toc-title toc-level1'><h3>ArcGIS License Manager for Portal for ArcGIS</h3></li> <li class='toc-level1'><i>•</i> <a href='007900000035000000.htm'>Introduction to ArcGIS License Manager for Portal for ArcGIS</a></li> <li class='toc-level1'><i>•</i> <a href='007900000031000000.htm'>Configure License Manager for use with ArcGIS Enterprise Portal</a></li> <li class='toc-level1'><i>•</i> <a href='007900000033000000.htm'>Useful information and best practices</a></li> <li class='toc-title toc-level1'><h3>Advanced Topics</h3></li> <li class='toc-level1'><i>•</i> <a href='00790000000r000000.htm'>Automatically starting the License Manager</a></li> <li class='toc-level1'><i>•</i> <a href='00790000000t000000.htm'>Defining port@host to one or more license servers</a></li> <li class='toc-level1'><i>•</i> <a href='00790000000v000000.htm'>Backup license servers</a></li> <li class='toc-level1'><i>•</i> <a href='00790000000w000000.htm'>Configure ArcGIS License Manager to work through a firewall</a></li> <ol class='toc-level2'> <li class='toc-title toc-level2'><h3>The Options File</h3></li> <li class='toc-level2'><i>•</i> <a href='00790000000z000000.htm'>Using the Options file</a></li> <li class='toc-level2'><i>•</i> <a href='00790000003n000000.htm'>ACTIVATION_EXPIRY_DAYS</a></li> <li class='toc-level2'><i>•</i> <a href='007900000029000000.htm'>DEBUGLOG</a></li> <li class='toc-level2'><i>•</i> <a href='007900000011000000.htm'>EXCLUDE</a></li> <li class='toc-level2'><i>•</i> <a href='007900000012000000.htm'>EXCLUDE_ENTITLEMENT</a></li> <li class='toc-level2'><i>•</i> <a href='007900000013000000.htm'>EXCLUDEALL</a></li> <li class='toc-level2'><i>•</i> <a href='007900000014000000.htm'>GROUP</a></li> <li class='toc-level2'><i>•</i> <a href='00790000002z000000.htm'>GROUPCASEINSENSITIVE</a></li> <li class='toc-level2'><i>•</i> <a href='007900000015000000.htm'>HOST_GROUP</a></li> <li class='toc-level2'><i>•</i> <a href='007900000016000000.htm'>INCLUDE</a></li> <li class='toc-level2'><i>•</i> <a href='007900000017000000.htm'>INCLUDE_ENTITLEMENT</a></li> <li class='toc-level2'><i>•</i> <a href='007900000018000000.htm'>INCLUDEALL</a></li> <li class='toc-level2'><i>•</i> <a href='007900000019000000.htm'>MAX</a></li> <li class='toc-level2'><i>•</i> <a href='00790000001m000000.htm'>NOLOG</a></li> <li class='toc-level2'><i>•</i> <a href='00790000001n000000.htm'>RESERVE</a></li> <li class='toc-level2'><i>•</i> <a href='00790000003m000000.htm'>Feature names for ArcGIS Option file</a></li> </ol> <li class='toc-level1'><i>•</i> <a href='00790000002p000000.htm'>Transferring licenses from one License Manager to another</a></li> <li class='toc-level1'><i>•</i> <a href='00790000001p000000.htm'>Using the license manager on Windows Terminal Server/Citrix</a></li> <li class='toc-level1'><i>•</i> <a href='00790000002n000000.htm'>Enterprise deployment of the ArcGIS Desktop or ArcGIS Engine licenses</a></li> <li class='toc-level1'><i>•</i> <a href='00790000002s000000.htm'>Provisioning files</a></li> <li class='toc-level1'><i>•</i> <a href='007900000030000000.htm'>Silent authorization commands</a></li> <li class='toc-title toc-level1'><h3>Troubleshooting</h3></li> <li class='toc-level1'><i>•</i> <a href='00790000001q000000.htm'>Incorrect clock setting</a></li> <li class='toc-level1'><i>•</i> <a href='00790000001r000000.htm'>Cannot connect to the License Manager</a></li> <li class='toc-title toc-level1'><h3>Glossary</h3></li> <li class='toc-level1'><i>•</i> <a href='00790000001s000000.htm'>ArcGIS Administrator</a></li> <li class='toc-level1'><i>•</i> <a href='00790000001t000000.htm'>ArcGIS License Manager</a></li> <li class='toc-level1'><i>•</i> <a href='00790000001v000000.htm'>authorization</a></li> <li class='toc-level1'><i>•</i> <a href='00790000001w000000.htm'>borrow</a></li> <li class='toc-level1'><i>•</i> <a href='00790000001z000000.htm'>Concurrent use</a></li> <li class='toc-level1'><i>•</i> <a href='007900000020000000.htm'>daemon</a></li> <li class='toc-level1'><i>•</i> <a href='007900000021000000.htm'>debug log file</a></li> <li class='toc-level1'><i>•</i> <a href='007900000022000000.htm'>feature</a></li> <li class='toc-level1'><i>•</i> <a href='007900000023000000.htm'>license</a></li> <li class='toc-level1'><i>•</i> <a href='007900000024000000.htm'>License Manager</a></li> <li class='toc-level1'><i>•</i> <a href='007900000025000000.htm'>license server</a></li> <li class='toc-level1'><i>•</i> <a href='007900000036000000.htm'>named user</a></li> <li class='toc-level1'><i>•</i> <a href='007900000032000000.htm'>Portal for ArcGIS</a></li> <li class='toc-level1'><i>•</i> <a href='00790000002v000000.htm'>provisioning file</a></li> <li class='toc-level1'><i>•</i> <a href='007900000026000000.htm'>Return</a></li> <li class='toc-level1'><i>•</i> <a href='007900000034000000.htm'>simultaneous session</a></li> <li class='toc-level1'><i>•</i> <a href='007900000027000000.htm'>Single use</a></li> <li class='toc-level1'><i>•</i> <a href='007900000028000000.htm'>Software Authorization Wizard</a></li> </ol></div><div id="content"><div class="header"><h1> Configure ArcGIS License Manager to work through a firewall</h1></div> <p id="GUID-0D6E24EF-C3EA-4275-BBD4-FA44E8ECB2D4">Many of today's networks use a firewall for enhanced security from outside threats. Because the license manager uses the TCP/IP protocols, implementing such a firewall can pose problems between the license manager server and the clients connecting to it.</p> <p id="GUID-561EA8BF-9379-4F2E-AFA1-DA07C3E55242">The problem is caused by the firewall often closing or blocking access to the ports the license manager uses to communicate. By default, the lmgrd daemon is set to TCP port 27000. The ARCGIS daemon, on the second line of the file, is not confined to a particular port range. It is dynamic, meaning that it can listen on any available TCP port. The License manager does not communicate over UDP.</p> <p id="GUID-7F4895C6-0D2B-48D7-8812-7FEC1EC2BEF2">To secure the license management environment and allow you to implement a firewall, you can lock the ARCGIS daemon to a specific port. You can also change the lmgrd daemon from the default 27000 to another port between 27000 and 27009. This range was pre-specified for license manager use because of the low traffic in that range.</p><p id="GUID-F15DEC27-0BE6-40B5-A274-7E9239266C40">This topic does not explain the procedures required to open your hosts firewall. Please refer to your firewall and operating system help documentation on opening ports.</p> <div class="section1" id="GUID-C54AF06C-274D-4E67-B64F-84062D0EBA06" purpose="section1"><h2> Procedure for locking License Manager to specific ports</h2><p id="GUID-BBDC0972-0509-466D-A624-3B352B4C1231">The steps provided require that you briefly stop the license manager. During this time, connections to the license manager may be lost. <ol purpose="ol" id="OL_1D1312C9F5DD4490A3D0AC974DDDBA19"> <li purpose="li" id="LI_C659B11ACAEA4466BB4A7EC043AEEE85">Click <span class="uicontrol">Start <span class="greaterthan">></span> Programs <span class="greaterthan">></span> ArcGIS <span class="greaterthan">></span> License Server Administrator</span>.</li> <li purpose="li" id="LI_D4D03FC7FA1F4DE681D6E8E54A08A751">Click <span class="uicontrol">Start/Stop License Server</span> in the table of contents and click <span class="uicontrol">Stop</span>.</li> <li purpose="li" id="LI_B50DB56D30414F9683769460F0D63B2A">Open Windows Explorer and navigate to your license manager installation location (<span class="usertext">C:\Program Files\ArcGIS\LicenseManager\bin</span> by default for ArcGIS License Manager 2021.0 and newer installations), in which you will see a <span class="usertext">service.txt</span> file. <p id="GUID-B04F26FD-704A-4BFF-AE26-06E9CA268C90">The file should look similar to this:</p> <pre purpose="pre" cid="wy0GJ">SERVER this_host ANY 27000 VENDOR ARCGIS USE_SERVER FEATURE ACT ARCGIS 1 permanent 1 vendor_info=7KNJDRHFHBK4CFDMJ214 SIGN="052E ABFC 32DD \ 2473 DEFD E276 4BF3 E0DB 87EB 2203 5A30 C014 19A1 C35E 2154 \ 08B1 9460 A2B9 6701 DC4D CAF2 E2FE 1347 0E36 90FA 4F3B E864 \ BEC8 D3A2 A615"</pre></li> </ol> </p><p id="GUID-F3C96E63-7C9F-4164-B22F-A2A9C8E9D714"> At the end of the SERVER line, you can choose to specify a port number for the lmgrd daemon, immediately after ANY (separated with a space).</p><p id="GUID-D9F668D5-5ADA-4023-AF70-EE1B4B2A71AF">On the VENDOR line, add <span class="usertext">PORT=####</span>, where #### is a specific port number designated by you, to lock the vendor daemon to that specific port (for example, 5152). After making the changes, your <span class="usertext">service.txt</span> file should look something like this:</p><p id="GUID-3F39D0BE-6595-4E05-B85F-3071C68058F4"><pre purpose="pre" id="GUID-1A79B796-2D0C-49F2-9BC2-9A1DC283E584">SERVER this_host ANY 27004 VENDOR ARCGIS PORT=5152 USE_SERVER FEATURE ACT ARCGIS 1 permanent 1 vendor_info=7KNJDRHFHBK4CFDMJ214 SIGN="052E ABFC 32DD \ 2473 DEFD E276 4BF3 E0DB 87EB 2203 5A30 C014 19A1 C35E 2154 \ 08B1 9460 A2B9 6701 DC4D CAF2 E2FE 1347 0E36 90FA 4F3B E864 \ BEC8 D3A2 A615"</pre></p><ol purpose="ol" id="OL_92AFE1ADFD7844C98085853E912B8533"> <li purpose="li" id="LI_5F48C9F85FE8474ABF035BD64F66F4FE">Save the <span class="usertext">.txt</span> file.</li> <li purpose="li" id="LI_6F5A10FDE4E54D428C58B61B8E6F6133">From License Server Administrator, click <span class="uicontrol">Start</span>. <p id="GUID-683F5F84-AC1A-461B-A765-F5D323E7A8A9">The vendor daemon is now static, locked to the port specified.</p></li> <li purpose="li" id="LI_8E31FB924D4D483E9D12A1317F57A820">These ports can now be saved as exceptions in the firewall to allow communication between the license server and the client.</li> </ol><div class="notes" id="GUID-F9438362-37D1-4733-BA5A-4F2EDCF9E1AB"><div class="note"><img class="note_img" src="rsrc/note.png" alt="Note" title="Note"><span>Note:</span></div><div class="tipbody"><p id="GUID-50C40875-2A7D-41CE-8CF6-1974202FB70E">With ArcGIS License Manager 10.3 and later, you must specify a port in the range 27000-27009 for the lmgrd daemon to use with a Portal for ArcGIS. The <span class="usertext">service.txt</span> file found in the installation directory (<span class="usertext">..\Program Files\ArcGIS\LicenseManager\bin</span> by default for 2021.0 and newer installations) will now include the port 27000 by default after installing ArcGIS License Manager. If ArcGIS License Manager 2021.1 was installed as an upgrade from an earlier version, for example over ArcGIS License Manager 10.2.2 and a port such as 27004 was already specified in the earlier installation, this port may not be carried over into the new installation. In this case, you must manually re-enter the port into the <span class="usertext">service.txt</span> file. If upgrading from ArcGIS License Manager 10.3-10.6 or ArcGIS License Manager 2018.0-2021.0 to ArcGIS License Manager 2021.1, then the port information in the <span class="usertext">service.txt</span> file will be retained. The lmgrd daemon port is communicated to the Portal for ArcGIS as part of the exported portal configuration <span class="usertext">*.json</span> file.</p><p id="GUID-11733A28-0118-42BA-8DB2-C89479945E20">When operating ArcGIS License Manager on the same host server as another vendor's Flexnet enabled license server, each LMGRD daemon should be locked to a different port in the 27000-27009 range to avoid conflicts in serving licenses.</p><p id="GUID-CA9BFD9A-EB33-47F0-AF60-90D44B554D5C"> For details on configuring Portal for ArcGIS to work through a firewall and for other security best practices, please also refer to the <a target="_blank" class="xref" href="https://links.esri.com/portal_firewall" rel="https://links.esri.com/portal_firewall">Portal for ArcGIS</a> help documentation.</p> </div></div></div> <div class="footer"> Copyright © 1995-2021 Esri. All rights reserved. </div></div></div></body></html>