Up through Pulse 9.1R10, the lockdown rules for exemption were pre-defined and administrators could not make changes to the configuration. (In the connstore.dat on the client they are labelled as V1)
Starting with Pulse 9.1R11, the PCS populates the list of core access rules depending on the platforms (these are observed as V2 in the connstore.dat file).
Administrators are allowed to modify and reorder these exceptions at Users>Pulse Secure Client>Connections>connectionSetName. Administrators can also configure the exception rules allow/deny behavior.
The following list contains the default applications and values for macOS
Components | Program | Protocol | Port | Direction |
---|
SNTP | /usr/sbin/sntp | UDP | R & L:123 | Inbound & Outbound |
NTP | /usr/sbin/ntpd | UDP | R & L:123 | Inbound & Outbound |
DHCP IPv4 Configd | /usr/libexec/configd | UDP | L:68, R:67 | Inbound & Outbound |
DHCP IPv4 Kerneltask | Kernel Task | UDP | L:68, R:67 | Inbound & Outbound |
DHCP IPv6 Configd | /usr/libexec/configd | UDP | L:546, R:547 | Inbound & Outbound |
DHCP IPv6 Kernel task | Kernel Task | UDP | L:546, R:547 | Inbound & Outbound |
NetBios | /System/Library/CoreServices/NetAuthAgent.app/Contents/MacOS/NetAuthSysAgent | UDP | R:137,138 | Inbound & Outbound |
NetBiosd | /usr/sbin/netbiosd | UDP | R:137,138 | Inbound & Outbound |
NetBios TCP | /System/Library/CoreServices/NetAuthAgent.app/Contents/MacOS/NetAuthSysAgent | TCP | R:139 | Outbound |
PortMap UDP | Kernel Task | UDP | R:111 | Inbound & Outbound |
PortMap TCP | Kernel Task | TCP | R:111 | Outbound |
Kerberos Client Kcm | /System/Library/PrivateFrameworks/Heimdal.framework/Helpers/kcm | TCP & UDP | R:88 | Outbound |
Kerberos Client Opendirectory | /usr/libexec/opendirectoryd | TCP & UDP | R:88 | Outbound |
LDAP | /usr/libexec/opendirectoryd | TCP | R:389,636,3268,3269 | Outbound |
LDAP Client | /usr/libexec/opendirectoryd | UDP | R:389 | Outbound |
Kerberos Password | /usr/libexec/opendirectoryd | TCP | R:464 | Outbound |
Legends:
L - Local portLegend:
R - Remote port