9.1.11.6. Information Flow EnforcementΒΆ

The pupmod puppet module listens on ports 8140 and 8141 by default and makes these ports available via the system firewall.

Port 8140 is the Puppet Server port and 8141 is the certificate authority port. The connecting source IPs are limited to the value of $trusted_nets, which for most installs, is the local network.

References: AC-4 : INFORMATION FLOW ENFORCEMENT