Updated on 2025-12-31 GMT+08:00

Checking Source Server Configuration

Source servers must meet specific requirements for the MgC Agent to perform collection and migration tasks.

Requirements for Source Servers

When the MgC Agent is used to collect data from and migrate source servers, the source servers must meet the requirements below.

Windows source servers must:
  • Allow access from the server where the MgC Agent is installed over port 5985 or 5986.
  • Use PowerShell 3.0 or later.
  • Have WinRM enabled and be able to access the server where the MgC Agent is installed. For more information, see How Do I Configure WinRM and Troubleshoot WinRM Connection Problems?
  • Allow the execution of shell scripts. To review the current execution policy, you can open PowerShell on the source servers as an administrator and run the following command:
    Get-ExecutionPolicy
    If Restricted is returned, no scripts can be executed. Run the following command and enter Y to change the policy to RemoteSigned:
    Set-ExecutionPolicy RemoteSigned
Linux source servers must:
  • Allow access from the server where the MgC Agent is installed over port 22.
  • Allow direct root access. This means remote connections using root with SSH or other tools must be allowed on these Linux source servers.
  • Have SFTP and SSH enabled.
  • Support the following key exchange algorithms and MAC algorithms:
    • Key exchange algorithms: ssh-ed25519, ecdsa-sha2-nistp256, ecdsa-sha2-nistp384, ecdsa-sha2-nistp521, rsa-sha2-512, and rsa-sha2-256
    • MAC algorithms: hmac-sha2-256 and hmac-sha2-512

    If a server does not support the preceding security algorithms, you are advised to upgrade OpenSSH to 8.0 or later. Otherwise, deep collection cannot be performed for that server.

  • Have their iptables configured to allow all communications with the server where the MgC Agent is installed. To verify that, you can run the following command on the source servers. If the source field in the command output contains the IP address and port of the server where the MgC Agent is installed, the MgC Agent is not allowed to access these source servers. In this case, you need to allow access from the MgC Agent.
    iptables -L INPUT -v -n

    Run the following command to allow the access.
    iptables -D INPUT -s <IP-address-of-the-MgC-Agent-server-indicated-by-the-source-field>