For the agent, the following firewall rules needs to be in place.
1. open TCP incoming/outgoing traffic for Agent input port (7520 default)
2. open all TCP outgoing ports > 1024
However, the second rule is not mandatory.
All incoming messages will be on the agent input port, default is port 7520.
Agent will sent the message back to the manager from a random port.
Note: On the DSeries server side, the manger input port needs to be open as well (usually 7507, by default)