At the "About upgrading to 6.2 - READ THIS FIRST" page, it states:
"This opens two network ports by default on the local machine: 8191 (for KV Store) and 8065 (for Appserver.) "
I want to upgrade my Splunk 5 search head to Splunk 6 today and upgrade all my indexers next week. In the meantime, I wanted to know if the indexers and search head will be communicating on these new ports? I assume so, but this statement isn't so explicit. When it says the ports are opened "on the local machine," it's not clear who the local machine will be communicating with when the new ports are opened.
The new network ports for Splunk Enterprise 6.2 are open for connections to the local instance. This means that other instances (such as search head cluster members, indexer cluster members, etc.) that use App Key Value Store (port 8191) and Appserver (8065) use these ports to handle those specific operations. If you block those ports, that communication can't happen.