Outbound SSH (TCP 22) from APs,
switches, and Edges to:
device.ruckus.cloud
device.eu.ruckus.cloud
device.asia.ruckus.cloud
Outbound connectivity to RUCKUS One proxy services (such as RADIUS UDP 1812/1813,
AD, and LDAP) from APs and local Authentication Servers to:
outgoing.ruckus.cloud
outgoing.eu.ruckus.cloud
outgoing.asia.ruckus.cloud
Make sure that you have a DNS server configured
for your network infrastructure devices. DNS is required for the access points
to
resolve the RUCKUS One controller names and perform the
upgrade successfully.
Note: APs and switches require the following DNS
entries to be reachable to establish secure connectivity to RUCKUS One. Ensure that the following DNS entries are whitelisted in your firewall:
ap-registrar.ruckuswireless.com
(this is the AP registrar FQDN)
sw-registrar.ruckuswireless.com
(this is the SWITCH registrar FQDN)
ocsp.comodoca.com (this is the CA
FQDN)
ocsp.ocsp.entrust.net (this is
the CA FQDN)
ocsp.godaddy.com (this is the CA
FQDN)
The following table lists the ports that must
be opened in the network firewall to ensure that managed APs, switches, guest users,
DNS
servers, and so on, can communicate successfully with RUCKUS One.
Ports Required for RUCKUS One
Communication
From (Sender)
To (Listener)
Port
Purpose
Symptoms When Blocked
Admin
Any
TCP:443
Login and access tenant account for managing tenant APs
or switches
RUCKUS One portal is inaccessible.
AP/Switch
RUCKUS One
TCP:22
SSH tunnel between the AP and RUCKUS One when the AP is running on
standalone or SmartZone firmware.
After the RUCKUS One AP image is upgraded, the AP uses HTTP/HTTPS for
management and control traffic
The AP or switch is unable to connect to RUCKUS One. On the AP, the DIR (newer models are labeled CTL) LED is
off.
Tenant account
shows that AP or switch is disconnected.
AP/Switch
RUCKUS One
TCP:443
Handles all traffic between AP or switch
and RUCKUS One
The AP or switch will be unable to connect to RUCKUS One.
AP/Switch
RUCKUS AP Registrar
TCP:443
Handles all traffic between AP or switch
and RUCKUS One
The AP or switch will be unable to connect to RUCKUS One.
AP/Switch
RUCKUS NTP Server (ntp.ruckuswireless.com)
UDP:123
Synchronization of the AP or switch clock with the NTP
server
The network device clock will be inaccurate.
AP/Switch
DNS server (provided by local DHCP)
TCP/UDP:53
Query to resolve RUCKUS AP/switch
Registrar's FQDN
This port is only used when an AP or switch is first added to a tenant
account. If this port is blocked, any factory-reset AP switch will be
unable to connect to RUCKUS One.
Guest
RUCKUS One (Guest Portal)
TCP:443
Guest authentication
Guest portal is unreachable.
Guest
RUCKUS One (Guest Portal)
TCP:8090
Enabling guest access to a tenant network
Guest authentication does not work and the guest is
unable to connect to the network.
Guest
RUCKUS One (Guest Portal)
TCP:8099
Enabling guest access to a tenant network
Guest authentication does not work and the guest is
unable to connect to the network.
RUCKUS One/AP
Location Server
TCP:8883 (default)
After authentication, the Location Server exchanges location messages
with the Sender, which may be either RUCKUS One or
the AP.
RUCKUS One or the AP will be unable to connect to the Location
Server and obtain location information.
AP
RUCKUS NATS
Server with MQTT enabled
TCP:443
For secure messaging, the AP communicates with the NATS Server with
MQTT enabled in RUCKUS One.
Securely handles communication between the AP and the RUCKUS One NATS Server with MQTT enabled.
UDP 1812-1813: Proxy mode networks depend on the
customer-supplied RADIUS server. By default, these are the standard RADIUS ports
(1812/1813), but you can change the port numbers, if necessary. Ensure that the
1812/1813 port range is open and can reach the RADIUS server of the customer, and
the
configured port on the RADIUS server is accessible by RUCKUS One to match the
proxy-mode configuration.
Protocols and Ports Required
for RADIUS Server Communication
Protocols and Ports
Firewall Flow
Purpose
UDP 1812/1813 (RADIUS)
RUCKUS One
IP ranges to the RADIUS server of the customer.
RUCKUS One
proxies the RADIUS AAA traffic from the AP and forwards it to the
RADIUS server of the customer.
UDP User-Defined (RADIUS)
RUCKUS One
IP ranges to the RADIUS server of the customer on the user-defined
port.
RUCKUS One
proxies the RADIUS AAA traffic from the AP and forwards it to the
RADIUS server of the customer on the user-defined port.
ACX-95294
In distributed network
environments, configuring outgoing IP addresses for RADIUS and AAA servers based
on
geographic regions is a critical practice. This involves assigning distinct source
IP
addresses to authentication traffic originating from specific locations, enabling
centralized or cloud-based RADIUS/AAA infrastructure to accurately identify, route,
and
process authentication requests based on the region.
Region-Specific Outgoing IP Configuration for RADIUS/AAA