Ports to Open Between Various RUCKUS Devices, Servers, and Controllers

The below table lists ports that must be opened in the network firewall to ensure that the vSZ-D/SZ/vSZ (controller), managed APs, and RADIUS servers can communicate with each other successfully.

Ports to Open Between Various RUCKUS Devices, Servers, and Controllers

From (Sender) To (Listener)

Communication Port Number

Layer 4 Protocol Interface Configurable from Web Interface? Purpose
AP Control plane of :

SZ-100

SZ-300

vSZ

21 TCP Control No ZD and Solo APs can download SZ AP firmware and convert themselves to SZ APs.
AP AP 1883 TCP Control No AP-AP communication for neighbor AP information exchange in FT, Client Load Balance, etc.
AP Control plane of :

SZ-100

SZ-300

vSZ

22 TCP Control No SSH Tunnel for management
AP ZD SZ 69 UDP Control No ZD Migration
AP vSZ control plane 91 (AP firmware version 2.0 to 3.1.x) and 443 (AP firmware version 3.2 and later) TCP Control No AP firmware upgrade

APs need Port 91 to download the Guest Logo and to update the signature package for the ARC.

Note: Starting with SZ 3.2 release, the controller uses an HTTPS connection and an encrypted path for the firmware download. The port used for AP firmware downloads has been changed from port 91 to 443 to distinguish between the two methods. To ensure that all APs can be upgraded successfully to the new firmware, open both ports 91 and 443 in the network firewall.
AP RAC (RADIUS Access Controller) 1813 UDP Management, Cluster, Control
Note: The Management interface is applicable when vSZ-H is in single-interface mode. If in 3-interface mode, Access and Core separation disabled, it depends on the configured Management traffic interface.
No RADIUS_Auth profile defines both inbound and outbound traffic. Information specified here is for inbound traffic only.
AP SZ 5353 UDP Control No

Resolves hostnames to IP addresses

AP

DP

SZ 8200 TCP Control No Captive Portal OAuth service port for HTTP

AP

DP

SZ 8222 TCP Control No Captive Portal OAuth service port for HTTPS

AP

DP

SZ 8280 TCP Control No Captive Portal Web Proxy service port for HTTPS
AP-MD SZ-MD 9191 TCP Cluster No Communication between AP-MD and SZ-MD
AP vSZ control plane 12223 UDP Control No LWAPP discovery sends image upgrade request to ZD-APs via LWAPP (RFC 5412).

AP

UE

SZ 18301 UDP Management, Cluster, Control No SpeedFlex tests the network performance between AP, UE, and SZ.
ICX vSZ control plane 22 TCP Control No SSH Tunnel.
ICX vSZ control plane 443 TCP Control No Access to the vSZ/SZ control plane over secure HTTPS.
SZ External FTP server 20-21 TCP Control, Cluster, Management No Transfer date to external FTP servers
Follower SZ nodes Master SZ node 123 UDP Cluster No Sync system time among SZ nodes
SZ External Licensing Server 443 TCP Management No Download licensing and support entitlements from the licensing server.
SZ External Licensing server 443 TCP Management No Download licensing and support entitlements from the licensing server.
SZ-RAC External AAA 1812 UDP Management, Cluster, Control
Note: The Management interface is applicable when vSZ-H is in single-interface mode. If in 3-interface mode, Access and Core separation disabled, it depends on the configured Management traffic interface.
Yes To Support RADIUS Proxy Authentication
SZ SZ 5671-5672 TCP Cluster No RabbitMQ inter-node cluster communication
SZ SZ 6379, 6380 TCP Cluster No Internal communication among SZ nodes
SZ SZ 7000 TCP/UDP Cluster No Cassandra (database) cluster communication and data replication
SZ SZ 7500 UDP Cluster No SZ Clustering Operation
SZ SZ 7800 TCP/UDP Cluster No Cluster node communication for cluster's operations
SZ SZ 7800-7805 TCP Cluster No A protocol stack using TCP on JGroups library for node to node communication
SZ SZ 7810 TCP Cluster No A protocol stack using FD_SOCK on JGroups library for node-to-node communication
SZ SZ 7811 TCP Cluster No A protocol stack using FD_SOCK on JGroups library for node-to-node communication
SZ SZ 7812 TCP Cluster No A protocol stack using FD_SOCK on JGroups library for node-to-node communication
SZ SPoT 8883
Note: The connection between the controller and vSPoT is an outbound connection, so it depends on the destination IP address. If the destination IP address falls in the subnet of one interface, it is routed to that interface. Otherwise, it is routed via the default route.
TCP Management, Cluster, Control No Communication between SZ and SPoT
SZ SZ 9300-9400 TCP Cluster No Internal communication between nodes within the cluster (ElasticSearch database)
SZ local modules SZ memproxy 11211 TCP Cluster No Internal proxy for saving in-memory data to memcached
SZ SZ 11311 TCP Cluster No Memory cache server
SZ SZ 33434-33534 UDP Management, Cluster, Control No ICX Troubleshooting (traceroute).
SZ CS DP 65534, 65535 TCP Management No DP Debug
TACACS+ Server TACACS+ Server 49 TCP Management, Cluster, Control No TACACS+
DNS Server DNS 53 TCP/UDP Management, Cluster, Control No DNS
DHCP Server SZ 67,68 UDP Management, Cluster, Control No DHCP
Walled-Garden Web Server Captive Portal with HTTP Proxy 80 TCP Management, Cluster, Control No

WISPr_WalledGarden

SNMP Client SZ 161 UDP Management No Simple Network Management Protocol (SNMP)
LDAP Server RAC 389 TCP/UDP Management, Cluster, Control Yes SZ to LDAP
SZ rsyslog 514 TCP/UDP Management, Cluster, Control No Remote Syslog
DHCP v6 Server SZ 546, 547 UDP Management, Cluster, Control No DHCPv6 Protocol
LDAPS Server RAC 636 TCP Management, Cluster, Control Yes SZ to LDAPS Server
AAA server SZ 2083 (RadSec) TCP Management, Cluster, Control No The default destination port number for RADIUS over TLS is TCP/2083 (As per RFC-6614)
AAA server SZ 2084 (CoA/DM Over RadSec) TCP Management, Cluster, Control No SZ as RadSec server listens on port 2084 for incoming TLS connection from client (AAA Client) to process CoA/DM messages over RadSec.
AD Server (MSTF-GC) RAC 3268 TCP Management, Cluster, Control Yes SZ to AD (MSTF-GC)
External AAA Server (free RADIUS) SZ-RAC (vSZ control plane) 3799 UDP Management, Cluster, Control No Supports Disconnect Message and CoA (Change of Authorization) which allows dynamic changes to a user session such as disconnecting users and changing authorizations applicable to a user session.
JITC CAC SZ 4443 TCP Control No Since SZ 5.1.2 release, mainly for JITC CAC login support. This port is opened for NGINX to configure for client certificate authentication.
Legacy Public API Client SZ 7443 TCP Management No Deprecated Public API
Any Management interface 8022 No (SSH) Management Yes

When the management ACL is enabled, you must use port 8022 (instead of the default port 22) to log on to the CLI or to use SSH.

Any vSZ control plane 8090 TCP Control No Allows unauthorized UEs to browse to an HTTP website
Any vSZ control plane 8099 TCP Control No Allows unauthorized UEs to browse to an HTTPS website
Any vSZ control plane 8100 TCP Control No Allows unauthorized UEs to browse using a proxy UE
Any vSZ management plane 8443
Note: The Public API port has changed from 7443 to 8443.
TCP Management No Access to the controller web interface via HTTPS
Any vSZ control plane 9080 HTTP Management, Control No Northbound Portal Interface for hotspots
Any vSZ control plane 9443 HTTPS Management, Control No Northbound Portal Interface for hotspots
Client device SZ control Plane 9997 TCP Control No Internal Subscriber Portal in HTTP
Any vSZ control plane 9998 TCP Control No Hotspot WISPr subscriber portal login/logout over HTTPS

vDP/ SZ300 DP Data Group(PG-2):

From (Sender) To (Listener) Port Number Layer 4 Protocol Interface Configurable from Web Interface? Purpose

AP

vSZ_D

vSZ control plane 22 TCP Control, Cluster, Management No SSH Tunnel
Note: The destination interfaces are meant for three-interface deployments. In a single-interface deployment, all the destination ports must be forwarded to the combined management and control interface IP address.
Note: Communication between APs is not possible across NAT servers.