Ports to Open Between Various RUCKUS Devices,
Servers, and Controllers
The following tables list the ports that
you must open on network firewalls to ensure that the virtual SmartZone Data Plane
(vSZ-D),
SmartZone (SZ), virtual SmartZone (vSZ) controller, managed Access Points (APs),
and Remote
Authentication Dial-In User Service (RADIUS) servers communicate successfully.
Ports to Open Between Various
RUCKUS Devices, Servers, and Controllers
From (Sender)
To (Listener)
Communication Port
Number
Layer 4 Protocol
Interface
Configurable from Web Interface?
Purpose
AP
Control Plane of :
SZ-144
vSZ (vSZ-H and
vSZ-E)
21
TCP
Control
No
ZD and Solo APs can download SZ AP
firmware and convert themselves to SZ APs.
AP
AP
1883
TCP
Control
No
AP-AP communication for neighbor AP information
exchange in FT, Client Load Balance, etc.
AP
Control Plane of :
SZ-144
vSZ
(vSZ-H and vSZ-E)
22
TCP
Control
No
SSH Tunnel for management
AP
vSZ control plane
91 (AP firmware version 2.0 to 3.1.x) and 443 (AP firmware
version 3.2 and
later)
TCP
Control
No
AP firmware upgrade
APs need Port 91
to download the Guest Logo and to update the signature package
for the ARC.
Note: Starting with SZ
3.2 release, the controller uses an HTTPS connection and an
encrypted path for the firmware download. The port used for AP
firmware downloads has been changed from port 91 to 443 to
distinguish between the two methods. To ensure that all APs can
be upgraded successfully to the new firmware, open both ports 91
and 443 in the network firewall.
AP
RAC (RADIUS Access Controller)
1813
UDP
Management, Cluster, Control
Note: The Management
interface is applicable when vSZ-H is in single-interface mode.
If in 3-interface mode, Access and Core separation disabled, it
depends on the configured Management traffic
interface.
No
RADIUS_Auth profile defines both
inbound and outbound traffic. Information specified here is for
inbound traffic only.
AP
SZ
5353
UDP
Control
No
Resolves
hostnames to IP addresses
AP
DP
SZ
8200
TCP
Control
No
Captive Portal OAuth service port for
HTTP
AP
DP
SZ
8222
TCP
Control
No
Captive Portal OAuth service port for
HTTPS
AP
DP
SZ
8280
TCP
Control
No
Captive Portal Web Proxy service port
for HTTPS
AP-MD
SZ-MD
9191
TCP
Cluster
No
Communication between AP-MD and SZ-MD
AP
vSZ control plane
12223
UDP
Control
No
LWAPP discovery sends image upgrade
request to ZD-APs via LWAPP (RFC 5412).
AP
UE
SZ
18301
UDP
Management, Cluster, Control
No
SpeedFlex tests the network performance
between AP, UE, and SZ.
ICX
vSZ control plane
22
TCP
Control
No
SSH Tunnel.
ICX
vSZ control plane
443
TCP
Control
No
Access to the vSZ/SZ control plane over secure
HTTPS.
SZ
External FTP server
20-21
TCP
Control, Cluster, Management
No
Transfer date to external FTP servers
Follower SZ nodes
Master SZ node
123
UDP
Cluster
No
Sync system time among SZ nodes
SZ
External Licensing Server
443
TCP
Management
No
Download licensing and support
entitlements from the licensing server.
SZ
External Licensing server
443
TCP
Management
No
Download licensing and support entitlements from the
licensing server.
SZ-RAC
External AAA
1812
UDP
Management, Cluster, Control
Note: The Management
interface is applicable when vSZ-H is in single-interface mode.
If in 3-interface mode, Access and Core separation disabled, it
depends on the configured Management traffic
interface.
Yes
To Support RADIUS Proxy Authentication
SZ
SZ
5671-5672
TCP
Cluster
No
RabbitMQ inter-node cluster communication
SZ
SZ
6379, 6380
TCP
Cluster
No
Internal communication among SZ nodes
SZ
SZ
7000
TCP/UDP
Cluster
No
Cassandra (database) cluster
communication and data replication
SZ
SZ
7500
UDP
Cluster
No
SZ Clustering Operation
SZ
SZ
7800
TCP/UDP
Cluster
No
Cluster node communication for
cluster's operations
SZ
SZ
7800-7805
TCP
Cluster
No
A protocol stack using TCP on JGroups
library for node to node communication
SZ
SZ
7810
TCP
Cluster
No
A protocol stack using FD_SOCK on
JGroups library for node-to-node communication
SZ
SZ
7811
TCP
Cluster
No
A protocol stack using FD_SOCK on
JGroups library for node-to-node communication
SZ
SZ
7812
TCP
Cluster
No
A protocol stack using FD_SOCK on
JGroups library for node-to-node communication
SZ
SPoT
8883
Note: The
connection between the controller and vSPoT is an outbound
connection, so it depends on the destination IP address. If the
destination IP address falls in the subnet of one interface, it
is routed to that interface. Otherwise, it is routed via the
default route.
TCP
Management, Cluster, Control
No
Communication between SZ and SPoT
SZ
SZ
9300-9400
TCP
Cluster
No
Internal communication between nodes
within the cluster (ElasticSearch database)
SZ local modules
SZ memproxy
11211
TCP
Cluster
No
Internal proxy for saving in-memory
data to memcached
SZ
SZ
11311
TCP
Cluster
No
Memory cache server
SZ
SZ
33434-33534
UDP
Management, Cluster, Control
No
ICX Troubleshooting
(traceroute).
SZ CS
DP
65534, 65535
TCP
Management
No
DP Debug
TACACS+ Server
TACACS+ Server
49
TCP
Management, Cluster, Control
No
TACACS+
DNS Server
DNS
53
TCP/UDP
Management, Cluster, Control
No
DNS
DHCP Server
SZ
67,68
UDP
Management, Cluster, Control
No
DHCP
Walled-Garden Web Server
Captive Portal with HTTP Proxy
80
TCP
Management, Cluster, Control
No
WISPr_WalledGarden
SNMP Client
SZ
161
UDP
Management
No
Simple Network Management Protocol
(SNMP)
LDAP Server
RAC
389
TCP/UDP
Management, Cluster, Control
Yes
SZ to LDAP
SZ
rsyslog
514
TCP/UDP
Management, Cluster, Control
No
Remote Syslog
DHCP v6 Server
SZ
546, 547
UDP
Management, Cluster, Control
No
DHCPv6 Protocol
LDAPS Server
RAC
636
TCP
Management, Cluster, Control
Yes
SZ to LDAPS Server
AAA server
SZ
2083 (RadSec)
TCP
Management, Cluster, Control
No
The default destination port number
for RADIUS over TLS is TCP/2083 (As per RFC-6614)
AAA server
SZ
2084 (CoA/DM Over RadSec)
TCP
Management, Cluster, Control
No
SZ as RadSec server listens on port 2084 for
incoming TLS connection from client (AAA Client) to process CoA/DM
messages over RadSec.
AD Server (MSTF-GC)
RAC
3268
TCP
Management, Cluster, Control
Yes
SZ to AD (MSTF-GC)
External AAA Server (free RADIUS)
SZ-RAC (vSZ control plane)
3799
UDP
Management, Cluster, Control
No
Supports Disconnect Message and CoA
(Change of Authorization) which allows dynamic changes to a user
session such as disconnecting users and changing authorizations
applicable to a user session.
JITC CAC
SZ
4443
TCP
Control
No
Since SZ 5.1.2 release, mainly for
JITC CAC login support. This port is opened for NGINX to configure
for client certificate authentication.
Legacy Public API Client
SZ
7443
TCP
Management
No
Deprecated Public API
Any
Management interface
8022
No (SSH)
Management
Yes
When the
management ACL is enabled, you must use port 8022 (instead of
the default port 22) to log on to the CLI or to use
SSH.
Any
vSZ control plane
8090
TCP
Control
No
Allows unauthorized UEs to browse to an
HTTP website
Any
vSZ control plane
8099
TCP
Control
No
Allows unauthorized UEs to browse to an
HTTPS website
Any
vSZ control plane
8100
TCP
Control
No
Allows unauthorized UEs to browse using
a proxy UE
Any
vSZ management plane
8443
Note: The
Public API port has changed from 7443 to 8443.
TCP
Management
No
Access to the controller web interface
via HTTPS
Any
vSZ control plane
9080
HTTP
Management, Control
No
Northbound Portal Interface for
hotspots
Any
vSZ control plane
9443
HTTPS
Management, Control
No
Northbound Portal Interface for
hotspots
Client device
SZ control plane
9997
TCP
Control
No
Internal Subscriber Portal in
HTTP
Any
vSZ control plane
9998
TCP
Control
No
Hotspot WISPr subscriber portal
login/logout over HTTPS
AP
SZ
23233
UDP
Data
No
GRE over UDP tunnel for data
AP
SZ
23232, 23233
TCP
Control
No
GRE over TCP tunnel for control
vSZ-D/SZ144-D Data Group
From (Sender)
To (Listener)
Port Number
Layer 4 Protocol
Interface
Configurable from Web Interface?
Purpose
AP
vSZ-D
vSZ control plane
22
TCP
Control, Cluster, Management
No
SSH Tunnel
vSZ-D
vSZ control plane
443
TCP
Control, Cluster, Management
No
SSH Tunnel
Note: The destination interfaces are meant for
three-interface deployments. In a single-interface deployment, all the destination
ports must be forwarded to the combined management and control interface IP
address.
Note: Communication between APs is not possible
across NAT servers.