Firewall Ports That Must Be Open For Zonedirector Communications; Nat Considerations - Ruckus Wireless ZoneDirector 1100 User Manual

Smart wi-fi controllers that support up to 1000 aps
Hide thumbs Also See for ZoneDirector 1100:
Table of Contents

Advertisement

Introducing Ruckus Wireless ZoneDirector
Ensuring That APs Can Communicate with ZoneDirector
Firewall Ports that Must be Open for ZoneDirector
Communications
Depending on how your network is designed, you may need to open firewall ports on any
firewalls located between ZoneDirector, FlexMaster or the access points. The following table
lists the ports that need to be open for different types of communications.
Table 11. Firewall ports that must be open for ZoneDirector communications
Communication
ZoneDirector Web UI access
AP > ZoneDirector LWAPP
AP > ZoneDirector SpeedFlex
AP > ZoneDirector (AP)
firmware upgrade
ZoneDirector > ZoneDirector
Smart Redundancy
ZoneDirector > FlexMaster
registration/inform/firmware
upgrade
FlexMaster > ZoneDirector
management interface
ZoneDirector CLI access

NAT Considerations

Beginning with version 9.2, ZoneDirector can be deployed in a private network behind a NAT
(Network Address Translation) device. When ZoneDirector is deployed on an isolated private
network where NAT is used, administrators can manually configure a port-mapping table on
the NAT device to allow remote access into ZoneDirector. This allows APs to establish an LWAPP
connection with ZoneDirector, as well as allowing remote HTTPS and SSH management access
to ZoneDirector.
Specifically, the following ports must be mapped to ZoneDirector's private IP address on the
NAT device's port mapping table: ports 21, 22, 80, 443, 12222, 12223.
Note that there are some limitations with this configuration, including:
SpeedFlex performance test tool will not work (ZoneDirector needs to know the IP
addresses of the APs).
Deploying two ZoneDirectors behind the same NAT in a Smart Redundancy configuration
will not work (NAT equipment limits mapping each port to a single ZoneDirector IP address).
Ports
TCP destination ports 80 and 443 (HTTP and
HTTPS)
UDP destination ports 12222 and 12223
UDP port 18301
TCP port 21 (the firewall must be stateful for PASV
FTP transfers)
TCP destination port 443 and port 33003
TCP destination port 443
TCP destination port as specified in FM Inventory
'Device Web Port Number Mapping'
TCP destination port 22 (SSH)
Table 11
lists the ports that must be open for trans-NAT communications.
20

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

Zonedirector 3000Zonedirector 5000

Table of Contents