Preconfiguring Appliances
Table 1-7
Default Communication Ports for Firepower System Features and Operations (continued)
Port
Description
443/tcp
HTTPS
AMQP
cloud comms.
514/udp
syslog
623/udp
SOL/LOM
1500/tcp
database
access
2000/tcp
1812/udp
RADIUS
1813/udp
3306/tcp
User Agent
8302/tcp
eStreamer
8305/tcp
appliance
comms.
8307/tcp
host input
client
32137/tcp
cloud comms. Bidirectional
Preconfiguring Appliances
You can preconfigure multiple appliances and Firepower Management Centers in a central location for
later deployment at other sites. For considerations when preconfiguring appliances, see
Firepower Managed Devices, page
Firepower 7000 and 8000 Series Installation Guide
1-16
Direction
Is Open on...
Bidirectional
Management Center
7000 and 8000 Series
devices
7000 and 8000 Series,
virtual devices, and
ASA FirePOWER
Outbound
Any
Bidirectional
7000 and 8000 Series
Inbound
Management Center
Bidirectional
Any except virtual
devices and
ASA FirePOWER
Inbound
Management Center
Bidirectional
Any except virtual
devices
Bidirectional
Any
Bidirectional
Management Center
Management Center
E-1.
Chapter 1
Introduction to the Firepower System
To...
obtain:
software, intrusion rule, VDB, and
•
GeoDB updates
URL category and reputation data (port
•
80 also required)
the Cisco Intelligence feed and other
•
secure Security Intelligence feeds
endpoint-based (FireAMP) malware
•
events
•
malware dispositions for files detected in
network traffic
dynamic analysis information on
•
submitted files
download software updates using the device's
local web interface.
submit files to the Cisco cloud for dynamic
analysis.
send alerts to a remote syslog server.
allow you to perform Lights-Out Management
using a Serial Over LAN (SOL) connection.
allow read-only access to the database by a
third-party client.
communicate with a RADIUS server for
external authentication and accounting.
communicate with User Agents.
communicate with an eStreamer client.
securely communicate between appliances in
a deployment. Required.
communicate with a host input client.
allow upgraded Management Centers to
communicate with the Cisco cloud.
Preconfiguring