Traffic Types - Black Box SmartPath LWN602A User Manual

Smartpath enterprise wireless system
Hide thumbs Also See for SmartPath LWN602A:
Table of Contents

Advertisement

12. Traffic Types

This is a list of all the types of traffic that might be involved with a SmartPath AP and SmartPath EMS VMA deployment. If a fire-
wall lies between any of the sources and destinations listed below, make sure that it allows these traffic types.
Service
Source
SmartPath AP
Active Directory
RADIUS server mgt0
interface
Unregistered wireless
DHCP
client
Unregistered wireless
DNS
client
SmartPath AP mgt0
GRE
interface
Unregistered wireless
HTTP
client
Unregistered wireless
HTTPS
client
SmartPath AP VPN
IKE
client mgt0 interface
SmartPath AP VPN
IPsec ESP
client or server mgt0
interface
SmartPath AP VPN
IPsec ESP with NAT—
client or server mgt0
Traversal enabled
interface
SmartPath AP
LDAP
RADIUS server mgt0
interface
SmartPath AP
LDAPS
RADIUS server mgt0
interface
SmartPath AP mgt0
RADIUS accounting
interface
SmartPath AP mgt0
RADIUS authentication
interface
*DNX = dynamic network extensions
†This is the default destination port number. You can change it to a different port number from 1 to 65535.
Table 12-1. Traffic supporting network access for wireless clients.
Destination
Protocol
6 TCP
Active Directory
domain controller or
global catalog server
17 UDP
SmartPath AP Wi-Fi
subinterface in access
17 UDP
mode
SmartPath AP Wi-Fi
subinterface in access
17 UDP
mode
SmartPath AP mgt0
47 GRE
interface
SmartPath AP Wi-Fi
subinterface in access
6 TCP
mode
SmartPath AP Wi-Fi
subinterface in access
6 TCP
mode
SmartPath AP VPN
17 UDP
server mgt0 interface
SmartPath AP VPN
50 ESP
server or client mgt0
interface
SmartPath AP VPN
server or client mgt0
17 UDP
interface
OpenLDAP server
6 TCP
OpenLDAP server
6 TCP
RADIUS server
17 UDP
RADIUS
724-746-5500 | blackbox.com
Chapter 12: Traffic Types
SRC Port
DST Port
139, and 445 or
1024-65535
3268
1024-65535
389
68
67
53, or 1024–
53
65535
N.A.
N.A.
1024–65535
80
1024–65535
443
500 and 4500
500 and 4500 for
for NAT—
NAT—Traversal
Traversal
N.A.
N.A.
4500
4500
1024–65535
389
1024–65535
636
1024–65535
1813†
1024–65535
1812†
Notes
Required for a SmartPath AP
RADIUS server to contact a domain
controller on Port 445 or a global
catalog server on Port 3268
Required for captive Web portal
functionality
Required for captive Web portal
functionality
Required to support DNX* and Layer
3 roaming between members of
different clusters
Required for captive Web portal
functionality
Required for captive Web portal
functionality using a server key
Required for SmartPath AP VPN
clients to connect to SmartPath AP
VPN servers
Required for IPsec VPN traffic to
flow between SmartPath AP VPN
clients and servers
Required for VPN traffic to flow
when a NAT device is detected
in-line
Required for a SmartPath AP
RADIUS server to contact an
OpenLDAP server
Required for a SmartPath AP
RADIUS server to make an encrypted
connection to an OpenLDAP server
Required to support RADIUS
accounting
Required for 802.1x authentication
of users
Page 191

Advertisement

Table of Contents
loading

Table of Contents