Users Guide

Table Of Contents
602 | External Firewall Configuration Dell PowerConnect ArubaOS 5.0 | [User Guide
Between a Remote AP (IPsec) and a controller:
z NAT-T (UDP port 4500).
z TFTP (UDP port 69) .
Network Management Access
This section describes the network ports that need to be configured on the firewall to manage the Dell network.
For WebUI access between the network administrator’s computer (running a Web browser) and a controller:
z HTTP (TCP ports 80 and 8888) or HTTPS (TCP ports 443 and 4343).
z SSH (TCP port 22) or TELNET (TCP port 23).
Other Communications
This section describes the network ports that need to be configured on the firewall to allow other types of traffic
in the Dell network. You should only allow traffic as needed from these ports.
z For logging: SYSLOG (UDP port 514) between the controller and syslog servers.
z For software upgrade or retrieving system logs: TFTP (UDP port 69) or FTP (TCP ports 21 and 22) between
the controller and a software distribution server.
z If the controller is a PPTP VPN server, allow PPTP (UDP port 1723) and GRE (protocol 47) to the controller.
z If the controller is an L2TP VPN server, allow NAT-T (UDP port 4500), ISAKMP (UDP port 500) and ESP
(protocol 50) to the controller.
z If a third-party network management system is used, allow SNMP (UDP ports 161 and 162) between the
network management system and all controllers. If the ArubaOS version is earlier than 2.5, allow SNMP traffic
between the network management system and APs.
z For authentication with a RADIUS server: RADIUS (typically, UDP ports 1812 and 813, or 1645 and 1646)
between the controller and the RADIUS server.
z For authentication with an LDAP server: LDAP (UDP port 389) or LDAPS (UDP port 636) between the
controller and the LDAP server.
z For authentication with a TACACS+ server: TACACS (TCP port 49) between the controller and the
TACACS+ server.
z For packet captures: UDP port 5555 from an AP to an Ethereal packet-capture station; UDP port 5000 from
an AP to a Wildpackets packet-capture station.
z For telnet access: Telnet (TCP port 23) from the network administrator's computer to any AP, if “telnet
enable” is present in the “ap location 0.0.0" section of the controller configuration.
z For External Services Interface (ESI): ICMP (protocol 1) and syslog (UDP port 514) between a controller and
any ESI servers.
z For XML API: HTTP (TCP port 80) or HTTPS (TCP port 443) between a controller and an XML-API client.
Note: TFTP is not needed for normal operation. If the remote AP loses its local image for any reason, it will use TFTP to download
the latest image.