Users Guide

Table Of Contents
614 | Behavior and Defaults Dell PowerConnect ArubaOS 5.0 | [User Guide
21 TCP controller FTP server for AP6X software download.
22 TCP controller SSH
23 TCP AP and controller Telnet is disabled by default but the port is still open.
53 UDP controller Internal domain.
67 UDP AP (and controller if
DHCP server is
configured)
DHCP server.
68 UDP AP (and controller if
DHCP server is
configured)
DHCP client.
69 UDP controller TFTP
80 TCP AP and controller HTTP Used for remote packet capture where the capture is saved on
the Access Point. Provides access to the WebUI on the controller.
123 UDP controller NTP
161 UDP AP and controller SNMP. Disabled by default.
443 TCP controller Used internally for captive portal authentication (HTTPS) and is
exposed to wireless users. A default self-signed certificate is
installed in the controller. Users in a production environment are
urged to install a certificate from a well known CA such as Verisign.
Self-signed certs are open to man-in-the-middle attacks and should
only be used for testing.
500 UDP controller ISAKMP
514 UDP controller Syslog
1701 UDP controller L2TP
1723 TCP controller PPTP
2300 TCP controller Internal terminal server opened by telnet soe command.
3306 TCP controller Remote wired MAC lookup.
4343 TCP controller HTTPS. A different port is used from 443 in order to not conflict with
captive portal. A default self-signed certificate is installed in the
controller. Users in a production environment are urged to install a
certificate from a well known CA such as Verisign. Self-signed certs
are open to man-in-the-middle attacks and should only be used for
testing
4500 UDP controller sae-urn
8080 TCP controller Used internally for captive portal authentication (HTTP-proxy). This
port is not exposed to wireless users.
8081 TCP controller Used internally for captive portal authentication (HTTPS). Not
exposed to wireless users. A default self-signed certificate is
installed in the controller. Users in a production environment are
urged to install a certificate from a well known CA such as Verisign.
Self-signed certs are open to man-in-the-middle attacks and should
only be used for testing.
8082 TCP controller Used internally for single sign-on authentication (HTTP). Not
exposed to wireless users.
Table 135 Default (Trusted) Open Ports (Continued)
Port
Number
Protocol Where Used Description