Cerbo GX Manual
13.14. Q14: The Blue Power Panel could be powered through the VE.Net net-
work, can I also do that with a Cerbo GX?
No, a Cerbo GX always needs to be powered itself.
13.15. Q15: What type of networking is used by the Cerbo GX (TCP and UDP
ports)?
Basics:
• The Cerbo GX needs to get a valid IP address from a DHCP server, including a working DNS server and gateway, or a static IP
configuration.
• DNS port 53 UDP and TCP
• NTP (time sync) UDP port 123
VRM Portal:
• Data to the VRM Portal is sent via HTTP POST and GET requests to http://ccgxlogging.victronenergy.com on port 80. Sensitive
data is sent using HTTPS on port 443 to the same host.
Firmware updates:
• The Cerbo GX connects to http://updates.victronenergy.com/ on port 443.
Remote support (default disabled):
• When enabled, an outbound SSH connection to supporthost.victronenergy.com is maintained. The Cerbo GX will try to connect
on port 22, 80 and 443, and the first that works is maintained.
• Enabling Remote Support also enables the sshd daemon, listening for incoming SSH requests on port 22. See next FAQ entry
for more information about the Remote Support functionality.
Two way communication (Remote VEConfig and Remote Firmware updates):
• Pre-v2.20: Uses HTTPS (port 443) to the Pubnub servers
• v2.20 and later: connects to mqtt-rpc.victronenergy.com on port 443
MQTT (default disabled):
• When enabled, a local MQTT broker is started, which accepts TCP connections on port 1883. The Cerbo GX will also try to
connect to the victron MQTT cloud server (mqtt.victronenergy.com) using SSL on port 8883.
Remote Console on VRM (default disabled):
• Remote Console on VRM uses the same reverse ssh tunnel as is used for Remote Support: outbound connection to suppor-
thosts.victronenergy.com on port 22, 80 or 443. No port forwarding in routers is necessary to use Remote Console on VRM.
Note that supporthosts.victronenergy.com resolves to multiple IP addresses: 84.22.108.49 and 84.22.107.120.
• See here to trouble shoot Remote Console on VRM.
Remote Console on LAN (default disabled):
• Remote Console on LAN requires port 80 (small website hosted on local hiawatha webserver on Cerbo GX). And also requires
port 81, which is the listening port for the websocket tunnel to VNC.
Modbus TCP (default disabled):
• ModbusTCP server uses port 502
13.16. Q16: What is the functionality behind the menu item Remote support
(SSH), in the Ethernet menu?
When enabled, the Color Control will open a SSH connection to our secure server, with a reverse tunnel back to the Color Con-
trol. Through this tunnel, Victron engineers can login to your Cerbo GX and perform remote support. This works when the Cerbo
GX is installed on an internet connection. The connection will even work when installed behind a firewall. The SSH connection will
be outbound, to port 80, 22 or 443 at supporthost.victronenergy.com. Remote support function is by default disabled.
13.17. Q17: I don’t see support for VE.Net products in the list, is that still com-
ing?
No.
Cerbo GX Manual
55