DellPowerConnect W- Series ArubaOS 6.2 | User Guide ExternalFirewall Configuration | 507
Chapte r 29

External Firew all Configuration

In many deployment scenarios, an externalfirewall is sit uated between Dell devices. This appendix describes the
network ports that needt o be configuredon the external firewall to allow properoperation of the Dell network. You
can alsouse this information to configure session ACLs to apply to physical ports on the controllerfor enhanced
security. Note, however, that this appendix does not describe requirements for allowing specific types of user traffic
on the network.
NOTE:A controll er uses bothi tsl oopback address and VLAN addressesfor com munications with other network elements. If the
firewall uses host-specificACLS, those ACLs must specify all IP addresses usedon the controller.
Topics in this chapter include:
l"UnderstandingFirewall Port Configuration Among Dell Devices" o n page 507
l"EnablingNetwo rkA ccess" on page 508
l"Ports Used for Virtual Internet Access (VIA )" on page 508
l"ConfiguringPorts t o Allow Other Traffic Types" on page 508

Understanding F irewall Port Configuration Among De ll Devices

This section describes the network ports that need to be configuredo nt hefirewall to allow proper operation of the
network.
Between any two Dell controllers:
lIPSec (UDP ports 500 and 45 00) and ESP (protocol 50). PAPI between a master and a local controlleris
encapsulatedin I PSec.
lIP-IP (protocol 94) and UDP port 443 if Layer-3 mobility is enabled.
lGRE (protocol 47) if tunnelingguest traffic over GRE to DMZco ntroller.
lIKE (UDP 500).
lESP (protocol 50).
lNAT-T (UDP 4500).
Between an AP and the controller:
lPAPI (UDP port 82 11). If the AP uses DNS to discover the LMS controller, the AP first attempts to connect to
the master controller.(Also allow DNS (UDP port 5 3) traffic fromthe AP to the DNS server.)
lPAPI (UDP port 8211). All APs running asA irMonito rs(AMs) require a permanentPA PI connection to the
master controller.
lFTP (TCP port 21).
lTFTP (UDP port 69) all APs, if there is no local image on the AP (for example, a new AP) the AP will use TFTP
to retrieve the initial image.
lSYSLOG(UDP port 514).
lPAPI (UDP port 8211).