Remote Collector Ports

For more information, see TOS Aurora Architecture.

Source Destination Service / Port Description
Administrator's PC

All Cluster Nodes Network IPs

SSH <TCP 22>

Mandatory

Used for system maintenance

All Cluster Nodes Network IPs

All Cluster Nodes Network IPs

TCP <TCP 7472>

Required for all deployments except Azure/AWS/GCP

Used by MetalLB speaker

All Cluster Nodes Network IPs

All Cluster Nodes Network IPs

UCP <UDP 323>

Mandatory

Used for Chrony

All Cluster Nodes Network IPs

DNS Server

DNS <UDP 53>

Mandatory

Used for domain lookups

All Cluster Nodes Network IPs

NTP Server

NTP <UDP 123>

Required if NTP is used for network time synchronization

All Cluster Nodes Network IPs

Syslog Server

Syslog <UDP 514> (default) or alternative port as configured

Required if you configure notifications via syslog.
Administrator's PC

RMM interfaces on all Tufin Appliances

Web GUI <TCP 80> or <TCP 443> (SSL certificate upload available)

Unencrypted: KVM <TCP 7578>

CDROM <TCP 5120>

USB <TCP 5123>

Encrypted (AES/RC4/Stunnel):

KVM <TCP 7582>

CDROM <TCP 5124>

USB <TCP 5127>

Required for Tufin appliances only.

Used for remote management module (RMM) network card address.

See also:

Configuring RMM for Gen 4

Configuring RMM for Gen 3.5

All Cluster Nodes Network IPs

All Cluster Nodes Network IPs

UDP 51820 Mandatory K3s server and agent nodes required by Wireguard

All Cluster Nodes Network IPs

All Cluster Nodes Network IPs

HTTPS <TCP 2379-2381> Mandatory Etcd server communication

All Cluster Nodes Network IPs

All Cluster Nodes Network IPs

HTTPS <TCP 6443-6444>

Mandatory

Kubernetes API Server

All Cluster Nodes Network IPs

All Cluster Nodes Network IPs

Application Specific <TCP/UDP 30000-32767>

Mandatory

Kubernetes internal service range

All Cluster Nodes Network IPs

All Cluster Nodes Network IPs

HTTPS <TCP 10248-10252,10255, 10256>

Mandatory

Kubernetes components

All Cluster Nodes Network IPs

All Cluster Nodes Network IPs

HTTPS <TCP 32500>

Mandatory

Docker registry

All Cluster Nodes Network IPs

All Cluster Nodes Network IPs

HTTPS <TCP 9100>

Mandatory

Kubernetes node-exporter

All Cluster Nodes Network IPs

All Cluster Nodes Network IPs

HTTPS <TCP 8080>

Required for adding and removing nodes from the cluster

Remote Collector cluster nodes network IPs

Central Cluster primary VIP

HTTPS <TCP 443, 8443, 61617, 8422, 9090>

For high availability, additionally: HTTPS <TCP 8423, 8424>

Required for connecting remote collector clusters

Allows central cluster to receive data from remote collector cluster

Remote Collector cluster nodes network IPs

  • External Load balancer VIP

  • All Cluster Nodes Network IPs

HTTPS <TCP 31443, 31617, 31843,31422, 31090>

For high availability, additionally: HTTPS <TCP 31423, 31424>

Required for connecting remote collector clusters

Allows central cluster to receive data from remote collector cluster

For a Central Cluster deployed on the cloud

All Central Cluster Nodes Network IPs

Remote collector cluster Primary VIP

HTTPS <TCP 8443>

Mandatory
Required for remote collector clusters

Allows remote collector cluster to receive data from central cluster