Port Information for Firewalls

Map the following service ports to the Service Set VRRP IP addresses listed in IP address relationship between the cluster's direct interfaces and external access.

ExtremeCloud IQ on-premises installations require access to ExtremeCloud IQ core services. Make sure the firewall configuration allows for access to ExtremeCloud IQ core services.

The following tables list outbound ports for use when the firewall configuration requires rules that enable outbound traffic.

Basic Access for ExtremeCloud Services

This is required for ExtremeCloud applications to run properly on ExtremeCloud Edge RDC.

Table 1. Firewall Configuration Details (Outbound Traffic)
Domain Name IPv4 Addresses Protocol Port
hac.extremecloudiq.com 34.253.190.192 ~ 34.253.190.255 HTTPS 443
<rdc>-inlets.extremecloudiq.com Dynamic IP range TCP 8090
hmupdates-ng.aerohive.com 54.86.95.132 HTTPS 443
extremecloudiq.com 34.253.190.192 ~ 34.253.190.255 HTTPS 443
18.194.95.0 ~ 18.194.95.15
3.234.248.0 ~ 3.234.248.31
44.234.22.92 ~ 44.234.22.95
mx.extremecloudiq.com 34.202.197.56/57 TCP 587
stun.extremecloudiq.com 3.234.248.28 - 29 UDP 12222
api.ip2location.com Dynamic IP range HTTPS 443
docker.io Dynamic IP range HTTPS 443
gcr.io Dynamic IP range HTTPS 443
Amazon S3 Dynamic IP range HTTPS 443
NTP Service <Any NTP Server IP> UDP/TCP 123
extremeportal.force.com Dynamic IP range HTTPS 443
prod.extreme.sentinelcloud.com Dynamic IP range HTTPS 443
cloud-status.extremecloudiq.com 18.67.39.6 HTTPS 443
cloud-cdn2.extremecloudiq.com Dynamic IP range HTTPS 443
rest.nexmo.com Dynamic IP range HTTPS 443

Access

Table 2. Outbound Traffic
Domain Name IPv4 Addresses Protocol Port
lc-eu.extremecloudiq.com 3.64.95.0/29 HTTPS