Communication ports for managed devices

Managed devices use these ports to communicate. For deployments behind a network barrier—like an edge firewall—make sure you allow traffic on the required ports. Note that ports not required for essential or default operations remain closed until needed by a configuration or feature.

Inbound ports for managed devices

Managed devices accept inbound traffic on these ports.

Inbound ports for managed devices

Inbound port

Protocol/Feature

Details

Required for specific configurations or features

22/tcp

SSH

Secure remote connections to the appliance.

161/udp

SNMP

Allow access to MIBs via SNMP polling.

443/tcp

Remote access VPN (SSL)

Allow secure VPN connections to your network from remote users.

443/udp

Remote access VPN (DTLS)

Allow secure VPN connections to your network from remote users.

500/udp

4500/udp

Remote access VPN (IKEv2) and site-to-site VPN

Allow secure VPN connections to your network from remote users and remote VPN peers.

885/tcp

Captive portal

Communicate with a captive portal identity source.

8989/tcp

Cisco Support Diagnostics

Accepts authorized requests. Also initiates connections on this port.

Outbound ports for managed devices

Managed devices initiate outbound traffic on these ports. Managed devices also use ephemeral source ports for TCP and UDP traffic that they initiate. Make sure intervening network barriers allow response traffic for these connections.

Outbound ports for managed devices

Outbound port

Protocol/Feature

Details

Required for initial setup

53/tcp

53/udp

DNS

DNS

123/udp

NTP

Synchronize time.

443/tcp

HTTPS

Send and receive data from the internet; see Internet access requirements for managed devices for a list of resources that the device needs to access. Also accepts connections on this port.

8305/tcp

Appliance communications

Securely communicate with the Cloud-Delivered Firewall Management Center.

Required for specific configurations or features

67/udp

68/udp

DHCP

DHCP

162/udp

SNMP

Send SNMP alerts to a remote trap server.

1812/udp

1813/udp

RADIUS

Communicate with a RADIUS server for external authentication and accounting.

Configurable.

389/tcp

636/tcp

LDAP

Communicate with an LDAP server for external authentication.

Configurable.

514/udp

Syslog (audit logging)

Send audit logs to a remote syslog server, when TLS is not configured.

8514/udp

Secure Network Analytics Manager

Send syslog messages to Secure Network Analytics using Security Analytics and Logging (On Premises).

8989/tcp

Cisco Support Diagnostics

Transmits usage information and statistics. Also accepts connections on this port.