Communication ports for managed devices
Managed devices use these ports to communicate. For deployments behind a network barrier—like an edge firewall—make sure you allow traffic on the required ports. Note that ports not required for essential or default operations remain closed until needed by a configuration or feature.
Inbound ports for managed devices
Managed devices accept inbound traffic on these ports.
|
Inbound port |
Protocol/Feature |
Details |
|---|---|---|
|
Required for specific configurations or features |
||
|
22/tcp |
SSH |
Secure remote connections to the appliance. |
|
161/udp |
SNMP |
Allow access to MIBs via SNMP polling. |
|
443/tcp |
Remote access VPN (SSL) |
Allow secure VPN connections to your network from remote users. |
|
443/udp |
Remote access VPN (DTLS) |
Allow secure VPN connections to your network from remote users. |
|
500/udp 4500/udp |
Remote access VPN (IKEv2) and site-to-site VPN |
Allow secure VPN connections to your network from remote users and remote VPN peers. |
|
885/tcp |
Captive portal |
Communicate with a captive portal identity source. |
|
8989/tcp |
Cisco Support Diagnostics |
Accepts authorized requests. Also initiates connections on this port. |
Outbound ports for managed devices
Managed devices initiate outbound traffic on these ports. Managed devices also use ephemeral source ports for TCP and UDP traffic that they initiate. Make sure intervening network barriers allow response traffic for these connections.
|
Outbound port |
Protocol/Feature |
Details |
|---|---|---|
|
Required for initial setup |
||
|
53/tcp 53/udp |
DNS |
DNS |
|
123/udp |
NTP |
Synchronize time. |
|
443/tcp |
HTTPS |
Send and receive data from the internet; see Internet access requirements for managed devices for a list of resources that the device needs to access. Also accepts connections on this port. |
|
8305/tcp |
Appliance communications |
Securely communicate with the Cloud-Delivered Firewall Management Center. |
|
Required for specific configurations or features |
||
|
67/udp 68/udp |
DHCP |
DHCP |
|
162/udp |
SNMP |
Send SNMP alerts to a remote trap server. |
|
1812/udp 1813/udp |
RADIUS |
Communicate with a RADIUS server for external authentication and accounting. Configurable. |
|
389/tcp 636/tcp |
LDAP |
Communicate with an LDAP server for external authentication. Configurable. |
|
514/udp |
Syslog (audit logging) |
Send audit logs to a remote syslog server, when TLS is not configured. |
|
8514/udp |
Secure Network Analytics Manager |
Send syslog messages to Secure Network Analytics using Security Analytics and Logging (On Premises). |
|
8989/tcp |
Cisco Support Diagnostics |
Transmits usage information and statistics. Also accepts connections on this port. |