How to set up the firewall for Portnox Docker containers to connect to Portnox Cloud

In this topic, you will learn how to configure your firewall to make sure that the Portnox Docker containers can communicate with Portnox Cloud.

You need to open the following ports on your firewall:

Container Address Protocol Ports Direction
All containers* 20.85.190.232/29 TCP 80, 443, 8081 Outbound
All containers* 20.67.6.144/29 TCP 80, 443, 8081 Outbound
All containers* 20.15.0.121/32 TCP 443 Outbound
All containers* 98.71.112.122/32 TCP 443 Outbound
Additionally:
portnox-siem portnox-centraal-prod.servicebus.windows.net TCP 443, 5671, 5672 Outbound
portnox-siem portnox-centraal-prod-eastus.servicebus.windows.net TCP 443, 5671, 5672 Outbound
portnox-siem siem-events-clear-prod-westeu.servicebus.windows.net TCP 443, 5671, 5672 Outbound
portnox-siem siem-events-clear-prod-eastus.servicebus.windows.net TCP 443, 5671, 5672 Outbound
portnox-siem pubsub-clear-prod-weu.webpubsub.azure.com TCP 443 Outbound
portnox-siem pubsub-clear-prod-eus.webpubsub.azure.com TCP 443 Outbound
portnox-dhcp 20.241.131.45 UDP 167 Outbound
portnox-dhcp 20.4.128.229 UDP 167 Outbound
ztna-gateway Any TCP 443 Outbound
ztna-gateway Any UDP 3478 Outbound
fw-id-mapper extfwint-local-gw.portnox.com TCP 443 Outbound

* – except fw-id-mapper.

Some Portnox Docker containers need to connect to Azure services that don’t have fixed static public IP addresses. In such cases, traffic must be allowed by domain name or you need to create and maintain scripts that verify current Azure IP addresses and update them on a regular basis.