How to set up the firewall for Portnox Docker containers to connect to Portnox Cloud
In this topic, you will learn how to configure your firewall to make sure that the Portnox Docker containers can communicate with Portnox Cloud.
You need to open the following ports on your firewall:
| Container | Address | Protocol | Ports | Direction |
|---|---|---|---|---|
| All containers* | 20.85.190.232/29 | TCP | 80, 443, 8081 | Outbound |
| All containers* | 20.67.6.144/29 | TCP | 80, 443, 8081 | Outbound |
| All containers* | 20.15.0.121/32 | TCP | 443 | Outbound |
| All containers* | 98.71.112.122/32 | TCP | 443 | Outbound |
| Additionally: | ||||
| portnox-siem | portnox-centraal-prod.servicebus.windows.net | TCP | 443, 5671, 5672 | Outbound |
| portnox-siem | portnox-centraal-prod-eastus.servicebus.windows.net | TCP | 443, 5671, 5672 | Outbound |
| portnox-siem | siem-events-clear-prod-westeu.servicebus.windows.net | TCP | 443, 5671, 5672 | Outbound |
| portnox-siem | siem-events-clear-prod-eastus.servicebus.windows.net | TCP | 443, 5671, 5672 | Outbound |
| portnox-siem | pubsub-clear-prod-weu.webpubsub.azure.com | TCP | 443 | Outbound |
| portnox-siem | pubsub-clear-prod-eus.webpubsub.azure.com | TCP | 443 | Outbound |
| portnox-dhcp | 20.241.131.45 | UDP | 167 | Outbound |
| portnox-dhcp | 20.4.128.229 | UDP | 167 | Outbound |
| ztna-gateway | Any | TCP | 443 | Outbound |
| ztna-gateway | Any | UDP | 3478 | Outbound |
| fw-id-mapper | extfwint-local-gw.portnox.com | TCP | 443 | Outbound |
* – except fw-id-mapper.
Some Portnox Docker containers need to connect to Azure services that don’t have fixed static public IP addresses. In such cases, traffic must be allowed by domain name or you need to create and maintain scripts that verify current Azure IP addresses and update them on a regular basis.
