Network Firewall Requirements
Following are the Network Firewall Requirements for Gigamon fabrics for Nutanix deployments.
Reduced Control-Plane Ports
Starting in release 6.14.02, the number of ports required for control-plane communication is reduced from 12 ports to 3 ports (443, 5671, and 9902). The reduced control-plane ports decrease the number of ports you must open between GigaVUE‑FM and other fabric components while preserving management, registration, certificate exchange, and operational communication.
This change applies to control-plane traffic only. It does not change any data-path ports.
Use the minimum versions required for the reduced three-port configuration.
|
Component |
Version |
|
GigaVUE‑FM |
6.14.02 |
|
GigaVUE V Series Node |
6.14.01 |
|
GigaVUE V Series Proxy |
6.14.01 |
|
UCT-V |
6.14.01 |
|
UCT-V Controller |
6.14.01 |
| Do not upgrade fabric components to version 6.14.01 unless GigaVUE‑FM is running version 6.14.02 or later. |
| Fabric components version 6.14.01 are incompatible with GigaVUE‑FM 6.14.00 and 6.14.01. |
| Deployments that use this unsupported version combination will not support reduced control-plane port communication and may not function correctly. |
Choose the section that applies to your deployment scenario:
| New Deployments – Use this section if you are deploying a new environment with GigaVUE‑FM 6.14.02 or later and all supported fabric components running version 6.14.01 or later. These deployments use only the reduced control-plane ports. |
| Existing Deployments – Use this section if you are upgrading an existing deployment and want to migrate from legacy control-plane ports to the reduced control-plane ports. This section identifies the ports to add and remove for each component during migration. |
| Legacy Control-Plane Ports – Use this section if GigaVUE‑FM is running a version earlier than 6.14.02, if any fabric component is running a version earlier than 6.14.01, or if your deployment requires backward compatibility during a mixed-version upgrade. |
New Deployments
For new deployments, configure only the reduced control-plane ports. You do not need to open any legacy control-plane ports. Use the firewall requirements in this section when deploying a new GigaVUE Cloud Suite environment.
The reduced configuration uses only the three ports listed below:
|
Direction |
Port |
Purpose |
|
Inbound/Outbound |
443 |
HTTPS/REST management and control-plane communication, including GigaVUE‑FM UI/API access, component registration, and certificate-related requests. |
|
Inbound |
5671 |
RMQ/RA control-plane messaging and statistics or health updates between GigaVUE‑FM and fabric components. |
|
Outbound |
9902 |
RPC and control-plane communication, especially between UCT-V Controllers and UCT-V agent. |
Existing Deployments
Existing deployments continue to operate without any firewall changes after upgrading GigaVUE‑FM and fabric components. Legacy control-plane ports remain supported for backward compatibility. You can continue to use the legacy control-plane ports or migrate to the reduced control-plane ports. For information about the legacy ports, refer to Legacy Control-Plane Ports
To migrate to the reduced control-plane ports, refer to Migration to Reduced Control-Plane Ports
Migration to Reduced Control-Plane Ports
If you are migrating your existing deployment from legacy control-plane ports to reduced control-plane ports, complete the following steps:
| Upgrade the deployment while keeping the legacy ports open. |
| Verify that all upgraded components are in the supported versions. |
| Open the required reduced control-plane ports for GigaVUE‑FM, other fabric components, and the UCT-V Agent. Use the port requirements listed in Firewall Rule Changes for Migrating to Reduced Control-Plane Ports. |
| Use the Reset option to force the monitoring domain to reconnect by using the new ports. For more information, refer to the Manage a Monitoring Domain |
| Verify that all applicable components are communicating over ports 443, 5671, and 9902. |
| Remove the legacy ports from your firewall or security group rules after verification is complete. |
Note: Do not close all legacy ports and enable only the new ports before upgrading. Doing so can disrupt existing connections and is not recommended.
Firewall Rule Changes for Migrating to Reduced Control-Plane Ports
The following tables summarize the firewall changes to make when migrating an existing deployment:
GigaVUE‑FM
|
Action |
Direction |
Port |
|
Remove |
Inbound |
9600 |
|
Remove |
Outbound |
8890 |
|
Remove |
Outbound |
8889 |
|
Remove |
Outbound |
80 |
|
Remove |
Outbound |
9990 |
|
Add |
Inbound |
443 |
|
Add |
Inbound |
5671 |
|
Add |
Outbound |
443 |
|
Add |
Outbound |
443 |
UCT-V Controller
|
Action |
Direction |
Port |
|
Remove |
Inbound |
9900 |
|
Remove |
Inbound |
80 |
|
Remove |
Inbound |
8300 |
|
Remove |
Inbound |
8892 |
|
Remove |
Outbound |
9600 |
|
Remove |
Outbound |
8301 |
|
Add |
Inbound |
443 |
|
Add |
Outbound |
443 |
|
Add |
Outbound |
5671 |
|
Add |
Outbound |
9902 |
UCT-V
|
Action |
Direction |
Port |
|
Remove |
Inbound |
8301 |
|
Remove |
Outbound |
8892 |
|
Remove |
Outbound |
9900 |
|
Remove |
Outbound |
8300 |
|
Add |
Inbound |
9902 |
|
Add |
Outbound |
5671 |
|
Add |
Outbound |
443 |
GigaVUE V Series Node
|
Action |
Direction |
Port |
|
Remove |
Inbound |
8889 |
|
Remove |
Inbound |
80 |
|
Remove |
Outbound |
8891 |
|
Remove |
Outbound |
8892 |
|
Remove |
Outbound |
9600 |
|
Remove |
Outbound |
8300 |
|
Add |
Inbound |
443 |
|
Add |
Outbound |
443 |
|
Add |
Outbound |
5671 |
GigaVUE V Series Proxy (Optional)
|
Action |
Direction |
Port |
|
Remove |
Inbound |
8890 |
|
Remove |
Inbound |
80 |
|
Remove |
Inbound |
8300 |
|
Remove |
Inbound |
8891 |
|
Remove |
Inbound |
8892 |
|
Remove |
Outbound |
8889 |
|
Remove |
Outbound |
9600 |
|
Remove |
Outbound |
80 |
|
Add |
Inbound |
5671 |
|
Add |
Inbound |
443 |
|
Add |
Outbound |
443 |
UCT-V OVS Controller
|
Action |
Direction |
Port |
|
Remove |
Inbound |
9900 |
|
Add |
Inbound |
443 |
|
Add |
Outbound |
9901 |
UCT-V OVS Module
|
Action |
Direction |
Port |
|
Add |
Inbound |
9901 |
The following tables identify the firewall changes required to migrate from the legacy control-plane ports to the optimized control-plane ports:
GigaVUE FM
The following table lists the reduced control-plane ports required for communication with GigaVUE-FM.
|
Direction |
Protocol |
Port |
Replaces Legacy Port |
Source CIDR2 |
Purpose |
|
Inbound |
TCP |
443 |
9600 |
GigaVUE V Series Node IP |
Allows GigaVUE‑FM to receive certificate requests from GigaVUE V Series Node. |
|
Inbound |
TCP |
443 |
9600 |
GigaVUE V Series Proxy IP |
Allows GigaVUE‑FM to receive certificate requests from GigaVUE V Series Proxy. |
|
Direction |
Protocol |
Port |
Replaces Legacy Port |
Destination CIDR |
Purpose |
|
Outbound |
TCP |
443 |
8889 |
GigaVUE V Series Node IP |
Allows GigaVUE‑FM to communicate control and management plane traffic to GigaVUE V Series Node. |
|
Outbound |
TCP |
443 |
8890 |
GigaVUE V Series Proxy IP |
Allows GigaVUE‑FM to communicate control and management plane traffic to GigaVUE V Series Proxy. |
|
Outbound |
TCP |
443 |
9900 |
UCT-V Controller IP |
Allows GigaVUE‑FM to communicate control and management plane traffic with UCT-V Controller. |
|
Outbound |
TCP |
443 |
9900 |
OVS Controller |
Controller management communication. |
UCT-V Controller
The following table lists the reduced control-plane ports required for communication with UCT-V Controller.
|
Direction |
Protocol |
Port |
Replaces Legacy Port |
Source CIDR |
Purpose |
|
Inbound |
TCP |
443 |
9900 |
GigaVUE‑FM IP |
Allows UCT-V Controller to communicate control and management plane traffic with GigaVUE‑FM. |
|
Inbound |
TCP |
443 |
8300 |
UCT-VSubnet |
Allows UCT-V Controller to receive the certificate requests from the UCT-V. |
|
Inbound |
TCP |
443 |
8892 |
UCT-V Subnet |
Allows UCT-V Controller to receive the registration requests and heartbeat from UCT-V. |
|
Inbound |
TCP |
443 |
9900 |
UCT-V or Subnet IP
|
Allows UCT-V Controller to receive traffic health updates from UCT-V. |
|
Direction |
Protocol |
Port |
Replaces Legacy Port |
Destination CIDR |
Purpose |
|
Outbound |
TCP |
5671 |
NA |
UCT-V Subnet |
Allows the UCT-V Controller to communicate control and management plane traffic with UCT-Vs for monitoring domains created in 6.14.01 and later. |
|
Outbound |
TCP |
9902 |
NA |
UCT-V Subnet |
Allows UCT-V Controller to communicate control and management plane traffic with UCT-Vs for UCT-Vs with version earlier than 6.14.01. |
Note: For UCT-V Controller–to–UCT-V traffic, the controller uses 5671 for monitoring domains created in 6.14.01 and later, and 9902 for monitoring domains created in earlier releases. The UCT-V RPC port is configurable at the monitoring-domain level.
UCT-V
The following table lists the reduced control-plane ports required for communication with UCT-V.
|
Direction |
Protocol |
Port |
Replaces Legacy Port |
Source CIDR |
Purpose |
|
Inbound |
TCP |
5671 |
NA |
UCT-V Controller IP |
Allows UCT-V to receive control and management plane traffic from UCT-V Controller for monitoring domains created in 6.14.01 and later. |
|
Inbound |
TCP |
9902 |
NA |
UCT-V Controller IP |
Allows UCT-V to receive control and management plane traffic from UCT-V Controller for existing monitoring domains created with version earlier than 6.14.01. |
|
Direction |
Protocol |
Port |
Replaces Legacy Port |
Destination CIDR |
Purpose |
|
Outbound |
TCP |
443 |
9900 |
UCT-V Controller IP |
Allows UCT-V to send traffic health updates to UCT-V Controller. |
|
Outbound (This is the port used for Third Party Orchestration) |
TCP |
443 |
8892 |
UCT-V Controller IP |
Allows UCT-V to receive the registration requests and heartbeat to UCT-V Controller. |
|
Outbound |
TCP |
443 |
8300 |
UCT-V Controller IP |
Allows UCT-V to receive the certificate requests from the UCT-V Controller. |
Note: A 6.14.01 UCT-V listens on both 5671 and 9902 during discovery. The default listening port is 5671 for monitoring domains created in 6.14.01; monitoring domains migrated from earlier releases default to 9902. This port is configurable at the monitoring-domain level.
GigaVUE V Series Node
The following table lists the reduced control-plane ports required for communication with GigaVUE V Series Node.
|
Direction |
Protocol |
Port |
Replaces Legacy Port |
Source CIDR |
Purpose |
|
Inbound |
TCP |
443 |
8889 |
GigaVUE-FM IP |
Allows GigaVUE V Series Node to communicate control and management plane traffic with GigaVUE-FM. |
|
Direction |
Protocol |
Port |
Replaces Legacy Port |
Destination CIDR |
Purpose |
|
Outbound |
TCP |
5671 |
8300 |
GigaVUE V Series Proxy |
Allows GigaVUE V Series Node to send certificate request to GigaVUE V Series Proxy IP. |
|
Outbound |
TCP |
443 |
8891 |
GigaVUE V Series Proxy |
Allows GigaVUE V Series Proxy to receive PKI requests from the GigaVUE V Series Node. |
|
Outbound |
TCP |
443 |
8892 |
GigaVUE V Series Proxy |
Allows GigaVUE V Series Proxy to receive registration requests and heartbeat messages from GigaVUE V Series Node. |
|
Outbound |
TCP |
443 |
9600 |
GigaVUE-FM IP |
Allows GigaVUE-FM to receive certificate requests from GigaVUE V Series Node. |
Note: Cross-version deployments between GigaVUE V Series Nodes and GigaVUE V Series Proxy are not supported. Ensure that the GigaVUE V Series Node and GigaVUE V Series Proxy are running the same software version. For example, a 6.13 GigaVUE V Series Node cannot communicate with a 6.14 GigaVUE V Series Proxy.
GigaVUE V Series Proxy (Optional)
The following table lists the reduced control-plane ports required for communication with GigaVUE V Series Proxy.
|
Direction |
Protocol |
Port |
Replaces Legacy Port |
Source CIDR |
Purpose |
|
Inbound |
TCP |
443 |
8890 |
GigaVUE‑FM IP |
Allows GigaVUE‑FM to communicate control and management plane traffic with GigaVUE V Series Proxy. |
|
Inbound |
TCP |
443 |
8891 |
GigaVUE V Series Node |
Allows GigaVUE V Series Proxy to receive PKI requests from GigaVUE V Series Node. |
|
Inbound |
TCP |
443 |
8892 |
GigaVUE V Series Node |
Allows GigaVUE V Series Proxy to receive registration requests and heartbeat messages from GigaVUE V Series Node. |
|
Inbound |
TCP |
5671 |
8300 |
GigaVUE V Series Node
|
Allows GigaVUE V Series Proxy to receive certificate requests from GigaVUE V Series Node for the configured params and provides the certificate using those parameters. |
|
Direction |
Protocol |
Port |
Replaces Legacy Port |
Destination CIDR |
Purpose |
|
Outbound |
TCP |
443 |
9600 |
GigaVUE-FM IP |
Allows GigaVUE-FM to receive certificate requests from GigaVUE V Series Proxy. |
UCT-V OVS Controller
The following table lists the reduced control-plane ports required for communication with UCT-V OVS Controller.
|
Direction |
Protocol |
Port |
Replaces Legacy Port |
Source CIDR |
Purpose |
|
Inbound |
TCP |
443 |
9900 |
GigaVUE‑FM IP |
Allows GigaVUE‑FM to communicate control and management plane traffic. The controller supports both ports for compatibility and falls back to 9900 when required. |
|
Direction |
Protocol |
Port |
Replaces Legacy Port |
Destination CIDR |
Purpose |
|
Outbound |
TCP |
9901 |
NA |
UCT-V OVS Module IP |
Allows to communicate with UCT-V OVS Modules (RPC). |
UCT-V OVS Module
The following table lists the reduced control-plane ports required for communication with UCT-V OVS Module.
|
Direction |
Protocol |
Port |
Replaces Legacy Port |
Source CIDR |
Purpose |
|
Inbound |
TCP |
9901 |
NA |
UCT-V OVS Controller IP |
Allows to receive control communication from UCT-V OVS Controller. The module listens on 9901 for backward compatibility. |
Legacy Control-Plane Ports
Legacy control-plane ports remain supported for backward compatibility with earlier versions and mixed-version deployments.
When to Use Legacy Ports
| GigaVUE‑FM is running version 6.10 or later but earlier than 6.14.02. |
| One or more fabric components (such as UCT-V Controller, UCT-V, GigaVUE V Series Node, GigaVUE V Series Proxy |
| This includes mixed-version deployments where GigaVUE‑FM 6.14.02 or later communicates with fabric components running N-1 or N-2 releases. |
| The deployment has not yet been migrated to the reduced control-plane port architecture. |
GigaVUE-FM
|
Direction |
Type |
Protocol |
Port |
CIDR |
Purpose |
|
Inbound |
HTTPS |
TCP |
443 |
Anywhere Any IP |
Allows GigaVUE® V Series Nodes, GigaVUE V Series Proxy, and GigaVUE‑FM administrators to communicate with GigaVUE‑FM |
|
Inbound |
SSH |
TCP |
22 |
Anywhere Any IP |
Allows GigaVUE® V Series Nodes, GigaVUE V Series Proxy, and GigaVUE‑FM administrators to communicate with GigaVUE‑FM |
|
Outbound (optional) |
Custom TCP Rule |
TCP |
8890 |
GigaVUE V Series Proxy IP |
Allows GigaVUE‑FM to communicate with GigaVUE V Series Proxy |
|
Outbound |
Custom TCP Rule |
TCP |
8889 |
GigaVUE V Series Node IP |
Allows GigaVUE‑FM to communicate with GigaVUE V Series Node |
|
Outbound |
Custom TCP Rule |
TCP |
9440 |
Prism Central IP, Prism Element IP |
Allows GigaVUE‑FM to communicate with Prism Central and Prism Element. |
GigaVUE V Series Node
|
Direction |
Type |
Protocol |
Port |
CIDR |
Purpose |
||||||||||||
|
Inbound |
Custom TCP Rule |
TCP |
9903 |
GigaVUE V Series Proxy IP |
Allows GigaVUE V Series Proxy to communicate with GigaVUE® V Series Nodes |
||||||||||||
|
Inbound |
UDP |
UDPGRE |
4754 |
Ingress Tunnel |
Allows to UDPGRE tunnel to communicate and tunnel traffic toGigaVUE V Series Nodes |
||||||||||||
|
Outbound |
Custom TCP Rule |
TCP |
5671 |
GigaVUE‑FM IP |
Allows GigaVUE® V Series Node to communicate and tunnel traffic to the Tool |
||||||||||||
|
Outbound |
Custom UDP Rule |
|
|
Tool IP |
Allows GigaVUE® V Series Node to communicate and tunnel traffic to the Tool |
||||||||||||
|
Outbound (optional) |
Custom ICMP Rule |
ICMP |
|
Tool IP |
Allows GigaVUE® V Series Node to health check the tunnel destination traffic. |
GigaVUE V Series Proxy (optional)
|
Direction |
Type |
Protocol |
Port |
CIDR |
Purpose |
|
Inbound |
Custom TCP Rule |
TCP |
8890 |
GigaVUE‑FM IP |
Allows GigaVUE‑FM to communicate with GigaVUE V Series Proxy |
|
Outbound |
Custom TCP Rule |
TCP |
8889 |
GigaVUE V Series Node IP |
Allows GigaVUE‑FM to communicate with GigaVUE V Series Node |



