Network Firewall Requirements

Following are the Network Firewall Requirements for Gigamon fabrics for Nutanix deployments.

Reduced Control-Plane Ports

Starting in release 6.14.02, the number of ports required for control-plane communication is reduced from 12 ports to 3 ports (443, 5671, and 9902). The reduced control-plane ports decrease the number of ports you must open between GigaVUE‑FM and other fabric components while preserving management, registration, certificate exchange, and operational communication.

This change applies to control-plane traffic only. It does not change any data-path ports.

Use the minimum versions required for the reduced three-port configuration.

Component

Version

GigaVUE‑FM

6.14.02

GigaVUE V Series Node

6.14.01

GigaVUE V Series Proxy

6.14.01

UCT-V

6.14.01

UCT-V Controller

6.14.01

Important
■   Do not upgrade fabric components to version 6.14.01 unless GigaVUE‑FM is running version 6.14.02 or later.
■   Fabric components version 6.14.01 are incompatible with GigaVUE‑FM 6.14.00 and 6.14.01.
■   Deployments that use this unsupported version combination will not support reduced control-plane port communication and may not function correctly.

Choose the section that applies to your deployment scenario:

■   New Deployments – Use this section if you are deploying a new environment with GigaVUE‑FM 6.14.02 or later and all supported fabric components running version 6.14.01 or later. These deployments use only the reduced control-plane ports.
■   Existing Deployments – Use this section if you are upgrading an existing deployment and want to migrate from legacy control-plane ports to the reduced control-plane ports. This section identifies the ports to add and remove for each component during migration.
■   Legacy Control-Plane Ports – Use this section if GigaVUE‑FM is running a version earlier than 6.14.02, if any fabric component is running a version earlier than 6.14.01, or if your deployment requires backward compatibility during a mixed-version upgrade.

New Deployments

For new deployments, configure only the reduced control-plane ports. You do not need to open any legacy control-plane ports. Use the firewall requirements in this section when deploying a new GigaVUE Cloud Suite environment.

The reduced configuration uses only the three ports listed below:

Direction

Port

Purpose

Inbound/Outbound

443

HTTPS/REST management and control-plane communication, including GigaVUE‑FM UI/API access, component registration, and certificate-related requests.

Inbound

5671

RMQ/RA control-plane messaging and statistics or health updates between GigaVUE‑FM and fabric components.

Outbound

9902

RPC and control-plane communication, especially between UCT-V Controllers and UCT-V agent.

Existing Deployments

Existing deployments continue to operate without any firewall changes after upgrading GigaVUE‑FM and fabric components. Legacy control-plane ports remain supported for backward compatibility. You can continue to use the legacy control-plane ports or migrate to the reduced control-plane ports. For information about the legacy ports, refer to Legacy Control-Plane Ports

To migrate to the reduced control-plane ports, refer to Migration to Reduced Control-Plane Ports

Migration to Reduced Control-Plane Ports

If you are migrating your existing deployment from legacy control-plane ports to reduced control-plane ports, complete the following steps:

■   Upgrade the deployment while keeping the legacy ports open.
■   Verify that all upgraded components are in the supported versions.
■   Open the required reduced control-plane ports for GigaVUE‑FM, other fabric components, and the UCT-V Agent. Use the port requirements listed in Firewall Rule Changes for Migrating to Reduced Control-Plane Ports.
■   Use the Reset option to force the monitoring domain to reconnect by using the new ports. For more information, refer to the Manage a Monitoring Domain
■   Verify that all applicable components are communicating over ports 443, 5671, and 9902.
■   Remove the legacy ports from your firewall or security group rules after verification is complete.

Note:  Do not close all legacy ports and enable only the new ports before upgrading. Doing so can disrupt existing connections and is not recommended.

Firewall Rule Changes for Migrating to Reduced Control-Plane Ports

The following tables summarize the firewall changes to make when migrating an existing deployment:

GigaVUE‑FM

Action

Direction

Port

Remove

Inbound

9600

Remove

Outbound

8890

Remove

Outbound

8889

Remove

Outbound

80

Remove

Outbound

9990

Add

Inbound

443

Add

Inbound

5671

Add

Outbound

443

Add

Outbound

443

UCT-V Controller

Action

Direction

Port

Remove

Inbound

9900

Remove

Inbound

80

Remove

Inbound

8300

Remove

Inbound

8892

Remove

Outbound

9600

Remove

Outbound

8301

Add

Inbound

443

Add

Outbound

443

Add

Outbound

5671

Add

Outbound

9902

UCT-V

Action

Direction

Port

Remove

Inbound

8301

Remove

Outbound

8892

Remove

Outbound

9900

Remove

Outbound

8300

Add

Inbound

9902

Add

Outbound

5671

Add

Outbound

443

GigaVUE V Series Node

Action

Direction

Port

Remove

Inbound

8889

Remove

Inbound

80

Remove

Outbound

8891

Remove

Outbound

8892

Remove

Outbound

9600

Remove

Outbound

8300

Add

Inbound

443

Add

Outbound

443

Add

Outbound

5671

GigaVUE V Series Proxy (Optional)

Action

Direction

Port

Remove

Inbound

8890

Remove

Inbound

80

Remove

Inbound

8300

Remove

Inbound

8891

Remove

Inbound

8892

Remove

Outbound

8889

Remove

Outbound

9600

Remove

Outbound

80

Add

Inbound

5671

Add

Inbound

443

Add

Outbound

443

UCT-V OVS Controller

Action

Direction

Port

Remove

Inbound

9900

Add

Inbound

443

Add

Outbound

9901

UCT-V OVS Module

Action

Direction

Port

Add

Inbound

9901

The following tables identify the firewall changes required to migrate from the legacy control-plane ports to the optimized control-plane ports:

GigaVUE FM

The following table lists the reduced control-plane ports required for communication with GigaVUE-FM.

Direction

Protocol

Port

Replaces Legacy Port

Source CIDR2

Purpose

Inbound

TCP

443

9600

GigaVUE V Series Node IP

Allows GigaVUE‑FM to receive certificate requests from GigaVUE V Series Node.

Inbound

TCP

443

9600

GigaVUE V Series Proxy IP

Allows GigaVUE‑FM to receive certificate requests from GigaVUE V Series Proxy.

Direction

Protocol

Port

Replaces Legacy Port

Destination CIDR

Purpose

Outbound

TCP

443

8889

GigaVUE V Series Node IP

Allows GigaVUE‑FM to communicate control and management plane traffic to GigaVUE V Series Node.

Outbound

TCP

443

8890

GigaVUE V Series Proxy IP

Allows GigaVUE‑FM to communicate control and management plane traffic to GigaVUE V Series Proxy.

Outbound

TCP

443

9900

UCT-V Controller IP

Allows GigaVUE‑FM to communicate control and management plane traffic with UCT-V Controller.

Outbound

TCP

443

9900

OVS Controller

Controller management communication.

Removed: Outbound TCP 80 (ACME challenge) is no longer required. Certificate issuance and renewal for fabric nodes (6.14.01 or later) use JWK-based authentication instead of the ACME HTTP challenge.

UCT-V Controller

The following table lists the reduced control-plane ports required for communication with UCT-V Controller.

Direction

Protocol

Port

Replaces Legacy Port

Source CIDR

Purpose

Inbound

TCP

443

9900

GigaVUE‑FM IP

Allows UCT-V Controller to communicate control and management plane traffic with GigaVUE‑FM.

Inbound

TCP

443

8300

UCT-VSubnet

Allows UCT-V Controller to receive the certificate requests from the UCT-V.

Inbound

TCP

443

8892

UCT-V Subnet

Allows UCT-V Controller to receive the registration requests and heartbeat from UCT-V.

Inbound

TCP

443

9900

UCT-V or Subnet IP

 

Allows UCT-V Controller to receive traffic health updates from UCT-V.

Direction

Protocol

Port

Replaces Legacy Port

Destination CIDR

Purpose

Outbound

TCP

5671

NA

UCT-V Subnet

Allows the UCT-V Controller to communicate control and management plane traffic with UCT-Vs for monitoring domains created in 6.14.01 and later.

Outbound

TCP

9902

NA

UCT-V Subnet

Allows UCT-V Controller to communicate control and management plane traffic with UCT-Vs for UCT-Vs with version earlier than 6.14.01.

Removed: Inbound TCP 80 (ACME challenge from GigaVUE-FM), Outbound TCP 9600 (certificate request to GigaVUE-FM), and Outbound TCP 8301 (ACME validation to UCT-V) are no longer required for 6.14.01+ deployments.

Note:  For UCT-V Controller–to–UCT-V traffic, the controller uses 5671 for monitoring domains created in 6.14.01 and later, and 9902 for monitoring domains created in earlier releases. The UCT-V RPC port is configurable at the monitoring-domain level.

UCT-V

The following table lists the reduced control-plane ports required for communication with UCT-V.

Direction

Protocol

Port

Replaces Legacy Port

Source CIDR

Purpose

Inbound

TCP

5671

NA

UCT-V Controller IP

Allows UCT-V to receive control and management plane traffic from UCT-V Controller for monitoring domains created in 6.14.01 and later.

Inbound

TCP

9902

NA

UCT-V Controller IP

Allows UCT-V to receive control and management plane traffic from UCT-V Controller for existing monitoring domains created with version earlier than 6.14.01.

Direction

Protocol

Port

Replaces Legacy Port

Destination CIDR

Purpose

Outbound

TCP

443

9900

UCT-V Controller IP

Allows UCT-V to send traffic health updates to UCT-V Controller.

Outbound

(This is the port used for Third Party Orchestration)

TCP

443

8892

UCT-V Controller IP

Allows UCT-V to receive the registration requests and heartbeat to UCT-V Controller.

Outbound

TCP

443

8300

UCT-V Controller IP

Allows UCT-V to receive the certificate requests from the UCT-V Controller.

Removed: Inbound TCP 8301 (ACME challenge) is no longer required for 6.14.01 or later.

Note:  A 6.14.01 UCT-V listens on both 5671 and 9902 during discovery. The default listening port is 5671 for monitoring domains created in 6.14.01; monitoring domains migrated from earlier releases default to 9902. This port is configurable at the monitoring-domain level.

GigaVUE V Series Node

The following table lists the reduced control-plane ports required for communication with GigaVUE V Series Node.

Direction

Protocol

Port

Replaces Legacy Port

Source CIDR

Purpose

Inbound

TCP

443

8889

GigaVUE-FM IP

Allows GigaVUE V Series Node to communicate control and management plane traffic with GigaVUE-FM.

Direction

Protocol

Port

Replaces Legacy Port

Destination CIDR

Purpose

Outbound

TCP

5671

8300

GigaVUE V Series Proxy

Allows GigaVUE V Series Node to send certificate request to GigaVUE V Series Proxy IP.

Outbound

TCP

443

8891

GigaVUE V Series Proxy

Allows GigaVUE V Series Proxy to receive PKI requests from the GigaVUE V Series Node.

Outbound

TCP

443

8892

GigaVUE V Series Proxy

Allows GigaVUE V Series Proxy to receive registration requests and heartbeat messages from GigaVUE V Series Node.

Outbound

TCP

443

9600

GigaVUE-FM IP

Allows GigaVUE-FM to receive certificate requests from GigaVUE V Series Node.

Removed: Inbound TCP 80 (ACME challenge) is no longer required for 6.14.01 or later.

Note:   Cross-version deployments between GigaVUE V Series Nodes and GigaVUE V Series Proxy are not supported. Ensure that the GigaVUE V Series Node and GigaVUE V Series Proxy are running the same software version. For example, a 6.13 GigaVUE V Series Node cannot communicate with a 6.14 GigaVUE V Series Proxy.

GigaVUE V Series Proxy (Optional)

The following table lists the reduced control-plane ports required for communication with GigaVUE V Series Proxy.

Direction

Protocol

Port

Replaces Legacy Port

Source CIDR

Purpose

Inbound

TCP

443

8890

GigaVUE‑FM IP

Allows GigaVUE‑FM  to communicate control and management plane traffic with GigaVUE V Series Proxy.

Inbound

TCP

443

8891

GigaVUE V Series Node

Allows GigaVUE V Series Proxy to receive PKI requests from GigaVUE V Series Node.

Inbound

TCP

443

8892

GigaVUE V Series Node

Allows GigaVUE V Series Proxy to receive registration requests and heartbeat messages from GigaVUE V Series Node.

Inbound

TCP

5671

8300

GigaVUE V Series Node

 

Allows GigaVUE V Series Proxy to receive certificate requests from GigaVUE V Series Node for the configured params and provides the certificate using those parameters.

Direction

Protocol

Port

Replaces Legacy Port

Destination CIDR

Purpose

Outbound

TCP

443

9600

GigaVUE-FM IP

Allows GigaVUE-FM to receive certificate requests from GigaVUE V Series Proxy.

Removed: Inbound and outbound TCP 80 (ACME challenge) is no longer required for 6.14.01 or later.

UCT-V OVS Controller

The following table lists the reduced control-plane ports required for communication with UCT-V OVS Controller.

Direction

Protocol

Port

Replaces Legacy Port

Source CIDR

Purpose

Inbound

TCP

443

9900

GigaVUE‑FM IP

Allows GigaVUE‑FM  to communicate control and management plane traffic. The controller supports both ports for compatibility and falls back to 9900 when required.

Direction

Protocol

Port

Replaces Legacy Port

Destination CIDR

Purpose

Outbound

TCP

9901

NA

UCT-V OVS Module IP

Allows to communicate with UCT-V OVS Modules (RPC).

UCT-V OVS Module

The following table lists the reduced control-plane ports required for communication with UCT-V OVS Module.

Direction

Protocol

Port

Replaces Legacy Port

Source CIDR

Purpose

Inbound

TCP

9901

NA

UCT-V OVS Controller IP

Allows to receive control communication from UCT-V OVS Controller. The module listens on 9901 for backward compatibility.

Legacy Control-Plane Ports

Legacy control-plane ports remain supported for backward compatibility with earlier versions and mixed-version deployments.

When to Use Legacy Ports

■   GigaVUE‑FM is running version 6.10 or later but earlier than 6.14.02.
■   One or more fabric components (such as UCT-V Controller, UCT-V, GigaVUE V Series Node, GigaVUE V Series Proxy, or OVS components) are running a version earlier than 6.14.01.
■   This includes mixed-version deployments where GigaVUE‑FM 6.14.02 or later communicates with fabric components running N-1 or N-2 releases.
■   The deployment has not yet been migrated to the reduced control-plane port architecture.

GigaVUE-FM

Direction

Type

Protocol

Port

CIDR

Purpose

Inbound

HTTPS

TCP

443

Anywhere

Any IP

Allows GigaVUE® V Series Nodes, GigaVUE V Series Proxy, and GigaVUE‑FM administrators to communicate with GigaVUE‑FM

Inbound

SSH

TCP

22

Anywhere

Any IP

Allows GigaVUE® V Series Nodes, GigaVUE V Series Proxy, and GigaVUE‑FM administrators to communicate with GigaVUE‑FM

Outbound (optional)

Custom TCP Rule

TCP

8890

GigaVUE V Series Proxy IP

Allows GigaVUE‑FM to communicate with GigaVUE V Series Proxy

Outbound

Custom TCP Rule

TCP

8889

GigaVUE V Series Node IP

Allows GigaVUE‑FM to communicate with GigaVUE V Series Node

Outbound

Custom TCP Rule

TCP

9440

Prism Central IP, Prism Element IP

Allows GigaVUE‑FM to communicate with Prism Central and Prism Element.

GigaVUE V Series Node

Direction

Type

Protocol

Port

CIDR

Purpose

Inbound

Custom TCP Rule

TCP

9903

GigaVUE V Series Proxy IP

Allows GigaVUE V Series Proxy to communicate with GigaVUE® V Series Nodes

Inbound

UDP

UDPGRE

4754

Ingress Tunnel

Allows to UDPGRE tunnel to communicate and tunnel traffic toGigaVUE V Series Nodes

Outbound

Custom TCP Rule

TCP

5671

GigaVUE‑FM IP

Allows GigaVUE® V Series Node to communicate and tunnel traffic to the Tool

Outbound

Custom UDP Rule

UDP(VXLAN)
IP Protocol (L2GRE)
VXLAN (default 4789)
L2GRE (IP 47)

Tool IP

Allows GigaVUE® V Series Node to communicate and tunnel traffic to the Tool

Outbound (optional)

Custom ICMP Rule

ICMP

echo request
echo reply

Tool IP

Allows GigaVUE® V Series Node to health check the tunnel destination traffic.

GigaVUE V Series Proxy (optional)

Direction

Type

Protocol

Port

CIDR

Purpose

Inbound

Custom TCP Rule

TCP

8890

GigaVUE‑FM IP

Allows GigaVUE‑FM to communicate with GigaVUE V Series Proxy

Outbound

Custom TCP Rule

TCP

8889

GigaVUE V Series Node IP

Allows GigaVUE‑FM to communicate with GigaVUE V Series Node