Network Firewall Requirement
Reduced Control-Plane Ports
Starting in release 6.14.02, the number of ports required for control-plane communication is reduced from 12 ports to 3 ports (443, 5671, and 9902). The reduced control-plane ports decrease the number of ports you must open between GigaVUE‑FM and other fabric components while preserving management, registration, certificate exchange, and operational communication.
This change applies to control-plane traffic only. It does not change any data-path ports.
Use the minimum versions required for the reduced three-port configuration.
|
Component |
Version |
|
GigaVUE‑FM |
6.14.02 |
|
GigaVUE V Series Node |
6.14.01 |
|
GigaVUE V Series Proxy |
6.14.01 |
|
UCT-V |
6.14.01 |
|
UCT-V Controller |
6.14.01 |
| Do not upgrade fabric components to version 6.14.01 unless GigaVUE‑FM is running version 6.14.02 or later. |
| Fabric components version 6.14.01 are incompatible with GigaVUE‑FM 6.14.00 and 6.14.01. |
| Deployments that use this unsupported version combination will not support reduced control-plane port communication and may not function correctly. |
Choose the section that applies to your deployment scenario:
| New Deployments – Use this section if you are deploying a new environment with GigaVUE‑FM 6.14.02 or later and all supported fabric components running version 6.14.01 or later. These deployments use only the reduced control-plane ports. |
| Existing Deployments – Use this section if you are upgrading an existing deployment and want to migrate from legacy control-plane ports to the reduced control-plane ports. This section identifies the ports to add and remove for each component during migration. |
| Legacy Control-Plane Ports – Use this section if GigaVUE‑FM is running a version earlier than 6.14.02, if any fabric component is running a version earlier than 6.14.01, or if your deployment requires backward compatibility during a mixed-version upgrade. |
New Deployments
For new deployments, configure only the reduced control-plane ports. You do not need to open any legacy control-plane ports. Use the firewall requirements in this section when deploying a new GigaVUE Cloud Suite environment.
The reduced configuration uses only the three ports listed below:
|
Direction |
Port |
Purpose |
|
Inbound/Outbound |
443 |
HTTPS/REST management and control-plane communication, including GigaVUE‑FM UI/API access, component registration, and certificate-related requests. |
|
Inbound/Outbound |
5671 |
RMQ/RA control-plane messaging and statistics or health updates between GigaVUE‑FM and fabric components. |
|
Inbound/Outbound |
9902 |
RPC and control-plane communication, especially between UCT-V Controllers and UCT-V agent. |
Existing Deployments
Existing deployments continue to operate without any firewall changes after upgrading GigaVUE‑FM and fabric components. Legacy control-plane ports remain supported for backward compatibility. You can continue to use the legacy control-plane ports or migrate to the reduced control-plane ports. For information about the legacy ports, refer to Legacy Control-Plane Ports
To migrate to the reduced control-plane ports, refer to Migration to Reduced Control-Plane Ports
Migration to Reduced Control-Plane Ports
If you are migrating your existing deployment from legacy control-plane ports to reduced control-plane ports, complete the following steps:
| Upgrade the deployment while keeping the legacy ports open. |
| Verify that all upgraded components are in the supported versions. |
| Open the required reduced control-plane ports for GigaVUE‑FM, other fabric components, and the UCT-V Agent. Use the port requirements listed in Firewall Rule Changes for Migrating to Reduced Control-Plane Ports. |
| Use the Reset option to force the monitoring domain to reconnect by using the new ports. |
| Verify that all applicable components are communicating over ports 443, 5671, and 9902. |
| Remove the legacy ports from your firewall or security group rules after verification is complete. |
Note: Do not close all legacy ports and enable only the new ports before upgrading. Doing so can disrupt existing connections and is not recommended.
Firewall Rule Changes for Migrating to Reduced Control-Plane Ports
The following tables summarize the firewall changes to make when migrating an existing deployment:
GigaVUE‑FM
|
Action |
Direction |
Port |
|
Remove |
Inbound |
9600 |
|
Remove |
Outbound |
8890 |
|
Remove |
Outbound |
8889 |
|
Remove |
Outbound |
80 |
|
Remove |
Outbound |
9990 |
|
Add |
Inbound |
443 |
|
Add |
Inbound |
5671 |
|
Add |
Outbound |
443 |
|
Add |
Outbound |
443 |
UCT-V Controller
|
Action |
Direction |
Port |
|
Remove |
Inbound |
9900 |
|
Remove |
Inbound |
80 |
|
Remove |
Inbound |
8300 |
|
Remove |
Inbound |
8892 |
|
Remove |
Outbound |
9600 |
|
Remove |
Outbound |
8301 |
|
Add |
Inbound |
443 |
|
Add |
Outbound |
443 |
|
Add |
Outbound |
5671 |
|
Add |
Outbound |
9902 |
UCT-V
|
Action |
Direction |
Port |
|
Remove |
Inbound |
8301 |
|
Remove |
Outbound |
8892 |
|
Remove |
Outbound |
9900 |
|
Remove |
Outbound |
8300 |
|
Add |
Inbound |
9902 |
|
Add |
Outbound |
5671 |
|
Add |
Outbound |
443 |
GigaVUE V Series Node
|
Action |
Direction |
Port |
|
Remove |
Inbound |
8889 |
|
Remove |
Inbound |
80 |
|
Remove |
Outbound |
8891 |
|
Remove |
Outbound |
8892 |
|
Remove |
Outbound |
9600 |
|
Remove |
Outbound |
8300 |
|
Add |
Inbound |
443 |
|
Add |
Outbound |
443 |
|
Add |
Outbound |
5671 |
GigaVUE V Series Proxy (Optional)
|
Action |
Direction |
Port |
|
Remove |
Inbound |
8890 |
|
Remove |
Inbound |
80 |
|
Remove |
Inbound |
8300 |
|
Remove |
Inbound |
8891 |
|
Remove |
Inbound |
8892 |
|
Remove |
Outbound |
8889 |
|
Remove |
Outbound |
9600 |
|
Remove |
Outbound |
80 |
|
Add |
Inbound |
5671 |
|
Add |
Inbound |
443 |
|
Add |
Outbound |
443 |
UCT-V OVS Controller
|
Action |
Direction |
Port |
|
Remove |
Inbound |
9900 |
|
Add |
Inbound |
443 |
|
Add |
Outbound |
9901 |
UCT-V OVS Module
|
Action |
Direction |
Port |
|
Add |
Inbound |
9901 |
The following tables identify the firewall changes required to migrate from the legacy control-plane ports to the optimized control-plane ports:
GigaVUE FM
The following table lists the reduced control-plane ports required for communication with GigaVUE-FM.
|
Direction |
Protocol |
Port |
Replaces Legacy Port |
Source CIDR2 |
Purpose |
|
Inbound |
TCP |
443 |
9600 |
GigaVUE V Series Node IP |
Allows GigaVUE‑FM to receive certificate requests from GigaVUE V Series Node. |
|
Inbound |
TCP |
443 |
9600 |
GigaVUE V Series Proxy IP |
Allows GigaVUE‑FM to receive certificate requests from GigaVUE V Series Proxy. |
|
Direction |
Protocol |
Port |
Replaces Legacy Port |
Destination CIDR |
Purpose |
|
Outbound |
TCP |
443 |
8889 |
GigaVUE V Series Node IP |
Allows GigaVUE‑FM to communicate control and management plane traffic to GigaVUE V Series Node. |
|
Outbound |
TCP |
443 |
8890 |
GigaVUE V Series Proxy IP |
Allows GigaVUE‑FM to communicate control and management plane traffic to GigaVUE V Series Proxy. |
|
Outbound |
TCP |
443 |
9900 |
UCT-V Controller IP |
Allows GigaVUE‑FM to communicate control and management plane traffic with UCT-V Controller. |
|
Outbound |
TCP |
443 |
9900 |
OVS Controller |
Controller management communication. |
UCT-V Controller
The following table lists the reduced control-plane ports required for communication with UCT-V Controller.
|
Direction |
Protocol |
Port |
Replaces Legacy Port |
Source CIDR |
Purpose |
|
Inbound |
TCP |
443 |
9900 |
GigaVUE‑FM IP |
Allows UCT-V Controller to communicate control and management plane traffic with GigaVUE‑FM. |
|
Inbound |
TCP |
443 |
8300 |
UCT-VSubnet |
Allows UCT-V Controller to receive the certificate requests from the UCT-V. |
|
Inbound |
TCP |
443 |
8892 |
UCT-V Subnet |
Allows UCT-V Controller to receive the registration requests and heartbeat from UCT-V. |
|
Inbound |
TCP |
443 |
9900 |
UCT-V or Subnet IP
|
Allows UCT-V Controller to receive traffic health updates from UCT-V. |
|
Direction |
Protocol |
Port |
Replaces Legacy Port |
Destination CIDR |
Purpose |
|
Outbound |
TCP |
5671 |
NA |
UCT-V Subnet |
Allows the UCT-V Controller to communicate control and management plane traffic with UCT-Vs for monitoring domains created in 6.14.01 and later. |
|
Outbound |
TCP |
9902 |
NA |
UCT-V Subnet |
Allows UCT-V Controller to communicate control and management plane traffic with UCT-Vs for UCT-Vs with version earlier than 6.14.01. |
Note: For UCT-V Controller–to–UCT-V traffic, the controller uses 5671 for monitoring domains created in 6.14.01 and later, and 9902 for monitoring domains created in earlier releases. The UCT-V RPC port is configurable at the monitoring-domain level.
UCT-V
The following table lists the reduced control-plane ports required for communication with UCT-V.
|
Direction |
Protocol |
Port |
Replaces Legacy Port |
Source CIDR |
Purpose |
|
Inbound |
TCP |
5671 |
NA |
UCT-V Controller IP |
Allows UCT-V to receive control and management plane traffic from UCT-V Controller for monitoring domains created in 6.14.01 and later. |
|
Inbound |
TCP |
9902 |
NA |
UCT-V Controller IP |
Allows UCT-V to receive control and management plane traffic from UCT-V Controller for existing monitoring domains created with version earlier than 6.14.01. |
|
Direction |
Protocol |
Port |
Replaces Legacy Port |
Destination CIDR |
Purpose |
|
Outbound |
TCP |
443 |
9900 |
UCT-V Controller IP |
Allows UCT-V to send traffic health updates to UCT-V Controller. |
|
Outbound (This is the port used for Third Party Orchestration) |
TCP |
443 |
8892 |
UCT-V Controller IP |
Allows UCT-V to receive the registration requests and heartbeat to UCT-V Controller. |
|
Outbound |
TCP |
443 |
8300 |
UCT-V Controller IP |
Allows UCT-V to receive the certificate requests from the UCT-V Controller. |
Note: A 6.14.01 UCT-V listens on both 5671 and 9902 during discovery. The default listening port is 5671 for monitoring domains created in 6.14.01; monitoring domains migrated from earlier releases default to 9902. This port is configurable at the monitoring-domain level.
GigaVUE V Series Node
The following table lists the reduced control-plane ports required for communication with GigaVUE V Series Node.
|
Direction |
Protocol |
Port |
Replaces Legacy Port |
Source CIDR |
Purpose |
|
Inbound |
TCP |
443 |
8889 |
GigaVUE-FM IP |
Allows GigaVUE V Series Node to communicate control and management plane traffic with GigaVUE-FM. |
|
Direction |
Protocol |
Port |
Replaces Legacy Port |
Destination CIDR |
Purpose |
|
Outbound |
TCP |
5671 |
8300 |
GigaVUE V Series Proxy |
Allows GigaVUE V Series Node to send certificate request to GigaVUE V Series Proxy IP. |
|
Outbound |
TCP |
443 |
8891 |
GigaVUE V Series Proxy |
Allows GigaVUE V Series Proxy to receive PKI requests from the GigaVUE V Series Node. |
|
Outbound |
TCP |
443 |
8892 |
GigaVUE V Series Proxy |
Allows GigaVUE V Series Proxy to receive registration requests and heartbeat messages from GigaVUE V Series Node. |
|
Outbound |
TCP |
443 |
9600 |
GigaVUE-FM IP |
Allows GigaVUE-FM to receive certificate requests from GigaVUE V Series Node. |
Note: Cross-version deployments between GigaVUE V Series Nodes and GigaVUE V Series Proxy are not supported. Ensure that the GigaVUE V Series Node and GigaVUE V Series Proxy are running the same software version. For example, a 6.13 GigaVUE V Series Node cannot communicate with a 6.14 GigaVUE V Series Proxy.
GigaVUE V Series Proxy (Optional)
The following table lists the reduced control-plane ports required for communication with GigaVUE V Series Proxy.
|
Direction |
Protocol |
Port |
Replaces Legacy Port |
Source CIDR |
Purpose |
|
Inbound |
TCP |
443 |
8890 |
GigaVUE‑FM IP |
Allows GigaVUE‑FM to communicate control and management plane traffic with GigaVUE V Series Proxy. |
|
Inbound |
TCP |
443 |
8891 |
GigaVUE V Series Node |
Allows GigaVUE V Series Proxy to receive PKI requests from GigaVUE V Series Node. |
|
Inbound |
TCP |
443 |
8892 |
GigaVUE V Series Node |
Allows GigaVUE V Series Proxy to receive registration requests and heartbeat messages from GigaVUE V Series Node. |
|
Inbound |
TCP |
5671 |
8300 |
GigaVUE V Series Node
|
Allows GigaVUE V Series Proxy to receive certificate requests from GigaVUE V Series Node for the configured params and provides the certificate using those parameters. |
|
Direction |
Protocol |
Port |
Replaces Legacy Port |
Destination CIDR |
Purpose |
|
Outbound |
TCP |
443 |
9600 |
GigaVUE-FM IP |
Allows GigaVUE-FM to receive certificate requests from GigaVUE V Series Proxy. |
UCT-V OVS Controller
The following table lists the reduced control-plane ports required for communication with UCT-V OVS Controller.
|
Direction |
Protocol |
Port |
Replaces Legacy Port |
Source CIDR |
Purpose |
|
Inbound |
TCP |
443 |
9900 |
GigaVUE‑FM IP |
Allows GigaVUE‑FM to communicate control and management plane traffic. The controller supports both ports for compatibility and falls back to 9900 when required. |
|
Direction |
Protocol |
Port |
Replaces Legacy Port |
Destination CIDR |
Purpose |
|
Outbound |
TCP |
9901 |
NA |
UCT-V OVS Module IP |
Allows to communicate with UCT-V OVS Modules (RPC). |
UCT-V OVS Module
The following table lists the reduced control-plane ports required for communication with UCT-V OVS Module.
|
Direction |
Protocol |
Port |
Replaces Legacy Port |
Source CIDR |
Purpose |
|
Inbound |
TCP |
9901 |
NA |
UCT-V OVS Controller IP |
Allows to receive control communication from UCT-V OVS Controller. The module listens on 9901 for backward compatibility. |
Legacy Control-Plane Ports
Legacy control-plane ports remain supported for backward compatibility with earlier versions and mixed-version deployments.
When to Use Legacy Ports
| GigaVUE‑FM is running version 6.10 or later but earlier than 6.14.02. |
| One or more fabric components (such as UCT-V Controller, UCT-V, GigaVUE V Series Node, GigaVUE V Series Proxy |
| This includes mixed-version deployments where GigaVUE‑FM 6.14.02 or later communicates with fabric components running N-1 or N-2 releases. |
| The deployment has not yet been migrated to the reduced control-plane port architecture. |
GigaVUE‑FM
The following table specifies the inbound and outbound communication parameters—protocols, ports, and CIDRs—required for GigaVUE‑FM to support secure access, registration, certificate exchange, and control-plane communication with associated components.
|
Direction |
Protocol |
Port |
Source CIDR |
Purpose |
|
Inbound |
TCP |
443 |
Administrator Subnet |
Allows GigaVUE-FM to accept Management connection using REST API. Allows users to access GigaVUE-FM UI securely through an HTTPS connection. |
|
Inbound |
TCP |
22 |
Administrator Subnet |
Allows CLI access to user-initiated management and diagnostics. |
|
Inbound (This is the port used for Third Party Orchestration) |
TCP |
443 |
UCT-V Controller IP |
Allows GigaVUE-FM to receive registration requests from UCT-V Controller using REST API. |
|
Inbound (This is the port used for Third Party Orchestration) |
TCP |
443 |
GigaVUE V Series Node IP |
Allows GigaVUE-FM to receive registration requests from GigaVUE V Series Node using REST API when GigaVUE V Series Proxy is not used. |
|
Inbound (This is the port used for Third Party Orchestration) |
TCP |
443 |
GigaVUE V Series Proxy IP |
Allows GigaVUE-FM to receive registration requests from GigaVUE V Series Proxy using REST API. |
|
Inbound |
TCP |
443 |
UCT-V Controller IP |
Allows GigaVUE-FM to receive registration requests from UCT-C Controller using REST API. |
|
Inbound |
TCP |
5671 |
GigaVUE V Series Node IP |
Allows GigaVUE‑FM to receive traffic health updates from GigaVUE V Series Nodes. |
|
Inbound |
TCP |
5671 |
UCT-V Controller IP |
Allows GigaVUE‑FM to receive statistics from UCT-V Controllers. |
|
Inbound |
TCP |
9600 |
UCT-V Controller |
Allows GigaVUE‑FM to receive certificate requests from UCT-V Controller. |
|
Inbound |
TCP |
9600 |
GigaVUE V Series Proxy |
Allows GigaVUE‑FM to receive certificate requests from GigaVUE V Series Proxy. |
|
Inbound |
TCP |
9600 |
GigaVUE V Series Node |
Allows GigaVUE‑FM to receive certificate requests from GigaVUE V Series Node. |
|
Inbound |
TCP |
5671 |
UCT-V Controller IP |
Allows GigaVUE‑FM to receive statistics from UCT-C Controllers. |
|
Inbound |
UDP |
2056 |
GigaVUE V Series Node IP |
Allows GigaVUE‑FM to receive Application Intelligence and Application Visualization reports from GigaVUE V Series Node. |
|
Direction |
Protocol |
Port |
Destination CIDR |
Purpose |
|
Outbound |
TCP |
9900 |
UCT-V Controller IP |
Allows GigaVUE‑FM to communicate control and management plane traffic with UCT-V Controller. |
|
Outbound (optional) |
TCP |
8890 |
GigaVUE V Series Proxy IP |
Allows GigaVUE‑FM to communicate control and management plane traffic to GigaVUE V Series Proxy. |
|
Outbound |
TCP |
8889 |
GigaVUE V Series Node IP |
Allows GigaVUE‑FM to communicate control and management plane traffic to GigaVUE V Series Node. |
|
Outbound |
TCP |
8443 |
UCT-C Controller IP |
Allows GigaVUE‑FM to communicate control and management plane traffic to UCT-C Controller. |
|
Outbound |
TCP |
80 |
UCT-V Controller IP |
Allows GigaVUE‑FM to send ACME challenge requests to UCT-V Controller. |
|
Outbound |
TCP |
80 |
GigaVUE V Series Node |
Allows GigaVUE‑FM to send ACME challenge requests to GigaVUE V Series Node. |
|
Outbound |
TCP |
80 |
GigaVUE V Series Proxy |
Allows GigaVUE‑FM to send ACME challenge requests to GigaVUE V Series Proxy. |
|
Outbound |
TCP |
443 |
Any IP Address |
Allows GigaVUE‑FM to reach the Public Cloud Platform APIs. |
UCT-V Controller
The following table defines the network communication parameters—protocols, ports, and CIDRs—required for UCT-V Controller to interact with GigaVUE-FM and UCT-V components, supporting registration, diagnostics, certificate exchange, and control-plane operations including third-party orchestration.
|
Direction |
Protocol |
Port |
Source CIDR |
Purpose |
|
Inbound |
TCP |
9900 |
GigaVUE‑FM IP |
Allows UCT-V Controller to communicate control and management plane traffic with GigaVUE‑FM. |
|
Inbound |
TCP |
9900 |
UCT-V or Subnet IP |
Allows UCT-V Controller to receive traffic health updates from UCT-V. |
|
Inbound |
TCP |
22 |
Administrator Subnet |
Allows CLI access for user-initiated management and diagnostics, specifically when using third party orchestration. |
|
Inbound |
TCP |
80 |
GigaVUE‑FM
|
Allows UCT-V Controller to receive the ACME challenge requests from GigaVUE‑FM. |
|
Inbound |
TCP |
8300 |
UCT-VSubnet |
Allows UCT-V Controller to receive the certificate requests from the UCT-V. |
|
Inbound (This is the port used for Third Party Orchestration) |
TCP |
8892 |
UCT-V Subnet
|
Allows UCT-V Controller to receive the registration requests and heartbeat from UCT-V. |
|
Direction |
Protocol |
Port |
Destination CIDR |
Purpose |
|
Outbound (This is the port used for Third Party Orchestration) |
TCP |
443 |
GigaVUE‑FM IP |
Allows UCT-V Controller to send the registration requests to GigaVUE-FM using REST API. |
|
Outbound |
TCP |
5671 |
GigaVUE-FM IP |
Allows UCT-V Controller to send traffic health updates to GigaVUE-FM. |
|
Outbound (This is the port used for Third Party Orchestration) |
TCP |
9600 |
GigaVUE‑FM IP |
Allows GigaVUE‑FM to receive certificate requests from the UCT-V Controller. |
|
Outbound |
TCP |
9902 |
UCT-V Subnet |
Allows UCT-V Controller to communicate control and management plane traffic with UCT-Vs for UCT-Vs with version greater than 6.10.00. |
|
Outbound |
TCP |
8301 |
UCT-V Subnet |
Allows ACME validation flow from UCT-V Controller to UCT-V. |
UCT-V
The following table outlines UCT-V Controller’s network communication requirements with GigaVUE-FM, detailing essential ports, protocols, and CIDRs for registration, diagnostics, certificate exchange, and orchestration traffic.
|
Direction |
Protocol |
Port |
Source CIDR |
Purpose |
|
Inbound |
TCP |
9902 |
UCT-V Controller IP |
Allows UCT-V to receive control and management plane traffic from UCT-V Controller. |
|
Inbound |
TCP |
8301 |
UCT-V Controller IP |
Allows UCT-V to receive the ACME challenge requests from the UCT-V Controller. |
|
Direction |
Protocol |
Port |
Destination CIDR |
Purpose |
|
Outbound |
UDP (VXLAN) |
VXLAN (default 4789) |
GigaVUE V Series Node IP |
Allows UCT-V to tunnel VXLAN traffic to GigaVUE V Series Nodes. |
|
Outbound |
IP Protocol (L2GRE) |
L2GRE (IP 47) |
GigaVUE V Series Node IP |
Allows UCT-V to tunnel L2GRE traffic to GigaVUE V Series Nodes. |
|
Outbound (Optional - This port is used only for Secure Tunnels) |
TCP |
11443 |
GigaVUE V Series Node IP |
Allows UCT-V to securely transfer the traffic to the GigaVUE V Series Node. |
|
Outbound |
TCP |
9900 |
UCT-V Controller IP |
Allows UCT-V to send traffic health updates to UCT-V Controller. |
|
Outbound (This is the port used for Third Party Orchestration) |
TCP |
8892 |
UCT-V Controller IP |
Allows UCT-V to receive the registration requests and heartbeat to UCT-V Controller. |
|
Outbound |
TCP |
8300 |
UCT-V Controller IP |
Allows UCT-V to receive ACME validation flow from UCT-V Controller. |
GigaVUE V Series Node
The following table outlines GigaVUE V Series Node’s network communication requirements, detailing protocols, ports, and CIDRs necessary for tunneling, management, diagnostics, and secure data transfer across connected components.
|
Direction |
Protocol |
Port |
Source CIDR |
Purpose |
||||||
|
Inbound |
TCP |
8889 |
GigaVUE-FM IP |
Allows GigaVUE V Series Node to communicate control and management plane traffic with GigaVUE-FM. |
||||||
|
Inbound |
TCP |
8889 |
GigaVUE V Series Proxy IP |
Allows GigaVUE V Series Node to communicate control and management plane traffic with GigaVUE V Series Proxy. |
||||||
|
Inbound |
UDP (VXLAN) |
VXLAN (default 4789) |
UCT-V Subnet IP |
Allows GigaVUE V Series Nodes to receive VXLAN tunnel traffic to UCT-V. |
||||||
|
Inbound |
IP Protocol (L2GRE) |
L2GRE |
UCT-V Subnet IP |
Allows GigaVUE V Series Nodes to receive L2GRE tunnel traffic to UCT-V. |
||||||
|
Inbound |
UDPGRE |
4754 |
Ingress Tunnel |
Allows GigaVUE V Series Node to receive tunnel traffic from UDPGRE Tunnel. |
||||||
|
Inbound |
TCP |
22 |
Administrator Subnet |
Allows CLI access for user-initiated management and diagnostics, specifically when using third party orchestration. |
||||||
|
Inbound |
TCP |
80 |
GigaVUE-FM
|
Allows GigaVUE V Series Node to receive the ACME challenge requests from GigaVUE-FM. |
||||||
|
Inbound |
TCP |
80 |
GigaVUE V Series Proxy IP |
Allows UCT-V to receive the ACME challenge requests from the GigaVUE V Series Proxy. |
||||||
|
Inbound (Optional - This port is used only for Secure Tunnels) |
TCP |
11443 |
UCT-V subnet |
Allows to securely transfer the traffic to GigaVUE V Series Nodes. |
||||||
|
Inbound (Optional - This port is used only for configuring AWS Gateway Load Balancer) |
UDP (GENEVE) |
6081 |
Ingress Tunnel |
Allows GigaVUE V Series Node to receive tunnel traffic from AWS Gateway Load Balancer. |
||||||
|
Direction |
Protocol |
Port |
Destination CIDR |
Purpose |
||||||
|
Outbound |
TCP |
5671 |
GigaVUE-FM IP |
Allows GigaVUE V Series Node to send traffic health updates to GigaVUE-FM. |
||||||
|
Outbound |
TCP |
9600 |
GigaVUE-FM IP |
Allows GigaVUE-FM to send certificate requests to GigaVUE V Series Node. |
||||||
|
Outbound |
UDP (VXLAN) |
VXLAN (default 4789) |
Tool IP |
Allows GigaVUE V Series Node to tunnel output to the tool. |
||||||
|
Outbound |
IP Protocol (L2GRE) |
L2GRE (IP 47) |
Tool IP |
Allows GigaVUE V Series Node to tunnel output to the tool. |
||||||
|
Outbound |
UDP |
2056 |
GigaVUE-FM IP |
Allows GigaVUE V Series Node to send Application Intelligence and Application Visualization reports to GigaVUE-FM. |
||||||
|
Outbound |
UDP |
2055 |
Tool IP |
Allows GigaVUE V Series Node to send NetFlow Generation traffic to an external tool. |
||||||
|
Outbound |
TCP |
8891 |
GigaVUE V Series Proxy |
Allows GigaVUE V Series Node to send PKI request to GigaVUE V Series Proxy IP. |
||||||
|
Outbound |
UDP |
8892 |
GigaVUE V Series Proxy |
Allows GigaVUE V Series Node to send certificate request to GigaVUE V Series Proxy IP. |
||||||
|
Outbound |
TCP |
514 |
Tool IP |
Allows GigaVUE V Series Node to send Application Metadata Intelligence log messages to external tools. |
||||||
|
Bidirectional (optional) |
ICMP |
|
Tool IP |
Allows GigaVUE V Series Node to send health check tunnel destination traffic. |
||||||
|
Outbound (This is the port used for Third Party Orchestration) |
TCP |
443 |
GigaVUE-FM IP |
Allows GigaVUE V Series Node to send registration requests and heartbeat messages to GigaVUE-FM when GigaVUE V Series Proxy is not used. |
||||||
|
Outbound (Optional - This port is used only for Secure Tunnels) |
TCP |
11443 |
Tool IP |
Allows to securely transfer the traffic to an external tool. |
GigaVUE V Series Proxy (Optional)
The following table defines GigaVUE V Series Proxy’s network communication parameters, listing essential protocols, ports, and CIDRs for registration, certificate exchange, diagnostics, and control-plane traffic with GigaVUE-FM and V Series Nodes.
|
Direction |
Protocol |
Port |
Source CIDR |
Purpose |
|
Inbound |
TCP |
8890 |
GigaVUE‑FM IP |
Allows GigaVUE‑FM to communicate control and management plane traffic with GigaVUE V Series Proxy. |
|
Inbound |
TCP |
22 |
Administrator Subnet |
Allows CLI access for user-initiated management and diagnostics, specifically when using third party orchestration. |
|
Inbound |
TCP |
80 |
GigaVUE‑FM
|
Allows GigaVUE V Series Proxy to receive the ACME challenge requests from the GigaVUE‑FM. |
|
Inbound |
TCP |
8300 |
GigaVUE V Series Node
|
Allows GigaVUE V Series Proxy to receive certificate requests from GigaVUE V Series Node for the configured params and provides the certificate using those parameters. |
|
Inbound |
TCP |
8891 |
GigaVUE V Series Node IP
|
Allows GigaVUE V Series Proxy to receive PKI request from GigaVUE V Series Node. |
|
Inbound |
TCP |
8892 |
GigaVUE V Series Node IP
|
Allows GigaVUE V Series Proxy to receive registration requests and heartbeat messages from GigaVUE V Series Node. |
|
Direction |
Protocol |
Port |
Destination CIDR |
Purpose |
|
Outbound |
TCP |
443 |
GigaVUE-FM IP |
Allows GigaVUE V Series Proxy to communicate the registration requests to GigaVUE-FM. |
|
Outbound |
TCP |
8889 |
GigaVUE V Series Node IP |
Allows GigaVUE V Series Proxy to communicate control and management plane traffic with GigaVUE V Series Node. |
UCT-C Controller - deployed in Kubernetes worker mode
The following table outlines UCT-C Controller’s network communication parameters in Kubernetes worker mode, specifying TCP ports and CIDRs required for management, statistics exchange, and secure connectivity with GigaVUE-FM.
|
UCT-C Controller deployed inside Kubernetes worker node |
||||
|
Direction |
Protocol |
Port |
Source CIDR |
Purpose |
|
Inbound |
TCP |
8443 (configurable) |
GigaVUE-FM IP |
Allows GigaVUE‑FM to communicate with UCT-C Controller. |
|
Direction |
Protocol |
Port |
Destination CIDR |
Purpose |
|
Outbound |
TCP |
5671 |
Any IP address |
Allows UCT-C Controller to send statistics to GigaVUE‑FM. |
|
Outbound |
TCP |
443 |
GigaVUE-FM IP |
Allows UCT-C Controller to communicate with GigaVUE‑FM. |
OVS Mirroring
The following table list the Network Firewall or Security Group requirements when using OVS Mirroring.
|
Direction |
Protocol |
Port |
CIDR |
Purpose |
|
UCT-V OVS Controller |
||||
|
Inbound |
TCP |
9900 |
GigaVUE-FM IP |
Allows GigaVUE-FM to communicate with UCT-V OVS Controllers |
|
UCT-V OVS Module |
||||
|
Inbound |
TCP |
9901 |
UCT-V OVS Controller IP |
Allows UCT-V OVS Controllers to communicate with UCT-V OVS Modules |
Note: The Security Group Rules table lists only the ingress rules. Make sure the egress ports are open for communication. Along with the ports listed in the Security Group Rules table, make sure the suitable ports required to communicate with Service Endpoints such as Identity, Compute, and Cloud Metadata are also open.
UCT-V Controller
The following table specifies the communication parameters required for third-party orchestration, detailing the TCP ports and CIDRs used by UCT-V Controller to manage registration and control-plane traffic with UCT-V components.
|
Direction |
Protocol |
Port |
Source CIDR |
Purpose |
|
Inbound (This is the port used for Third Party Orchestration) |
TCP |
8891 |
UCT-V or Subnet IP |
Allows UCT-V Controller to receive the registration requests from UCT-V. |
|
Direction |
Protocol |
Port |
Destination CIDR |
Purpose |
|
Outbound |
TCP |
9901 |
UCT-V Controller IP |
Allows UCT-V Controller to communicate control and management plane traffic with UCT-Vs. |
GigaVUE V Series Node
The following table specifies the outbound communication requirement for GigaVUE V Series Node, detailing the protocol, port, and source CIDR used to send registration and heartbeat messages to the GigaVUE V Series Proxy during third-party orchestration.
|
Direction |
Protocol |
Port |
Source CIDR |
Purpose |
|
Outbound (This is the port used for Third Party Orchestration) |
TCP |
8891 |
GigaVUE V Series Proxy IP |
Allows GigaVUE V Series Node to send registration requests and heartbeat messages to GigaVUE V Series Proxy when GigaVUE V Series Proxy is used. |
GigaVUE V Series Proxy(Optional)
The following table specifies the optional inbound communication parameter for GigaVUE V Series Proxy, detailing the protocol, port, and source CIDR required to receive security parameter requests from GigaVUE V Series Node during third-party orchestration.
|
Direction |
Protocol |
Port |
Source CIDR |
Purpose |
|
Inbound (This is the port used for Third Party Orchestration) |
TCP |
8891 |
GigaVUE V Series Node IP |
Allows GigaVUE V Series Proxy to receive security parameter requests from GigaVUE V Series Node. |
GigaVUE‑FM Debug/Supportability
You can use this page to check connectivity, debug issues, and collect diagnostic output for supported products managed by GigaVUE‑FM. Go to this page in GigaVUE‑FM when you need to troubleshoot connectivity, service, certificate, or port-related issues and want a faster way to identify the source of the problem.
To verify the connectivity, Go to Settings in GigaVUE‑FM and under Troubleshoot > FM Debug and Supportability.
The page supports the following product types:
| GigaVUE‑FM |
| GigaVUE V Series |
| GigaVUE V Series Proxy |
| UCTV Controller |
You can add multiple targets and run scripts across them. Targets can belong to the same supported product type or different supported product types.
There are two tabs in this page. Select the appropriate tab based on the task that you want to perform.
| Execute Debug Scripts |
| Check Connectivity |
Execute Debug Scripts
Use Execute Debug Scripts to run predefined scripts for the selected product type. Provide the Configure the Target Connection for one of the product types. These scripts quickly identify connectivity, service, certificate, and port-related issues in the target environment.
The page provides four debug scripts:
| Active Connections: View active connections on the selected target. The target acts as a server for incoming connections and as a client for outgoing connections. |
| Check Services: Verify that the core services required by the selected product are running and healthy. |
| Collect Logs: Collect the specified number of bytes from selected log files on each fabric node and return the logs for analysis. |
| Verify Connectivity: Verify service reachability from the selected product. The selected product IP is used to verify the reachability of services running on that product (self-reachability). You can also provide optional IP addresses for other product types to verify whether the selected product can reach services running on those products. The optional IP address fields are: |
| fm_ips: One or more GigaVUE‑FM IP addresses. |
| vseries_ips: One or more GigaVUE V Series node IP addresses. |
| vseries_proxy_ips: One or more GigaVUE V Series Proxy IP addresses. |
| uctv_controller_ips: One or more UCT-V Controller IP addresses. |
Enter multiple IP addresses as a comma-separated list.
Each Verify Connectivity execution is unidirectional and supports connectivity validation only between GigaVUE-FM and a peer component. To verify connectivity between GigaVUE-FM and a peer component, run the script twice:
| Select GigaVUE-FM and provide the peer component's IP address as the optional input. |
| Select the peer component and provide the GigaVUE-FM IP address as the optional input. |
Running the script in both directions verifies service reachability between the two products.
If your environment uses a custom certificate, you can optionally provide the following certificate details:
| custom_cn: The Common Name (CN) configured in the custom certificate uploaded to GigaVUE-FM. |
| custom_sni: A Subject Alternative Name (SAN) or CN value that matches the custom certificate. |
Run Scripts
| To run one or more scripts for a single target, select Run Selected Scripts. |
| To run scripts across multiple targets, select Run All. |
| You can add multiple targets from the same or different supported product types. |
All script results are displayed in JSON format. The following example shows the JSON output format for the Active Connections script.
{
"output": {
"incomingConnections": {
"443": {
"connections": 2,
"unique_remote_ip_sample": [
"192.0.2.66",
"198.51.100.102"
],
"unique_remote_ips": 2
},
"5671": {
"connections": 4,
"unique_remote_ip_sample": [
"203.0.113.36",
"198.51.100.195",
"192.0.2.175",
"203.0.113.158"
],
"unique_remote_ips": 4
},
"9600": {
"connections": 0
}
},
"outgoingConnections": {
"443": {
"connections": 40,
"unique_remote_ip_sample": [
"198.51.100.195",
"192.0.2.175",
"203.0.113.36",
"203.0.113.158"
],
"unique_remote_ips": 4
}
},
"summary": {
"incoming_port_count": 3,
"outgoing_port_count": 1,
"total_incoming_connections": 6,
"total_outgoing_connections": 40
}
},
"result": "pass",
"script_name": "active_connections"
}
Check Connectivity
Use the Check Connectivity tab to verify connectivity between GigaVUE‑FM and a peer component. Unlike Verify Connectivity, which validates connectivity only from GigaVUE‑FM to a target component, Check Connectivity performs a comprehensive connectivity assessment that includes:
| GigaVUE‑FM self reachability validation. |
| Peer component self reachability validation. |
| Connectivity from GigaVUE‑FM to the peer component. |
| Connectivity from the peer component to GigaVUE‑FM. |
These checks help verify both service availability and bidirectional communication between GigaVUE‑FM and supported fabric components or other supported peer components.
Configure the Target Connection for both GigaVUE‑FM and the peer component.
Configure the Target Connection
Before you run diagnostics, enter the connection details for the target system:
| 1. | Choose a Product Type. The options are GigaVUE‑FM and other fabric components. |
| 2. | Enter the target IP address of the fabric. |
| 3. | [Optional] Enter the user name. |
| 4. | Select an SSH authentication method: |
| Password: If you select password, enter the password. |
| SSH Key: If you select SSH Key, paste the private key or upload a key file. |



