Appendix
C
AP-SCG/SZ/vSZ/vSZ-D Communication
The table below lists the ports that must be opened in the network firewall to ensure that the
SCG/vSZ-D/SZ/vSZ (controller), managed APs, and RADIUS servers can communicate with each
other successfully.
Table 46: Ports to open for AP-SCG/SZ/vSZ/vSZ-D communication
PurposeConfigurable
from Web
Interface?
To (Listener)From
(Sender)
Layer 4
Protocol
Port
Number
FTP upload of reports,
statistics, and configuration
backups
YesvSZ control
plane
APTCP21
SSH tunnelNovSZ control
plane
TCP22 • AP
• vSZ-D
TACACS+ based
authentication of controller
administrators
YesvSZ control
plane
TACACS+
server
TCP49
AP firmware upgradeNovSZ control
plane
APTCP91 and
11443
NTP sync up
Not required in 2.1.2, 2.1.3,
2.5.1, 2.6, 3.0
NovSZ control
plane
APUDP123
Required in1.x, 2.1, 2.1.1,
2.5
Access to the SCG/vSZ/SZ
control plane over secure
HTTPS
NovSZ control
plane
TCP443 • AP
• vSZ-D
Internal communication portNovSZvSZ-DTCP6868
SmartCell Gateway 200/Virtual SmartZone High-Scale for Release 3.4.1 Administrator Guide
430
AP-SCG/SZ/vSZ/vSZ-D Communication