<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Necessary Ports for Cisco 9800-CL in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/necessary-ports-for-cisco-9800-cl/m-p/5304647#M284494</link>
    <description>&lt;P&gt;Capwap ports 5246/5247&lt;/P&gt;
&lt;P&gt;CoA port 1700&lt;/P&gt;
&lt;P&gt;Radius port 1812/1813&amp;nbsp;&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
    <pubDate>Wed, 02 Jul 2025 01:11:29 GMT</pubDate>
    <dc:creator>MHM Cisco World</dc:creator>
    <dc:date>2025-07-02T01:11:29Z</dc:date>
    <item>
      <title>Necessary Ports for Cisco 9800-CL</title>
      <link>https://community.cisco.com/t5/wireless/necessary-ports-for-cisco-9800-cl/m-p/5304642#M284493</link>
      <description>&lt;P&gt;We are looking to implement a zero trust through ThreatLocker and therefore we would like to find out which ports on the WLC need to be able to communicate with our domain controllers, our radius server, and with the APs.&amp;nbsp;I have already looked at the reference guide for the Cisco Catalyst 9800 Wireless Controller for Cloud, and I am not seeing any reference concerning which ports need allowed. Thank you in advance.&lt;/P&gt;</description>
      <pubDate>Wed, 02 Jul 2025 00:56:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/necessary-ports-for-cisco-9800-cl/m-p/5304642#M284493</guid>
      <dc:creator>jmorton1</dc:creator>
      <dc:date>2025-07-02T00:56:24Z</dc:date>
    </item>
    <item>
      <title>Re: Necessary Ports for Cisco 9800-CL</title>
      <link>https://community.cisco.com/t5/wireless/necessary-ports-for-cisco-9800-cl/m-p/5304647#M284494</link>
      <description>&lt;P&gt;Capwap ports 5246/5247&lt;/P&gt;
&lt;P&gt;CoA port 1700&lt;/P&gt;
&lt;P&gt;Radius port 1812/1813&amp;nbsp;&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Wed, 02 Jul 2025 01:11:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/necessary-ports-for-cisco-9800-cl/m-p/5304647#M284494</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2025-07-02T01:11:29Z</dc:date>
    </item>
    <item>
      <title>Re: Necessary Ports for Cisco 9800-CL</title>
      <link>https://community.cisco.com/t5/wireless/necessary-ports-for-cisco-9800-cl/m-p/5304655#M284496</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Thanks. What ports are required for DNS? I saw what appeared to be a random selection of ports being used ranging from the 8000s all the way up to the 46000s.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 02 Jul 2025 01:22:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/necessary-ports-for-cisco-9800-cl/m-p/5304655#M284496</guid>
      <dc:creator>jmorton1</dc:creator>
      <dc:date>2025-07-02T01:22:21Z</dc:date>
    </item>
    <item>
      <title>Re: Necessary Ports for Cisco 9800-CL</title>
      <link>https://community.cisco.com/t5/wireless/necessary-ports-for-cisco-9800-cl/m-p/5304685#M284505</link>
      <description>&lt;P&gt;when you refer to something its best to include a URL where you saw that.&lt;/P&gt;
&lt;P&gt;standard port is 53 typically UDP for standard query but can also be TCP for&amp;nbsp;Zone transfers, large queries.&lt;/P&gt;
&lt;P&gt;other than the one mentioned above like&lt;/P&gt;
&lt;P&gt;UDP 5246 for AP-WLC control messages&lt;/P&gt;
&lt;P&gt;UDP 5247 for AP-WLC data messages&lt;/P&gt;
&lt;P&gt;UDP 1700 for change of authorization&lt;/P&gt;
&lt;P&gt;UDP 1812 for authentication and authorization&lt;/P&gt;
&lt;P&gt;UDP 1813 for accounting&lt;/P&gt;
&lt;P&gt;you can use https,tftp,ntp, sftp, ldap(389), ldap secure (636).&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 02 Jul 2025 03:20:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/necessary-ports-for-cisco-9800-cl/m-p/5304685#M284505</guid>
      <dc:creator>Ambuj M</dc:creator>
      <dc:date>2025-07-02T03:20:05Z</dc:date>
    </item>
    <item>
      <title>Re: Necessary Ports for Cisco 9800-CL</title>
      <link>https://community.cisco.com/t5/wireless/necessary-ports-for-cisco-9800-cl/m-p/5304688#M284507</link>
      <description>&lt;P&gt;This was not something I read online. I pulled a report from ThreatLocker which showed DNS replies being sent to a whole bunch of different ports on the WLC. I know port 53 is the port that a DNS query is sent to on a DC, but the DNS replies went to a whole bunch of different ports on the WLC. I was not sure if there was a standard range of ports on the WLC that received DNS replies.&lt;/P&gt;</description>
      <pubDate>Wed, 02 Jul 2025 03:39:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/necessary-ports-for-cisco-9800-cl/m-p/5304688#M284507</guid>
      <dc:creator>jmorton1</dc:creator>
      <dc:date>2025-07-02T03:39:31Z</dc:date>
    </item>
    <item>
      <title>Re: Necessary Ports for Cisco 9800-CL</title>
      <link>https://community.cisco.com/t5/wireless/necessary-ports-for-cisco-9800-cl/m-p/5304939#M284523</link>
      <description>&lt;P&gt;I think dns use 53 port&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Also you need many other ports like snmp abd ssh/telnet http/https ...etc.&lt;/P&gt;
&lt;P&gt;So open port one by one depend on what you need to run&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Wed, 02 Jul 2025 16:32:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/necessary-ports-for-cisco-9800-cl/m-p/5304939#M284523</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2025-07-02T16:32:15Z</dc:date>
    </item>
    <item>
      <title>Re: Necessary Ports for Cisco 9800-CL</title>
      <link>https://community.cisco.com/t5/wireless/necessary-ports-for-cisco-9800-cl/m-p/5325948#M285910</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1041311"&gt;@jmorton1&lt;/a&gt;&amp;nbsp;The WLC specific ports and protocols are listed in the release notes.&lt;BR /&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/wireless/controller/9800/17-18/release-notes/rn-17-18-9800.html#Networkprotocolsandportmatrix" target="_blank" rel="noopener"&gt;https://www.cisco.com/c/en/us/td/docs/wireless/controller/9800/17-18/release-notes/rn-17-18-9800.html#Networkprotocolsandportmatrix&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;gt;&amp;nbsp;&lt;SPAN&gt;I pulled a report from ThreatLocker which showed DNS replies being sent to a whole bunch of different ports on the WLC.&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;I think you might be misunderstanding how IP protocols work.&amp;nbsp; UDP 53 is the DNS server port - the destination port for DNS query packets.&amp;nbsp; The source port can be any high port (often used to be referred to as &lt;/SPAN&gt;&lt;A style="font-family: inherit; background-color: #ffffff;" href="https://en.wikipedia.org/wiki/Ephemeral_port" target="_blank" rel="noopener"&gt;ephemeral ports&lt;/A&gt;&lt;SPAN&gt;) so the DNS &lt;/SPAN&gt;&lt;STRONG style="font-family: inherit;"&gt;reply&lt;/STRONG&gt;&lt;SPAN&gt; from the server will have that high port as its destination (with source port being 53 in that case).&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Example:&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;DNS query: UDP&amp;nbsp;49152 -&amp;gt; UDP 53&lt;BR /&gt;DNS reply: UDP 53 -&amp;gt; UDP&amp;nbsp;49152&lt;BR /&gt;Next DNS query: UDP&amp;nbsp;49153 -&amp;gt; UDP 53&lt;BR /&gt;with DNS reply: UDP 53 -&amp;gt; UDP&amp;nbsp;49153&lt;BR /&gt;Each DNS query will use a new source port, which has no specific meaning, so no point in even looking at that, it simply identifies that particular flow.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 31 Aug 2025 12:59:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/necessary-ports-for-cisco-9800-cl/m-p/5325948#M285910</guid>
      <dc:creator>Rich R</dc:creator>
      <dc:date>2025-08-31T12:59:19Z</dc:date>
    </item>
    <item>
      <title>Re: Necessary Ports for Cisco 9800-CL</title>
      <link>https://community.cisco.com/t5/wireless/necessary-ports-for-cisco-9800-cl/m-p/5326436#M285965</link>
      <description>&lt;P&gt;I am aware that ports 49152-65535 are typically used to receive DNS replies on an endpoint, but I was seeing DNS traffic from the server hit the WLC on port numbers in the 8000s range, so that is why I originally posted this.&lt;/P&gt;</description>
      <pubDate>Tue, 02 Sep 2025 13:10:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/necessary-ports-for-cisco-9800-cl/m-p/5326436#M285965</guid>
      <dc:creator>jmorton1</dc:creator>
      <dc:date>2025-09-02T13:10:09Z</dc:date>
    </item>
    <item>
      <title>Re: Necessary Ports for Cisco 9800-CL</title>
      <link>https://community.cisco.com/t5/wireless/necessary-ports-for-cisco-9800-cl/m-p/5326468#M285971</link>
      <description>&lt;P&gt;Historically anything &amp;gt;1024 was used.&amp;nbsp; Some OS or apps may still use the lower ports.&amp;nbsp; Sometimes you can configure what should be used.&amp;nbsp; The point is the server is just replying to the port the request was sent from.&amp;nbsp; It's the client that determines the choice of source port.&amp;nbsp; Some NAT routers may also PAT to lower ports.&amp;nbsp; Unless you control the clients that traffic comes from, there's nothing you can do about it.&lt;/P&gt;</description>
      <pubDate>Tue, 02 Sep 2025 15:17:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/necessary-ports-for-cisco-9800-cl/m-p/5326468#M285971</guid>
      <dc:creator>Rich R</dc:creator>
      <dc:date>2025-09-02T15:17:54Z</dc:date>
    </item>
    <item>
      <title>Re: Necessary Ports for Cisco 9800-CL</title>
      <link>https://community.cisco.com/t5/wireless/necessary-ports-for-cisco-9800-cl/m-p/5326501#M285980</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1041311"&gt;@jmorton1&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P data-start="0" data-end="109"&gt;Here’s the short list you’ll need to allow for a 9800-CL to function properly with APs, RADIUS, and AD/PKI:&lt;/P&gt;
&lt;P data-start="111" data-end="146"&gt;&lt;STRONG data-start="111" data-end="144"&gt;Between WLC and APs (CAPWAP):&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL data-start="147" data-end="237"&gt;
&lt;LI data-start="147" data-end="169"&gt;
&lt;P data-start="149" data-end="169"&gt;UDP/5246 (Control)&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-start="170" data-end="189"&gt;
&lt;P data-start="172" data-end="189"&gt;UDP/5247 (Data)&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-start="190" data-end="237"&gt;
&lt;P data-start="192" data-end="237"&gt;Optional: UDP/16666 (AP console if enabled)&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P data-start="239" data-end="274"&gt;&lt;STRONG data-start="239" data-end="272"&gt;Between WLC and RADIUS / AAA:&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL data-start="275" data-end="383"&gt;
&lt;LI data-start="275" data-end="304"&gt;
&lt;P data-start="277" data-end="304"&gt;UDP/1812 (Authentication)&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-start="305" data-end="383"&gt;
&lt;P data-start="307" data-end="383"&gt;UDP/1813 (Accounting)&lt;BR data-start="328" data-end="331" /&gt;&lt;EM data-start="331" data-end="381"&gt;(Legacy: 1645/1646 if your RADIUS server is old)&lt;/EM&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P data-start="385" data-end="454"&gt;&lt;STRONG data-start="385" data-end="452"&gt;Between WLC and Domain Controllers (if using AD/LDAP directly):&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL data-start="455" data-end="646"&gt;
&lt;LI data-start="455" data-end="492"&gt;
&lt;P data-start="457" data-end="492"&gt;TCP/389 (LDAP) or TCP/636 (LDAPS)&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-start="493" data-end="571"&gt;
&lt;P data-start="495" data-end="571"&gt;TCP/88, TCP/464, UDP/88 (Kerberos, if 802.1X with AD/Kerberos integration)&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-start="572" data-end="646"&gt;
&lt;P data-start="574" data-end="646"&gt;TCP/3268/3269 (Global Catalog, optional depending on your auth design)&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P data-start="648" data-end="689"&gt;&lt;STRONG data-start="648" data-end="687"&gt;Management / Other common services:&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL data-start="690" data-end="875"&gt;
&lt;LI data-start="690" data-end="706"&gt;
&lt;P data-start="692" data-end="706"&gt;TCP/22 (SSH)&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-start="707" data-end="739"&gt;
&lt;P data-start="709" data-end="739"&gt;TCP/443 (HTTPS / GUI / APIs)&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-start="740" data-end="784"&gt;
&lt;P data-start="742" data-end="784"&gt;UDP/123 (NTP sync is highly recommended)&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-start="785" data-end="834"&gt;
&lt;P data-start="787" data-end="834"&gt;SNMP: UDP/161, UDP/162 (if you’re monitoring)&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-start="835" data-end="875"&gt;
&lt;P data-start="837" data-end="875"&gt;Syslog: UDP/514 (if you export logs)&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P data-start="877" data-end="956"&gt;That’s usually all you need to pin down in ThreatLocker or a firewall policy.&lt;/P&gt;</description>
      <pubDate>Tue, 02 Sep 2025 16:52:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/necessary-ports-for-cisco-9800-cl/m-p/5326501#M285980</guid>
      <dc:creator>Stefan Mihajlov</dc:creator>
      <dc:date>2025-09-02T16:52:49Z</dc:date>
    </item>
    <item>
      <title>Re: Necessary Ports for Cisco 9800-CL</title>
      <link>https://community.cisco.com/t5/wireless/necessary-ports-for-cisco-9800-cl/m-p/5326505#M285981</link>
      <description>&lt;P&gt;NOW it so clear&amp;nbsp;&lt;BR /&gt;this hit how you see it ?&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Tue, 02 Sep 2025 16:58:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/necessary-ports-for-cisco-9800-cl/m-p/5326505#M285981</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2025-09-02T16:58:27Z</dc:date>
    </item>
  </channel>
</rss>

