cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
789
Views
0
Helpful
5
Replies

Firewall between 5508 controllers

roger perkin
Level 2
Level 2

I am deploying a 5508 controller with a second HA-SKU 5508 controller as backup - they will be separated by a firewall.

Apart from 16666 UDP are there any other ports that need to be open between the controllers?

I already have setup UDP 5246 and 5247 for CAPWAP to the controllers.

Thanks

 

Roger

 

 

5 Replies 5

Abhishek Abhishek
Cisco Employee
Cisco Employee

Make sure that the CAPWAP UDP ports 5246 and 5247 (similar to the LWAPP UDP ports 12222 and 12223) are enabled and are not blocked by an intermediate device that could prevent an access point from joining the controller.

Thanks Abhishek, 

I already have those enabled my question was referencing the communication between the Primary and Backup controller 

This is not an HA setup, There will be a Primary controller in one location and a backup controller in a secondary location. they will be separated by a firewall.

I will be enabling 16666 and 16667 UDP between the controllers. 

My question was had anyone had to open any more ports in this setup? 

 

Thanks

 

Roger

abwahid
Level 4
Level 4

HI,

Please go through the below deployment guide.

http://www.cisco.com/c/en/us/td/docs/wireless/controller/technotes/7-5/High_Availability_DG.html

I have been through that, but it does not mention which firewall ports are involved between two controllers running primary / backup between two firewalls. 

 

varunag
Level 1
Level 1

Please be informed that you can open the below ports in your firewall

UPD 16667

UDP 16666 for tunnel control traffic

IP protocol 97 for user data traffic

UDP 161 and 162 for SNMP

UDP 5246 and 5247 for CAPWAP

Please let me know if my answer is helpful for you .

Review Cisco Networking for a $25 gift card