dCloud Help

Find the answers you need to get started using dCloud.

Open Firewall Ports for Session Access

May 2023

There are many ways to connect to dCloud sessions. Today, we recommended Meraki. While some legacy routers are permitted, many are soon becoming obsolete because of the simplicity and benefits Meraki routers and endpoints provide.

Also See: Get a Meraki MX Router for dCloud Use.

A Cisco Meraki Device must be able to communicate with the Cisco Meraki cloud (dashboard) over a secure tunnel. This tunnel is created between Cisco Meraki devices and dashboard to pass management and reporting traffic in both directions. 

Table 1 is in progress.

Table 1.    Meraki Ruleset Required for dCloud

Source IP Destination IP FQDN Ports Protocol Direction Description Devices using this rule
Your network(s)

64.62.142.12/32,                 

209.206.48.0/20,                    

216.157.128.0/20,                    

158.115.128.0/19

  80,443    TCP  outbound  Meraki cloud MX Security Appliance
Your network(s) Any     TCP outbound  Meraki cloud MX Security Appliance
Your network(s)

209.206.48.0/20,

216.157.128.0/20,

158.115.128.0/19

 

80,993,         

7734,7752 ,  

60000-61000 

  outbound

Backup Meraki     

cloud, Backup

config downloads... 

MX Security Appliance

209.206.48.0/20,   

216.157.128.0/20,

158.115.128.0/19

 Your network(s)     Any UDP inbound SNMP traps   MX Security Appliance
Your network(s)   Any    123 UDP outbound NTP time sync  MX Security Appliance
Your network(s)

 209.206.48.0/20,                                   

 216.157.128.0/20,

 158.115.128.0/19

    ICMP outbound  Uplink connection MX Security Appliance
Your network(s)  209.206.48.0/20          9350-9381   UDP outbound AutoVPN registry MX Security Appliance


Table 2. Supported Meraki Endpoints

Router Model Tested Router IOS Version Tested AP IOS Version External/Internet Port (Connect router to Internet) Switch Ports (Connect router to laptops, IP phones, VXC devices)
MX67 MX16.16 Not Applicable Internet 1 2 - 5 (No PoE support)
MX67W MX16.16 Not Applicable Internet 1 2 - 5 (No PoE support)
MX68 MX16.16 Not Applicable Internet 1 3 - 12 (PoE support)
MX68W MX16.16 Not Applicable Internet 1 3 - 12 (PoE support)

 

Meraki Details and Troubleshooting

To learn more about Meraki Firewall rules and services, review:

If you connect to a session through a firewall, the ports that must be permitted and opened on that firewall depend on the method you use to connect to the session. The table lists dCloud access methods and the firewall port number that must be permitted to enable the communication type used by each method.

Table 1. Firewall Port to Open and Communication Type to Enable Session Access Methods

Method Used to Connect to dCloud Sessions Port (Communication Type)
VPN (AnyConnect) Port 443 (TCP and UDP)
VPN (Endpoint Router Kit) Port 443 (TCP)
IP Phone VPN Port 443 (UDP)
BYOD Port 5247 (UDP)
Data for BYOD Port 5246 (UDP)
Standard HTTPS (dCloud Remote Desktop) Port 443
Standard HTTP Port 80

Firewall

For VPN connections (the first three access methods): When you permit a VPN connection to dCloud sessions for the specified port, you don't need to make any further modifications to the firewall.

Example: Assume you have a router that you want to connect to a dCloud session via VPN. You must permit port 443 on the firewall for the VPN to establish between your router and dCloud. When VPN is established, any device connected to your router can connect through the router directly to the active session. This is because

After the VPN is established,

all traffic to the active session will go over the VPN; however, any Internet browsing traffic is sent over the local connection. This is done by the split-tunneling setup on the router. Similarly, assume that you want to connect an endpoint device to a dCloud session using AnyConnect.

When the VPN connection is permitted across port 443 and established, all traffic between the endpoint device and the session across that VPN is allowed.

Some dCloud content may require that additional firewall ports be opened for specific communication types. Those port numbers will be provided in the content documentation or the Help for that architecture.

Meraki is Recommended

As Meraki endpoints & routers are now recommended, multiple legacy routers are moving toward retirement and some will continue to be permitted. Review these topics for helpful information:

Resources

Contact these teams for support:

Back to top






    Was this page useful ?
    Was this page useful ?
    Email*
    Enter Valid Email Address
    What can we do to improve your experience?
    Help us with more info *


    *Required field
    Was this page useful ?
    Email*
    Enter Valid Email Address
    What did you like about it?
    *Required field
    The feedback has been submitted successfully!