Wireless Access

last person joined: 20 hours ago 

Access network design for branch, remote, outdoor, and campus locations with HPE Aruba Networking access points and mobility controllers.
Expand all | Collapse all

What ports for communication between Virtual Mobility Master and Mobility Controller?

This thread has been viewed 11 times
  • 1.  What ports for communication between Virtual Mobility Master and Mobility Controller?

    Posted Jun 09, 2019 10:11 AM

    I've installed a Virtual Mobility Master on a Proxmox (KVM) instance, hosted in a data center. This VMM is sitting behind a pfSense instance that does NAT.

     

    I then have multiple hardware Mobility Controllers at different physical locations.

     

    So the VMM and Mobility Controllers would be communicating over the internet.

     

    I haven't yet added them to the VMM yet.

     

    My question is - what ports do I need to forward on the VMM side, in order for the Mobility Controller to communicate with it?



  • 2.  RE: What ports for communication between Virtual Mobility Master and Mobility Controller?



  • 3.  RE: What ports for communication between Virtual Mobility Master and Mobility Controller?

    Posted Jun 09, 2019 12:17 PM

    So just to be clear - for VMM (Virtual Mobility Master) to MC (Mobility Controller), I need all of the following ports to be port forwarded?

     

    IPsec (UDP port 4500) for communication between Mobility Master and a managed device.

    IPsec (UDP ports 500 and 4500) and ESP (protocol 50). PAPI between Mobility Master and a managed device is encapsulated in IPsec.

    IP-IP (protocol 94) and UDP port 443 if Layer-3 mobility is enabled

    GRE (protocol 47) if tunneling guest traffic over GRE to DMZ managed device

    IKE (UDP 500)

    ESP (protocol 50)

    NAT-T (UDP 4500)

     

    That seems like...an awful lot of ports =(.

     

    Is there any other way of linking a VMM hosted somewhere in a colo or in the cloud, and where you have Mobility Controllers and APs in various locations?



  • 4.  RE: What ports for communication between Virtual Mobility Master and Mobility Controller?

    EMPLOYEE
    Posted Jun 09, 2019 01:20 PM

    That looks like port udp 4500 repeated several times along with IKE (udp 500) ESP (protocol 50).

     

    There is not another way, unfortunately.

     

    EDIT:  All you need is UDP 4500 between a mobility master and a mobility controller, btw.  The other protocols are not necessary.