Firewall Requirements
Allow the connections below through your network and host firewalls. Ports are destination ports. Restrict each rule to the listed source and destination.
Application Access
Use the application load-balancer IPv4 address configured during installation. The application hostname must resolve to this address. Clients use that hostname; firewall rules target the load-balancer IP.
| From | To | Protocol | Port | Notes |
|---|---|---|---|---|
Application clients |
Application load-balancer IP |
TCP |
443 |
ERS application access over HTTPS using the application hostname. |
OCSP clients and ACME servers |
Application load-balancer IP |
TCP |
80 |
OCSP requests and ACME HTTP-01 certificate validation, when used. |
Customer monitoring server |
Application load-balancer IP |
TCP |
9443 |
Optional. Scrape |
Appliance Access
Use each appliance node’s static IPv4 address configured during installation. Allow Management to reach every node IP.
| From | To | Protocol | Port | Notes |
|---|---|---|---|---|
Management |
Appliance node IPs |
TCP |
50000 |
Talos API. |
Management |
Appliance node IPs |
TCP |
6443 |
Kubernetes API during the access lease. |
Management |
Appliance node IPs |
TCP |
443 |
Node registry during the access lease. |
Management Access
| From | To | Protocol | Port | Notes |
|---|---|---|---|---|
Operator workstation |
Management |
TCP |
443 |
Management web UI. Use your configured HTTPS port if different. |
Administrator workstation |
Management host |
TCP |
22 |
Host SSH from approved maintenance sources only. For ISO hosts, restrict access before first boot and complete required SSH policy configuration and credential rotation before production use. |
ACME server |
Management |
TCP |
80 |
Only for ACME HTTP-01 certificate validation. |
Between Appliance Nodes
All appliance nodes must be in the same subnet. If traffic between them is unrestricted, no additional internode firewall rules are needed; the table below is a reference for the connections they use.
If a host, hypervisor or network firewall filters traffic within that subnet, allow every node to initiate the listed connections to every other node’s static IPv4 address.
| From | To | Protocol | Port | Notes |
|---|---|---|---|---|
Appliance node IPs |
Appliance node IPs |
TCP |
2380 |
etcd peer replication and quorum. |
Appliance node IPs |
Appliance node IPs |
TCP |
4240 |
Cilium HTTP health probes for connectivity reporting. |
Appliance node IPs |
Appliance node IPs |
TCP |
6443 |
Kubernetes API and KubePrism access to API servers on other nodes. |
Appliance node IPs |
Appliance node IPs |
TCP |
9100 |
Required for appliance monitoring of node CPU, memory, disks and network. |
Appliance node IPs |
Appliance node IPs |
TCP |
9962 |
Required for appliance monitoring of Cilium agents. |
Appliance node IPs |
Appliance node IPs |
TCP |
9963 |
Required for appliance monitoring of Cilium operators. |
Appliance node IPs |
Appliance node IPs |
TCP |
9965 |
Required for appliance monitoring of network flows through Hubble. |
Appliance node IPs |
Appliance node IPs |
TCP |
10250 |
Kubelet operations, including logs and exec, and metrics collection. |
Appliance node IPs |
Appliance node IPs |
TCP |
50000 |
Talos API requests forwarded between nodes. |
Appliance node IPs |
Appliance node IPs |
TCP |
50001 |
Talos |
Appliance node IPs |
Appliance node IPs |
UDP |
8472 |
VXLAN transport. Keep allowed for bootstrap and the configured Cilium overlay. |
Appliance node IPs |
Appliance node IPs |
UDP |
51871 |
WireGuard encrypted workload traffic between nodes. |
Appliance node IPs |
Appliance node IPs |
ICMP |
Not applicable |
Cilium health probes. Echo request type 8 and reply type 0, code 0. |
Keep TCP 4240 and ICMP echo enabled for appliance health reporting.
Blocking these probes reduces connectivity visibility even when workload forwarding still works.
Database replication, object-storage replication and other traffic between application pods use the network tunnels listed above. Their internal service ports do not require separate openings in the firewall between node IPs.
External Services
| From | To | Protocol | Port | Notes |
|---|---|---|---|---|
Management and nodes |
DNS servers |
UDP / TCP |
53 |
Name resolution. |
Management and nodes |
NTP servers |
UDP |
123 |
Time synchronization. |
Management |
Release registry |
TCP |
443 |
Connected downloads. Use the registry’s configured port. |
Appliance nodes |
Syslog receiver |
TCP / UDP |
Configured |
Optional. Default TLS setting: TCP 6514. |
Appliance nodes |
S3 backup endpoint |
TCP |
Configured |
Optional external backups. |
Appliance nodes |
SFTP backup server |
TCP |
22 |
Optional external backups; port can be changed. |
In an air-gapped installation, use internal DNS and NTP and transfer release archives and boot media into the environment. Add the ports specified by the selected ERS interfaces, HSM and other integrations.
Address and DNS planning: IP addresses and DNS.
Core node-port references: Kubernetes, Talos and Cilium.
Access Lifetime and Network Restrictions
A valid artifact bundle opens external Kubernetes and registry access for a six-hour lease. Expiry, explicit eviction and normal Management shutdown attempt to close those external paths while preserving cluster-internal traffic. After a crash or loss of node connectivity, Management may be unable to confirm that remote access is closed. Reconnect to reconcile access and follow the displayed warning.
The lease does not create a Management source-IP allowlist. While open, these authenticated endpoints can be reached from routable IPv4 sources permitted by your surrounding network. Restrict those sources through your own network controls. See Renew or end cluster access and Security and hardening.
Next Step
Follow the installation introduction to deploy Management and prepare the Appliance release.