Use these firewall requirements to configure rules in your external firewall to allow Nutanix Remote Support, Pulse, SMTP, 1-click upgrades, and LCM updates.
Source | Controller VM / Prism Central IP addresses |
Destination | nsc01.nutanix.net and nsc02.nutanix.net |
Protocol - Port | TCP - 80 and 8443 |
Action | ALLOW |
Source | Controller VM / Prism Central IP addresses | Allows Pulse messages from the cluster to Nutanix support servers.
|
Destination | insights.nutanix.com | |
Protocol - Port | For insights.nutanix.com: TCP - 443 For nsc01.nutanix.net and nsc02.nutanix.net:
| |
Action | ALLOW |
Source | Controller VM / Prism Central IP addresses |
Destination | insights.nutanix.com and designated email addresses (if any) |
Protocol - Port | TCP - 443 |
Action | ALLOW |
Source | Primary Site Controller VM IP addresses (including Virtual IP Addresses) |
Destination | Replication Site Controller VM IP addresses (including Virtual IP Addresses) |
Protocol - Port |
|
Action | ALLOW |
Source | SMTP Server IP Address | Allows cluster e-mails to be sent to Nutanix Support for Pulse. If your security policy does not allow ports 80 and 8443 to be opened, Pulse can send messages using any accessible SMTP server. If you do not have an SMTP server, you can use an HTTP proxy. |
Destination | nos-alerts@nutanix.com and nos-asups@nutanix.com | |
Protocol - Port | SMTP - 25,465, or 587 (standard) | |
Action | ALLOW |
Source | Controller VM / Prism Central IP addresses | Note: The destination IP address ranges are controlled by the external service provider (AWS). See the AWS documentation topic AWS IP Address Ranges. |
Destination |
| |
Protocol - Port | HTTP - 80 HTTPS - 443 | |
Action | ALLOW |
Source | Controller VM IP addresses |
Destination |
|
Protocol - Port |
|
Action | ALLOW |
Source | Clients accessing the cluster where Nutanix Volumes is enabled |
Destination | Nutanix cluster, through the cluster iSCSI Data Services IP Address |
Ports on clients | 3260 and 3205 |
Action | ALLOW |