Configure your firewalls to permit the following flows based on your
selected topology.
Public Internet Access (Port 1)
| Rule Name | Source IP Address | Destination | Protocol/Port | Action | Note |
| Cloud Controller | Connector Port 1 | *.cgnx.net¥ | TCP 443 | Allow | Disable SSL Decryption⁂ |
| ZTT IPSec ф | Connector Port 1 | Prisma Access Service IP addresses | UDP 500, 4500 | Allow | IKE and NAT-T |
| ZTT-NTP | Connector Port 1 | time.nist.gov, *.cloudgenix.pool.ntp.org | UDP 123 | Allow | Time synchronization |
| ZTT-Public-DNS | Connector Port 1 | Public DNS (example 8.8.8.8) | UDP and TCP 53 | Allow | Public FQDN resolution |
| Diagnostics | Connector LAN IP | ping ZTT, traceroute to ZTT, ping app server, traceroute
to app server, tcpping controller endpoint | ICMP, UDP and TCP | Allow | For ping, tccping, nslookup or traceroute tools |
ф If ZTNA Connector uses a public IP address for its internet interface,
you must allow a IP/50 Encapsulating Security Payload (ESP).
⁂The Connector to controller connection uses certificates for
authentication and therefore SSL decryption must be disabled.
Data Center Access (Port 1 for 1-Arm; Port 2 for 2-Arm)
| Rule Name | Source IP Address | Destination | Protocol/Port | Action | Note |
| Internal-DNS | Connector LAN IP | Internal DNS Servers | UDP and TCP/53 | Allow | App FQDN resolution |
| App-Probing | Connector LAN IP | Internal Application Servers | Health probe protocol and port | Allow | TCP Ping health check |
| User-Access | Connector LAN IP | Internal Application Servers | App Specific Protocols or Ports | Allow | Production user traffic |
| Diagnostics | Connector LAN IP | tcpping app server, ping app server, traceroute to app
server, ping DNS, traceroute to DNS | ICMP, UDP and TCP | Allow | For ping, tccping, nslookup or traceroute tools |
The following requirements enable connectivity between ZTNA Connector and
Prisma Access: