Configure your firewalls to permit the following flows based on your
selected topology.
Public Internet Access (Port 1)
| Rule Name | Source IP Address | Destination | Protocol/Port | Action | Note |
| Cloud Controller | Connector Port 1 | *.cgnx.net¥ | TCP 443 | Allow | Disable SSL Decryption⁂ |
| ZTT IPSec ф | Connector Port 1 | Prisma Access Service IP addresses | UDP 500, 4500 | Allow | IKE and NAT-T |
| ZTT-NTP | Connector Port 1 | time.nist.gov, *.cloudgenix.pool.ntp.org | UDP 123 | Allow | Time synchronization |
| ZTT-Public-DNS | Connector Port 1 | Public DNS (example 8.8.8.8) | UDP and TCP 53 | Allow | Public FQDN resolution |
| Diagnostics | Connector LAN IP | ping ZTT, traceroute to ZTT, ping app server, traceroute
to app server, tcpping controller endpoint | ICMP, UDP and TCP | Allow | For ping, tccping, nslookup or traceroute tools |
фIf ZTNA Connector uses a public IP address for its internet interface,
you must allow an IP/50 Encapsulating Security Payload (ESP). ESP must be
allowed bi-directionally (both inbound and outbound traffic). There are no ports
for ESP; it is a separate IP protocol (IP 50), not TCP or UDP. This requirement
applies to all IPSec devices, not just ZTNA Connectors.
⁂The Connector to controller connection uses certificates for
authentication and therefore SSL decryption must be disabled.
Data Center Access (Port 1 for 1-Arm; Port 2 for 2-Arm)
| Rule Name | Source IP Address | Destination | Protocol/Port | Action | Note |
| Internal-DNS | Connector LAN IP | Internal DNS Servers | UDP and TCP/53 | Allow | App FQDN resolution |
| App-Probing | Connector LAN IP | Internal Application Servers | Health probe protocol and port | Allow | TCP Ping health check |
| User-Access | Connector LAN IP | Internal Application Servers | App Specific Protocols or Ports | Allow | Production user traffic |
| Diagnostics | Connector LAN IP | tcpping app server, ping app server, traceroute to app
server, ping DNS, traceroute to DNS | ICMP, UDP and TCP | Allow | For ping, tccping, nslookup or traceroute tools |
The following requirements enable connectivity between ZTNA Connector and
Prisma Access: