Required Communication Ports

Table 1 lists the open ports and services that run on the Apstra DCD server

Apstra DCD requires the following minimum SSH configurations:

  • Eight (8) SSH connections

  • Two (2) SSH max-sessions-per-connection

  • Twenty (20) SSH rate-limit (maximum connection attempts per minute)

A running iptables instance ensures that network traffic to and from the Apstra DCD server is restricted to the services listed.

Note: GPU server network protocol requirements include the Network Device, Network Device for device agents, Network Device and Offbox Agent, and Network Device or Offbox Agent only.
Table 1: Apstra DCD Server Network Protocol Requirements
Source Destination Protocol Description

User workstation

Apstra DCD Server

tcp/22 (ssh)

CLI access to Apstra DCD server

User workstation

Apstra DCD Server

tcp/80 (http)

Redirects to tcp/443 (https)

Network Device

Apstra DCD Flow

udp/6343 (sflow)

sFlow traffic monitoring

User workstation

Apstra DCD Server

tcp/443 (https)

GUI and REST API

Network Device for device agents

Apstra DCD Server

tcp/80 (http)

Redirects to tcp/443 (https)

Network Device and Offbox Agent

Apstra DCD Server

tcp/443 (https)

Device agent installation and upgrade, Rest API

Network Device or Offbox Agent

Apstra DCD Server

tcp/29730-29739

Agent binary protocol (Sysdb)

ZTP Server

Apstra DCD Server

tcp/443 (https)

Rest API for Device System Agent Install

Apstra DCD Server

Network Devices

tcp/22 (ssh)

Device agent installation and upgrade

Offbox Agent

Network Devices

tcp/32767 (grpc/ssl)

Junos streaming telemetry using gRPC over SSL

Offbox Agent

Network Devices tcp/443 (https) tcp/9443 (nxapi) tcp/830 (for Junos)

Management from Off-box Agent