Firewall Rules
This document provides a comprehensive matrix of the network ports and protocols required by SUSE Virtualization platform services. Opening and allowing traffic on these ports is critical for node-to-node cluster communication, high availability, and external service integrations.
For more information on baseline host network requirements, see Network Requirements.
To reduce the attack surface by applying strict iptables rules for these ports, refer to Host Network Security.
Internal Node-to-Node Traffic
The following ports must be open for internal communication between nodes in the SUSE Virtualization cluster. Typically, all outbound traffic between cluster nodes is allowed.
Core Kubernetes & Etcd Services
| Protocol | Port | Source | Description |
|---|---|---|---|
TCP |
2379 |
Management nodes |
Etcd client port |
TCP |
2380 |
Management nodes |
Etcd peer port |
TCP |
2381 |
Management nodes |
Etcd metrics collection |
TCP |
2382 |
Management nodes |
Etcd client port (HTTP only) |
TCP |
6443 |
Management nodes |
Kubernetes API |
TCP |
9345 |
Management nodes |
Kubernetes API (RKE2 supervisor API) |
TCP |
10250 |
Management and compute nodes |
Kubelet API |
TCP |
10251 |
Management nodes |
Kube-scheduler health checks |
TCP |
10252 |
Management nodes |
Kube-controller-manager health checks |
TCP |
10256 |
Management and compute nodes |
Kube-proxy health checks |
TCP |
10257 |
Management nodes |
Kube-controller-manager secure port |
TCP |
10258 |
Management nodes |
cloud-controller-manager |
TCP |
10259 |
Management nodes |
Kube-scheduler secure port |
TCP |
10260 |
Management nodes |
cloud-controller-manager |
TCP |
6444 |
Management and compute nodes |
RKE2 agent |
TCP |
10010 |
Management and compute nodes |
Containerd |
Networking, Ingress and Platform Services
| Protocol | Port | Source | Description |
|---|---|---|---|
ICMP |
All |
All nodes |
ICMP (ping, MTU discovery, etc.) |
UDP |
67-68 |
All nodes |
DHCP server replies and client requests |
UDP |
8472 |
Management and compute nodes |
Canal CNI with VxLAN (Overlay Network) |
TCP |
9091 |
Management and compute nodes |
Canal calico-node metrics (Prometheus) |
TCP |
9099 |
Management and compute nodes |
Canal CNI health checks |
TCP |
2112 |
Management nodes |
Kube-vip Prometheus metrics |
TCP |
80 |
Management and compute nodes |
Nginx (Harvester UI HTTP) |
TCP |
8181 |
Management and compute nodes |
Nginx-ingress-controller |
TCP |
8444 |
Management and compute nodes |
Nginx-ingress-controller |
TCP |
10245 |
Management and compute nodes |
Nginx-ingress-controller |
TCP |
10246-10249 |
Management and compute nodes |
Nginx worker process |
TCP |
30000-32767 |
Management and compute nodes |
NodePort TCP range |
UDP |
30000-32767 |
Management and compute nodes |
NodePort UDP range |
TCP |
9796 |
Management and compute nodes |
Prometheus node-exporter metrics (rancher-monitoring) |
TCP |
22 |
Management, compute, and witness nodes |
sshd |
TCP |
3260 |
Management and compute nodes |
iscsid |
Kube-OVN Operator (Experimental Add-on)
If you enable the kubeovn-operator add-on, the following ports must be permitted based on the node role:
| Protocol | Port | Source | Description |
|---|---|---|---|
TCP |
8080 |
Management and compute nodes |
kube-ovn-webhook HTTP |
TCP |
8443 |
Management and compute nodes |
kube-ovn-webhook HTTPS |
TCP |
6641-6644 |
Management nodes |
OVN NB/SB DB, Northd, and Raft |
TCP |
10660 |
Compute (Worker) nodes |
kube-ovn-controller |
TCP |
10661 |
Management nodes |
kube-ovn-monitor metrics |
TCP |
10665 |
All nodes |
kube-ovn-daemon |
UDP |
4789 |
All nodes |
VXLAN (Kube-OVN) |
External & Integration Traffic
These ports are required for external administrative access, UI access, and integrations with external infrastructure.
| Protocol | Port | Source/Destination | Description |
|---|---|---|---|
TCP |
443 |
External Client → Management VIP |
Access to the SUSE Virtualization API and UI via HTTPS. For details, see Management Address. |
TCP |
443 |
SUSE Virtualization nodes → SUSE Rancher Prime |
Required for SUSE Rancher Prime integration. All SUSE Virtualization nodes must connect to TCP 443 of the SUSE Rancher Prime load balancer. For details, see SUSE Rancher Prime Integration. |
UDP |
123 |
SUSE Virtualization nodes → External NTP Servers |
Required for accurate time synchronization for etcd quorum. For details, see High Availability Principles. |