Firewall Rules

This document provides a comprehensive matrix of the network ports and protocols required by SUSE Virtualization platform services. Opening and allowing traffic on these ports is critical for node-to-node cluster communication, high availability, and external service integrations.

For more information on baseline host network requirements, see Network Requirements.

To reduce the attack surface by applying strict iptables rules for these ports, refer to Host Network Security.

Internal Node-to-Node Traffic

The following ports must be open for internal communication between nodes in the SUSE Virtualization cluster. Typically, all outbound traffic between cluster nodes is allowed.

Core Kubernetes & Etcd Services

Protocol Port Source Description

TCP

2379

Management nodes

Etcd client port

TCP

2380

Management nodes

Etcd peer port

TCP

2381

Management nodes

Etcd metrics collection

TCP

2382

Management nodes

Etcd client port (HTTP only)

TCP

6443

Management nodes

Kubernetes API

TCP

9345

Management nodes

Kubernetes API (RKE2 supervisor API)

TCP

10250

Management and compute nodes

Kubelet API

TCP

10251

Management nodes

Kube-scheduler health checks

TCP

10252

Management nodes

Kube-controller-manager health checks

TCP

10256

Management and compute nodes

Kube-proxy health checks

TCP

10257

Management nodes

Kube-controller-manager secure port

TCP

10258

Management nodes

cloud-controller-manager

TCP

10259

Management nodes

Kube-scheduler secure port

TCP

10260

Management nodes

cloud-controller-manager

TCP

6444

Management and compute nodes

RKE2 agent

TCP

10010

Management and compute nodes

Containerd

Networking, Ingress and Platform Services

Protocol Port Source Description

ICMP

All

All nodes

ICMP (ping, MTU discovery, etc.)

UDP

67-68

All nodes

DHCP server replies and client requests

UDP

8472

Management and compute nodes

Canal CNI with VxLAN (Overlay Network)

TCP

9091

Management and compute nodes

Canal calico-node metrics (Prometheus)

TCP

9099

Management and compute nodes

Canal CNI health checks

TCP

2112

Management nodes

Kube-vip Prometheus metrics

TCP

80

Management and compute nodes

Nginx (Harvester UI HTTP)

TCP

8181

Management and compute nodes

Nginx-ingress-controller

TCP

8444

Management and compute nodes

Nginx-ingress-controller

TCP

10245

Management and compute nodes

Nginx-ingress-controller

TCP

10246-10249

Management and compute nodes

Nginx worker process

TCP

30000-32767

Management and compute nodes

NodePort TCP range

UDP

30000-32767

Management and compute nodes

NodePort UDP range

TCP

9796

Management and compute nodes

Prometheus node-exporter metrics (rancher-monitoring)

TCP

22

Management, compute, and witness nodes

sshd

TCP

3260

Management and compute nodes

iscsid

Kube-OVN Operator (Experimental Add-on)

If you enable the kubeovn-operator add-on, the following ports must be permitted based on the node role:

Protocol Port Source Description

TCP

8080

Management and compute nodes

kube-ovn-webhook HTTP

TCP

8443

Management and compute nodes

kube-ovn-webhook HTTPS

TCP

6641-6644

Management nodes

OVN NB/SB DB, Northd, and Raft

TCP

10660

Compute (Worker) nodes

kube-ovn-controller

TCP

10661

Management nodes

kube-ovn-monitor metrics

TCP

10665

All nodes

kube-ovn-daemon

UDP

4789

All nodes

VXLAN (Kube-OVN)

External & Integration Traffic

These ports are required for external administrative access, UI access, and integrations with external infrastructure.

Protocol Port Source/Destination Description

TCP

443

External Client → Management VIP

Access to the SUSE Virtualization API and UI via HTTPS. For details, see Management Address.

TCP

443

SUSE Virtualization nodes → SUSE Rancher Prime

Required for SUSE Rancher Prime integration. All SUSE Virtualization nodes must connect to TCP 443 of the SUSE Rancher Prime load balancer. For details, see SUSE Rancher Prime Integration.

UDP

123

SUSE Virtualization nodes → External NTP Servers

Required for accurate time synchronization for etcd quorum. For details, see High Availability Principles.