Ports used by Meraki Z3 Teleworker

Solved
Bobby-P
Here to help

Ports used by Meraki Z3 Teleworker

Need to deploy a Teleworker on a network not under our management.  Noc for this network needs to know ports teleworkers use to communicated to our Meraki firewall.  What ports need to be open to allow teleworkers to connect to our network.

1 Accepted Solution
alemabrahao
Kind of a big deal
Kind of a big deal

But those are the ports, it doesn't matter the model.

Protocol Port Purpose

UDP7351Meraki Auto VPN
UDP9350Meraki Auto VPN
UDP500IKE (for VPN)
UDP4500NAT-T (for VPN)
UDP53DNS resolution
TCP80Dashboard communication (HTTP)
TCP443Dashboard communication (HTTPS)
I am not a Cisco Meraki employee. My suggestions are based on documentation of Meraki best practices and day-to-day experience.

Please, if this post was useful, leave your kudos and mark it as solved.

View solution in original post

5 Replies 5
alemabrahao
Kind of a big deal
Kind of a big deal

You can check it under Firewall info on the dashboard.

 

alemabrahao_0-1751042206386.png

 

I am not a Cisco Meraki employee. My suggestions are based on documentation of Meraki best practices and day-to-day experience.

Please, if this post was useful, leave your kudos and mark it as solved.
Bobby-P
Here to help

I didn't find this useful.  I have also viewed this information but need to know specifically the ports used.

alemabrahao
Kind of a big deal
Kind of a big deal

But those are the ports, it doesn't matter the model.

Protocol Port Purpose

UDP7351Meraki Auto VPN
UDP9350Meraki Auto VPN
UDP500IKE (for VPN)
UDP4500NAT-T (for VPN)
UDP53DNS resolution
TCP80Dashboard communication (HTTP)
TCP443Dashboard communication (HTTPS)
I am not a Cisco Meraki employee. My suggestions are based on documentation of Meraki best practices and day-to-day experience.

Please, if this post was useful, leave your kudos and mark it as solved.
cmr
Kind of a big deal
Kind of a big deal

Adding to what @alemabrahao said, the ones highlighted in green are needed, the others not for a Z, only generally an MX:

 

Source IPDestination IPFQDNPortsProtocolDescription
Your network(s)64.62.142.12/32, 158.115.128.0/19, 209.206.48.0/20, 216.157.128.0/20 7351, 9350-9381UDPMeraki cloud communication, VPN registry
Your network(s) cloud-meraki-asn.amp.cisco.com443TCPAdvanced Malware Protection (AMP) Lookups
Your network(s) cloud-meraki-est.amp.cisco.com443TCPAdvanced Malware Protection (AMP) Enrollment
Your network(s)158.115.128.0/19, 209.206.48.0/20, 216.157.128.0/20syslog.log-ingester.emea.production.insight.meraki.com443TCPInsight data collection
Your network(s)158.115.128.0/19registry.meraki-applications.com443TCPMeraki Container Registry
Your network(s)158.115.128.0/19, 209.206.48.0/20, 216.157.128.0/20, 2606:6940:0000:0000:0000:0000:0000:0000/32, 2606:7bc0:0000:0000:0000:0000:0000:0000/32, 2620:012f:c000:0000:0000:0000:0000:0000/44 80, 443, 7734, 7752TCPMeraki cloud communication, Splash pages, Backup Meraki cloud communication, Backup configuration downloads, Measured throughput to dashboard.meraki.com, Backup firmware downloads
Your network(s)0.0.0.0/0 123UDPNTP time synchronization 
Your network(s)8.8.8.8/32, 158.115.128.0/19, 209.206.48.0/20, 216.157.128.0/20  ICMPUplink connection monitor
If my answer solves your problem please click Accept as Solution so others can benefit from it.
cmr
Kind of a big deal
Kind of a big deal

Note this is for a particular organisation, if you go to the firewall information on your organisation it may differ, but the same rows / descriptions are the important ones for a Z3.

If my answer solves your problem please click Accept as Solution so others can benefit from it.
Get notified when there are additional replies to this discussion.