OpenRoaming firewall rules
The Cisco Spaces Connector and OpenRoaming integration path require reachability to OpenRoaming, OpenRoaming services, and RadSec endpoints. For controller-based deployments, allow controller-to-connector RADIUS traffic. For connector cloud access and Meraki RadSec, allow the required outbound paths. If direct internet access is restricted, configure the required ports, FQDNs, and Meraki RadSec HAProxy IP destinations on the firewall, DNS security service, proxy, or SSL inspection device.
Note |
|
|
Traffic / service |
Requirement |
|---|---|
|
Cisco Spaces or OpenRoaming cloud |
Allow HTTPS or TCP 443 to the regional Cisco and OpenRoaming domains. |
|
Controller to Connector RADIUS |
For controller-based deployments, allow Cisco AireOS/Catalyst controller traffic to the OpenRoaming Connector on UDP/TCP 1812 and 1813 for OpenRoaming RADIUS messages. |
|
RADSec |
Allow TCP 2083 where RADSec-secured authentication is used. |
|
Meraki AP RadSec |
For Meraki deployments, allow Meraki AP outbound TCP 2083 to the applicable OpenRoaming RadSec HAProxy IP destination listed in the Meraki RadSec IP allowlist. |
|
RADIUS |
Allow UDP 1812 and UDP 1813 where customer RADIUS authentication/accounting flows are used. |
|
DNS |
Required FQDNs must resolve from the connector/controller/API egress network. |
|
Proxy or SSL inspection |
Bypass or explicitly trust required OpenRoaming service traffic. Proxy authentication, TLS inspection, or certificate substitution can prevent onboarding even when DNS resolution succeeds. |
Feedback