cancel
Showing results for 
Search instead for 
Did you mean: 

ZoneDirector 10.5.1.0.124 behind a firewall - AP upgrade broken

ms264556
Contributor II

Is there updated guidance for firewall ports to open, for ZoneDirector 10.5.1?

I did an upgrade to 10.5.1.0.124, and all of my APs (R600s, H510s, R650s) failed to upgrade.

I reverted to 10.5.0.0.212, turned on Secured AP Image Upgrade, and re-attempted the upgrade. Now all the APs updated, but the APs at remote sites kept rebooting with config sync errors: "Configuration update request failed".

I notice in the release notes for 10.5.1.0.124, the new feature:-

Replace FTP with HTTPS
As a security enhancement, File Transfer Protocol (FTP) is replaced with Hypertext Transfer Protocol Secure (HTTPS).

Do I need to let port 443 traffic through my firewall for the configuration upgrade to succeed?
(I have a reverse proxy on port 443 of the firewall currently, so this would be a significant infrastructure change).

1 ACCEPTED SOLUTION

Since I have websites on port 443, and don't want to give these up, I figured out which URL needed to be forwarded to the ZoneDirector (/firmwares/avpport), and documented the firewall setup (pfSense) here: https://ms264556.net/pages/ZD1200OpenPfsensePorts .

View solution in original post

5 REPLIES 5

Since I have websites on port 443, and don't want to give these up, I figured out which URL needed to be forwarded to the ZoneDirector (/firmwares/avpport), and documented the firewall setup (pfSense) here: https://ms264556.net/pages/ZD1200OpenPfsensePorts .