Network
Barracuda Admin avatar
Written by Barracuda Admin
Updated over a week ago

Requirements

  • These are the network requirements for a secure working installation:

    • Internal resources (configured from the CloudGen Access Console) can only communicate with the internal leg of the Envoy Proxy.

    • The Envoy proxy has an internal leg and an internet-facing leg.

    • The Internet-facing leg needs to expose the configured CloudGen Access Proxy port.

    • For High Availability mode (HA), the Envoy Proxy must be placed behind a layer 3 round robin load balancer.

Firewall Configuration

All values are assumed to be default values.

Component

Description

Direction

Protocol / Port

Mode

Envoy Proxy
​
​

Access port

Inbound

Configured in Console

All

Registered resources

Outbound

Configured in Console

All

CloudGen Access Proxy Orchestrator

Outbound

TCP 50051

All

CloudGen Access Proxy Orchestrator
​
​

Envoy Proxy Cluster

Inbound

TCP 50051

All

CloudGen Access Console API

Outbound

TCP 443

All

Redis

Outbound

Configured Redis port

HA mode

Network Diagrams

Single Mode

cg_access_ap-net_single_mode.png

High Availability Mode

Redis Replication is beyond the scope of this document. See Redis Replication on the redis site.

cg_access_ap-net_ha_mode.png
Did this answer your question?