Authorizing base station flows to and from ThingPark core network for self-hosted ThingPark Enterprise
If using self-hosted ThingPark Enterprise, this topic describes the required
flows to authorize in your base station deployment environment, such as
proxies, firewalls... These flows allow base stations to exchange
traffic with ThingPark core network, as well as external
time-synchronization servers.
# | From (system) | From (application) | Type | Protocol | Dest. Port | To (system) | To (application) | Description | STANDALONE | HIGH AVAILABILITY |
---|
i1 | BASE STATION | strongswan (client) | Bidirectional | IKE v2 (secure) MOBIKE v2 (secure) | UDP/500 UDP/4500 | TPE | strongswan | IPsec IKE (UDP) / MOBIKE (UDP) ike=aes128-sha256-ecp256,aes128-sha384-ecp384,aes256-sha512-ecp521 | MUST | MUST |
i2 | BASE STATION | strongswan (client) | Bidirectional | ESP (secure) | - | TPE | strongswan | ESP (protocol 50) ike=aes128-sha256-ecp256,aes128-sha384-ecp384,aes256-sha512-ecp521 esp=aes128gcm128,aes256gcm128 | MUST | MUST |
i3 | BASE STATION | OS | Unidirectional | ICMP | - | TPE | OS | Ping (TPE) | MUST | MUST |
i4 | BASE STATION | Key installer (client) | Unidirectional | SFTP | TCP/22 | TPE | Key installer (server) | SFTP protocol | MUST | MUST |
i5 | BASE STATION | OS | Unidirectional | SSH v2 (secure) | TCP/22 | TPE | OS | LRR admin (Reverse SSH) | MUST | MUST |
i38 | BASE STATION | OS | Unidirectional | TLS | TCP/3001 | TPE | server | Check certificate validity on server side (only applicable to LRR version >= 2.8) | MUST | MUST |
i39 | BASE STATION | OS | Unidirectional | TLS | TCP/3002 | TPE | server | Check certificate validity on server side (only applicable to LRR version >= 2.8) | MUST | MUST |
i40 | BASE STATION | OS | Unidirectional | TLS | TCP/3003 | TPE | OS | Check certificate validity on server side (only applicable to LRR version >= 2.8) | MUST | MUST |
n1 | BASE STATION | OS | Unidirectional | NTP | UDP/123 | NTP service | service | NTP requests when TPE is not used for NTP | OPTIONAL | OPTIONAL |
n2 | BASE STATION | OS | Unidirectional | DNS | UDP/53 | DNS service | service | DNS requests | OPTIONAL | OPTIONAL |
n3 | BASE STATION | OS | Unidirectional | NTP | UDP/123 | TPE | NTP service | NTP requests when TPE is used for NTP | OPTIONAL | OPTIONAL |
n4 | BASE STATION | OS | Unidirectional | DHCP | - | DHCP service | service | DHCP request | OPTIONAL | OPTIONAL |
# | From (system) | From (application) | Type | Protocol | Dest. Port | To (system) | To (application) | Description | STANDALONE | HIGH AVAILABILITY |
---|
i3 | BASE STATION | OS | Unidirectional | ICMP | - | TPE | OS | Ping (TPE) | MUST | MUST |
i4 | BASE STATION | Key installer (client) | Unidirectional | SFTP | TCP/22 | TPE | Key installer (server) | SFTP protocol | MUST | MUST |
i5 | BASE STATION | OS | Unidirectional | SSH v2 (secure) | TCP/22 | TPE | OS | LRR admin (Reverse SSH) | MUST | MUST |
i38 | BASE STATION | OS | Unidirectional | IEC 104 over TLS (secure) | TCP/3001 | TPE | server | LRR IEC 104 link: LRR commands and LoRa uplink/donwlink data and metadata exchange. | MUST | MUST |
i39 | BASE STATION | OS | Unidirectional | SFTP over TLS (secure) | TCP/3002 | TPE | server | LRR sofware download LRR sofware configuration download | MUST | MUST |
i40 | BASE STATION | OS | Unidirectional | SFTP over TLS (secure) | TCP/3003 | TPE | OS | LRR rf scan upload LRR software configuration upload | MUST | MUST |
n1 | BASE STATION | OS | Unidirectional | NTP | UDP/123 | NTP service | service | NTP requests when TPE is not used for NTP | OPTIONAL | OPTIONAL |
n2 | BASE STATION | OS | Unidirectional | DNS | UDP/53 | DNS service | service | DNS requests | OPTIONAL | OPTIONAL |
n3 | BASE STATION | OS | Unidirectional | NTP | UDP/123 | TPE | NTP service | NTP requests when TPE is used for NTP | OPTIONAL | OPTIONAL |
n4 | BASE STATION | OS | Unidirectional | DHCP | - | DHCP service | service | DHCP request | OPTIONAL | OPTIONAL |
# | From (system) | From (application) | Type | Protocol | Dest. Port | To (system) | To (application) | Description | STANDALONE | HIGH AVAILABILITY |
---|
i3 | BASE STATION | OS | Unidirectional | ICMP | - | TPE | OS | Ping (TPE) | MUST | MUST |
i5 | BASE STATION | OS | Unidirectional | SSH v2 (secure) | TCP/22 | TPE | OS | LRR admin (Reverse SSH) | MUST | MUST |
i6 | BASE STATION | OS | Unidirectional | IEC 104 | TCP/2404 | TPE | server | LRR IEC 104 link: LRR commands and LoRa uplink/donwlink data and metadata exchange. | MUST | MUST |
i7 | BASE STATION | OS | Unidirectional | FTP | TCP/21 | TPE | server | LRR sofware download LRR sofware configuration download. | MUST | MUST |
i8 | BASE STATION | OS | Unidirectional | FTP | TCP/21 | TPE | OS | LRR rf scan upload LRR software configuration upload | MUST | MUST |
n1 | BASE STATION | OS | Unidirectional | NTP | UDP/123 | NTP service | service | NTP requests when TPE is not used for NTP | OPTIONAL | OPTIONAL |
n2 | BASE STATION | OS | Unidirectional | DNS | UDP/53 | DNS service | service | DNS requests | OPTIONAL | OPTIONAL |
n3 | BASE STATION | OS | Unidirectional | NTP | UDP/123 | TPE | NTP service | NTP requests when TPE is used for NTP | OPTIONAL | OPTIONAL |
n4 | BASE STATION | OS | Unidirectional | DHCP | - | DHCP service | service | DHCP request | OPTIONAL | OPTIONAL |
# | From (system) | From (application) | Type | Protocol | Dest. Port | To (system) | To (application) | Description | STANDALONE | HIGH AVAILABILITY |
---|
i42 | BASE STATION | Semtech Basics Station | Unidirectional | HTTPS/WSS | TCP/4443 | TPE | haproxy | LNS interface | MUST | MUST |
i43 | BASE STATION | Semtech Basics Station | Unidirectional | HTTP+TLS v1.2 (secure) | TCP/443 | TPE | RCA | CUPS interface | MUST | MUST |
n1 | BASE STATION | OS | Unidirectional | NTP | UDP/123 | NTP service | service | NTP requests when TPE is not used for NTP | OPTIONAL | OPTIONAL |
n2 | BASE STATION | OS | Unidirectional | DNS | UDP/53 | DNS service | service | DNS requests | OPTIONAL | OPTIONAL |
n3 | BASE STATION | OS | Unidirectional | NTP | UDP/123 | TPE | NTP service | NTP requests when TPE is used for NTP | OPTIONAL | OPTIONAL |
n4 | BASE STATION | OS | Unidirectional | DHCP | - | DHCP service | service | DHCP request | OPTIONAL | OPTIONAL |